BaitCheck User Guide
v1.1 · Jul 2026

Program Administrator Guide

Running BaitCheck, end to end.

BaitCheck simulates realistic phishing attempts against your staff, scores how they respond, and turns the results into short, targeted awareness training. This guide covers everything a Program Administrator needs to launch, monitor, and act on a campaign.

Authority

Impersonates a regulator or senior figure demanding action.

Urgency

A fabricated deadline built to make you act before you think.

Reward

A too-good-to-be-true bonus or prize notice.

Section 01

Welcome to BaitCheck

BaitCheck is a phishing simulation and security awareness platform built for Nigerian financial institutions. It sends realistic, controlled phishing lures to staff, measures how people respond, and turns those results into targeted awareness training — without punishing anyone for a single click.

This guide is written for the Program Administrator: the person, or small team, who runs BaitCheck day to day — launching campaigns, reviewing results, and keeping the awareness loop turning. It does not cover server setup or infrastructure; that lives in a separate technical deployment guide.

The BaitCheck loop

1

Simulate

A realistic phishing email is sent to a target group of staff.

2

Score

Every response — ignored, clicked, submitted, or reported — updates each person's risk profile.

3

Personalise

Anyone who clicked or submitted data gets a short video on the exact trigger used against them.

Repeating this cycle over successive campaigns is what produces a measurable, improving click-rate trend — and the evidence trail your regulator and board will want to see.

Section 02

Who does what

RoleWhat they do
Program Administrator (you)Works from the BaitCheck Hub — launches campaigns in the Console, reviews results and reports in the Reports & Admin app, and shares results with leadership. This guide is written for this role.
Staff / Target GroupThe employees who receive simulated lures. They never see the Hub, Console, or Reports & Admin app — only the email, and, if they click, a short, non-punitive learning page.
AegisIntel AdvisoryDeploys and maintains the underlying BaitCheck infrastructure, adds new templates and videos, and supports your institution's pilot or subscription.

Section 03

Getting started

Bookmark one address — the Hub — and start every session there. It's an open landing page (no login) with three cards that route you to everything else. You'll also end up with two separate logins behind those cards; both are set up once during onboarding.

1 · Hub — start here

start.<yourinstance>.aegisintel.io

Open, no login. Three cards: Manage Phishing Exercises, Reports & Admin, and Documentation. Safe to bookmark and share internally.

2 · Console

console.<yourinstance>.aegisintel.io

Where campaigns are built and launched. Reached via the Hub's "Manage Phishing Exercises" card. Protected by your BaitCheck username and password.

3 · Reports & Admin

reports.<yourinstance>.aegisintel.io

Dashboard, live risk report, board compliance report, CSV export, and data retention. Reached via the Hub's "Reports & Admin" card. Its own separate login.

Your exact addresses

The subdomain in front of "aegisintel.io" is unique to your institution's BaitCheck instance and is issued by AegisIntel Advisory during onboarding. Keep all three links and both sets of credentials in a password manager, not a shared chat thread.

Logging in for the first time

You'll do this once for the Console and once for Reports & Admin — the steps are the same for both:

  1. From the Hub, click through to the Console or the Reports & Admin card.
  2. Enter the username and temporary password provided during onboarding.
  3. You'll be prompted to set your own password immediately — do this, don't skip it.
  4. Store the new password in your password manager. If it's lost, contact AegisIntel Advisory to reset it.
Why this matters

The Console's underlying engine can print a fresh, random admin password whenever the platform restarts for maintenance — but only if you never set your own. Choosing your own password the first time stops that from ever happening again.

Had the old direct Live Report link bookmarked?

The old stand-alone report page has been replaced by the Reports & Admin app. Update your bookmark to the Hub, or straight to the Reports & Admin address above.

Section 04

Key concepts

A handful of terms come up throughout the Hub, Console, and Reports & Admin app. Knowing them makes everything else straightforward.

TermWhat it means
HubThe open landing page you start every session at, with cards routing to the Console, Reports & Admin, and Documentation.
ConsoleThe GoPhish-based screen where campaigns are built and launched. Reached via the Hub.
Reports & AdminThe separate, login-protected app for dashboards, reports, exports, and data retention. Reached via the Hub.
CampaignOne send of one lure email to one target group, over a defined time window.
Template (Lure)The phishing email itself. BaitCheck ships four templates, each built around a different trigger.
Landing PageThe page someone reaches if they click a lure's link — always a learning moment, never a real data-capture form.
Sending ProfileThe outgoing mailbox a campaign sends from. Set up once per institution, reused across campaigns.
Target GroupThe list of staff a campaign is sent to, organised by department.
TriggerThe psychological lever a template exploits: Authority, Urgency, Reward, or Social Proof.
Risk ScoreA running, per-person and per-department score, updated after every campaign.

Section 05

The four trigger templates

Every lure is built around one specific psychological trigger — the same categories real attackers use against Nigerian banks. Knowing what each one tests helps you choose the right template for a given campaign and department.

TemplateTriggerSuggested audience
Regulator Verification NoticeAuthorityGeneral staff, executives, compliance
Payroll Portal — Action RequiredUrgencyGeneral staff, finance, HR
Staff Bonus NotificationRewardGeneral staff
Vendor Account ConfirmationGeneral staff, finance, developers

Each template has a matching short awareness video, sent to anyone who falls for it — see Section 9.

Section 06

Running a campaign

The core workflow you'll repeat for every simulation. Steps 1–2 are typically done once and reused; steps 3–5 are done for every new campaign.

Step 1 — Confirm your Sending Profile

Console: Sending Profiles → your institution's profile. Set up once during onboarding. If your mail credentials change, contact AegisIntel Advisory before editing it yourself.

Step 2 — Check templates and landing pages are loaded

Console: Email Templates and Landing Pages. All four templates should already be present. If one is missing, contact AegisIntel Advisory rather than recreating it — the name must match exactly for scoring to work.

Step 3 — Build or confirm your Target Group

Console: Users & Groups. Record each person's department in the Position field — this powers the Department Risk Matrix in Reports & Admin.

Step 4 — Run pre-flight checks

  • Rotation check — has this group already seen this exact template recently?
  • Cadence check — has this group been simulated too recently, on any template?

Step 5 — Launch

Console: Campaigns → New Campaign. Choose a name, template, matching landing page, sending profile, and target group, then click Launch.

Step 6 — Point Reports & Admin at your campaign

Reports & Admin: Campaign Selection. Pick the campaign you just launched so the Dashboard and Live Risk Report start tracking it. This is self-service — you no longer need to ask AegisIntel Advisory which campaign is being watched.

Consent first, always

Never launch against a group that has not given the informed consent your pilot or program agreement requires. If you're unsure a group is cleared, check with AegisIntel Advisory before launching, not after.

Section 07

Understanding results

Everything in this section lives in the Reports & Admin app, reached via the Hub. Log in and you'll land on the Dashboard, with five other pages in the sidebar: Campaign Selection (Section 6, Step 6), Live Risk Report, Board Compliance Report, Export CSV, and Data Retention — plus a link back to the Console for managing exercises.

Dashboard & Live Risk Report

The Dashboard gives you an at-a-glance summary of your selected campaign; the Live Risk Report is the detailed, auto-refreshing view — leave the tab open and it updates on its own as responses come in, no manual refresh needed.

What each status means

StatusScoringMeaning
Email Sent / OpenedNeutralNo action yet, or opened without clicking. Never counted against anyone.
Clicked LinkNegativeShown the learning landing page immediately, and queued for the matching video.
Submitted DataNegative (higher)Clicked through and entered information. Weighted more, still a learning moment, never disciplinary.
Email ReportedPositiveCorrectly flagged as suspicious. Faster reports score better — but any report is a good outcome.
The philosophy behind the scoring

Hesitation is never punished, and reporting is always rewarded. Someone who hasn't acted yet is treated exactly the same as someone still deciding — neither is a failure. Only a click or a data submission moves a risk score up.

Reading the Department Risk Matrix

The matrix cross-references departments against the four triggers. A department that scores high on Urgency is more likely to click a same-day-deadline lure than an Authority one — useful when deciding which template to run next, and when briefing leadership on where awareness effort should focus.

Board Compliance Report

Reports & Admin: Board Compliance Report. Generates a formatted summary built for your BRMC or board pack — click rate trend, report rate trend, and department breakdown — without you having to assemble it by hand. This is the same evidence AegisIntel Advisory previously had to run for you from the command line; it's now a button.

Export CSV

Reports & Admin: Export CSV. Exports the full results of your selected campaign for audit evidence — CBN, NDPA, or your own internal records. Also self-service now; run it as often as your record-keeping requires rather than requesting it from AegisIntel Advisory.

Data Retention

Reports & Admin: Data Retention. Lets you purge old campaign data once it's past the retention period your institution's data policy sets. This is destructive and irreversible, so it sits behind a genuine two-step confirmation — read the confirmation screen carefully, and export first (above) if you need to keep a copy.

Section 08

What staff see

Staff never see the Hub, Console, or Reports & Admin app. Their entire experience is the lure email and, depending on what they do next, one of two short web pages.

If they click the link

They land on a page that immediately explains: this was a simulated exercise, no real data was collected, and exactly which trigger was used against them — followed by a short (60–80 second) video going deeper on that trigger. The tone is deliberately constructive: "Nice catch — almost," never "You failed."

If they report the email

Anyone who reports a lure through the normal channel is shown explicit, specific recognition — not a generic "thanks." It reinforces that reporting is exactly the behaviour BaitCheck is training for.

What staff should be told beforehand

  • That simulated phishing exercises happen periodically, as part of the security awareness program.
  • That results are used to improve training, not to discipline individuals.
  • How to report a suspicious email through the normal channel.

Your consent and communications requirements are set out in your institution's Pilot Plan / Program Agreement — check there for the exact wording to use.

Section 09

Awareness videos

Each trigger has a matching short video, identified as due whenever someone clicks or submits data on that trigger's template.

VideoTriggerLength
"When the Regulator Really Calls"Authority~72 sec
"The 4-Minute Deadline Trick"Urgency~65 sec
"Too Good, Too Fast"Reward~80 sec
"Everyone Else Clicked — Did They?"~68 sec
Current process is manual

In this MVP phase, BaitCheck identifies who is due which video after each results sync, but does not send it automatically. You, or AegisIntel Advisory on your behalf, email the flagged list their video link. Automatic sending is on the near-term roadmap — this page will update once it ships.

Section 10

Operator tools

Some of what used to require AegisIntel Advisory now lives directly in Reports & Admin (Section 7). The rest is still run by your technical contact or AegisIntel Advisory from the command line. Listed here so you know what's self-service and what to ask for.

Now self-service, in Reports & Admin

PageWhat it's for
Campaign SelectionPoint the Dashboard and Live Risk Report at the campaign you want to watch.
Board Compliance ReportGenerate a board/BRMC-ready compliance summary on demand.
Export CSVExport full campaign results for CBN/NDPA audit evidence.
Data RetentionPurge old campaign data past your retention period, behind a two-step confirmation.

Still CLI-only — ask your technical contact or AegisIntel Advisory

Quick reference — 5 tools
ToolWhat it's for
Sync resultsPull the latest responses from a campaign and update everyone's risk score.
Rotation checkBefore sending, check who in the group has already seen that template recently.
Cadence checkCheck who in the group has been simulated too recently, on any template.
Plan sendGet a randomised per-recipient send-time spread, so a batch doesn't land all at once.
Set roleTag a person's role for future role-based template targeting.

Section 11

Good practice & guardrails

  • Never launch without confirmed, current consent for the target group.
  • Run a rotation check and a cadence check before every send.
  • Keep every follow-up communication constructive — match the tone BaitCheck's own pages already model.
  • Treat campaign data like any staff personal data — restrict Console and Reports & Admin access, follow retention rules.
  • Export results regularly so you always have audit-ready evidence.
  • Route template, landing page, or credential changes through AegisIntel Advisory — scoring depends on exact name matches.
  • Export before you purge — Data Retention's two-step confirmation is destructive and irreversible, so use it deliberately.

Section 12

Frequently asked questions

The Live Risk Report page looks blank or stuck.

It shows data only once a campaign is being actively watched. Go to Campaign Selection in Reports & Admin and confirm the right campaign is picked — this is self-service now, no need to contact AegisIntel Advisory.

I can get into the Console but not Reports & Admin (or the other way around).

That's expected, not a bug — the Console and Reports & Admin have separate logins (Section 3). Make sure you completed the first-login password-change step for both, and check your password manager has an entry for each. If either is genuinely lost, contact AegisIntel Advisory to reset it.

My browser warns a Console or Reports & Admin connection isn't secure.

On the addresses AegisIntel Advisory gave you at onboarding, this shouldn't happen — real certificates are in place on all three. If you do see a warning there, stop and contact AegisIntel Advisory before logging in, rather than clicking through it.

A staff member says they didn't receive the simulation email.

Check their entry in Users & Groups for a correct email address, and confirm the campaign's Sending Profile is healthy. If both look right, flag it to AegisIntel Advisory — it may be a delivery issue on the receiving mail system.

Someone is upset about being "tested."

Point them to Section 8 and your institution's staff communication about the program. BaitCheck's design is built specifically so no individual outcome is punitive — that message is worth repeating directly.

I need a new template, department, or login for a colleague.

These go through AegisIntel Advisory rather than being self-service in this version of BaitCheck — see Section 13.

Section 13

Getting help

For anything not covered here — access issues, new templates, new target groups, or general questions about running your program — contact your AegisIntel Advisory engagement lead.

ContactDetails
AegisIntel Advisory
Program Support
Your assigned engagement lead (contact details provided at onboarding).
↑ Back to top

Section 14

Change log

This guide is updated as BaitCheck's Console, scoring engine, and workflows change on the technical thread. Newest first — check here before relying on step-by-step instructions elsewhere.

  • v1.1 July 2026 Current

    Updated for the new Hub, and the Reports & Admin app replacing the old static Live Report page.

    • New Hub landing page (Section 3) as the single starting point, routing to the Console and Reports & Admin.
    • Reports & Admin app introduced — its own login, and a Dashboard, Live Risk Report, Campaign Selection, Board Compliance Report, Export CSV, and Data Retention (Sections 6–7).
    • Campaign Selection, Board Compliance Report, Export CSV, and Data Retention moved from AegisIntel-only operator tools to self-service (Sections 7 & 10).
    • FAQ and Good Practice updated for the two-login model and the destructive Data Retention purge.
    AegisIntel Advisory
  • v1.0 July 2026

    Initial release of the BaitCheck User Guide.

    • Console and Live Report access, first-login and password guidance.
    • The four trigger templates (Authority, Urgency, Reward, Social Proof).
    • Full campaign launch workflow, results scoring, and the Department Risk Matrix.
    • Employee-facing experience, awareness videos, and the manual video-assignment process.
    • Operator tools reference, good practice guardrails, and FAQ.
    AegisIntel Advisory
↑ Back to top