Program Administrator Guide
Running BaitCheck, end to end.
BaitCheck simulates realistic phishing attempts against your staff, scores how they respond, and turns the results into short, targeted awareness training. This guide covers everything a Program Administrator needs to launch, monitor, and act on a campaign.
Urgency
A fabricated deadline built to make you act before you think.
Reward
A too-good-to-be-true bonus or prize notice.
Section 01
Welcome to BaitCheck
BaitCheck is a phishing simulation and security awareness platform built for Nigerian financial institutions. It sends realistic, controlled phishing lures to staff, measures how people respond, and turns those results into targeted awareness training — without punishing anyone for a single click.
This guide is written for the Program Administrator: the person, or small team, who runs BaitCheck day to day — launching campaigns, reviewing results, and keeping the awareness loop turning. It does not cover server setup or infrastructure; that lives in a separate technical deployment guide.
The BaitCheck loop
Simulate
A realistic phishing email is sent to a target group of staff.
Score
Every response — ignored, clicked, submitted, or reported — updates each person's risk profile.
Personalise
Anyone who clicked or submitted data gets a short video on the exact trigger used against them.
Repeating this cycle over successive campaigns is what produces a measurable, improving click-rate trend — and the evidence trail your regulator and board will want to see.
Section 02
Who does what
| Role | What they do |
|---|---|
| Program Administrator (you) | Works from the BaitCheck Hub — launches campaigns in the Console, reviews results and reports in the Reports & Admin app, and shares results with leadership. This guide is written for this role. |
| Staff / Target Group | The employees who receive simulated lures. They never see the Hub, Console, or Reports & Admin app — only the email, and, if they click, a short, non-punitive learning page. |
| AegisIntel Advisory | Deploys and maintains the underlying BaitCheck infrastructure, adds new templates and videos, and supports your institution's pilot or subscription. |
Section 03
Getting started
Bookmark one address — the Hub — and start every session there. It's an open landing page (no login) with three cards that route you to everything else. You'll also end up with two separate logins behind those cards; both are set up once during onboarding.
1 · Hub — start here
start.<yourinstance>.aegisintel.ioOpen, no login. Three cards: Manage Phishing Exercises, Reports & Admin, and Documentation. Safe to bookmark and share internally.
2 · Console
console.<yourinstance>.aegisintel.ioWhere campaigns are built and launched. Reached via the Hub's "Manage Phishing Exercises" card. Protected by your BaitCheck username and password.
3 · Reports & Admin
reports.<yourinstance>.aegisintel.ioDashboard, live risk report, board compliance report, CSV export, and data retention. Reached via the Hub's "Reports & Admin" card. Its own separate login.
The subdomain in front of "aegisintel.io" is unique to your institution's BaitCheck instance and is issued by AegisIntel Advisory during onboarding. Keep all three links and both sets of credentials in a password manager, not a shared chat thread.
Logging in for the first time
You'll do this once for the Console and once for Reports & Admin — the steps are the same for both:
- From the Hub, click through to the Console or the Reports & Admin card.
- Enter the username and temporary password provided during onboarding.
- You'll be prompted to set your own password immediately — do this, don't skip it.
- Store the new password in your password manager. If it's lost, contact AegisIntel Advisory to reset it.
The Console's underlying engine can print a fresh, random admin password whenever the platform restarts for maintenance — but only if you never set your own. Choosing your own password the first time stops that from ever happening again.
The old stand-alone report page has been replaced by the Reports & Admin app. Update your bookmark to the Hub, or straight to the Reports & Admin address above.
Section 04
Key concepts
A handful of terms come up throughout the Hub, Console, and Reports & Admin app. Knowing them makes everything else straightforward.
| Term | What it means |
|---|---|
| Hub | The open landing page you start every session at, with cards routing to the Console, Reports & Admin, and Documentation. |
| Console | The GoPhish-based screen where campaigns are built and launched. Reached via the Hub. |
| Reports & Admin | The separate, login-protected app for dashboards, reports, exports, and data retention. Reached via the Hub. |
| Campaign | One send of one lure email to one target group, over a defined time window. |
| Template (Lure) | The phishing email itself. BaitCheck ships four templates, each built around a different trigger. |
| Landing Page | The page someone reaches if they click a lure's link — always a learning moment, never a real data-capture form. |
| Sending Profile | The outgoing mailbox a campaign sends from. Set up once per institution, reused across campaigns. |
| Target Group | The list of staff a campaign is sent to, organised by department. |
| Trigger | The psychological lever a template exploits: Authority, Urgency, Reward, or Social Proof. |
| Risk Score | A running, per-person and per-department score, updated after every campaign. |
Section 05
The four trigger templates
Every lure is built around one specific psychological trigger — the same categories real attackers use against Nigerian banks. Knowing what each one tests helps you choose the right template for a given campaign and department.
| Template | Trigger | Suggested audience |
|---|---|---|
| Regulator Verification Notice | General staff, executives, compliance | |
| Payroll Portal — Action Required | Urgency | General staff, finance, HR |
| Staff Bonus Notification | Reward | General staff |
| Vendor Account Confirmation | General staff, finance, developers |
Each template has a matching short awareness video, sent to anyone who falls for it — see Section 9.
Section 06
Running a campaign
The core workflow you'll repeat for every simulation. Steps 1–2 are typically done once and reused; steps 3–5 are done for every new campaign.
Step 1 — Confirm your Sending Profile
Console: Sending Profiles → your institution's profile. Set up once during onboarding. If your mail credentials change, contact AegisIntel Advisory before editing it yourself.
Step 2 — Check templates and landing pages are loaded
Console: Email Templates and Landing Pages. All four templates should already be present. If one is missing, contact AegisIntel Advisory rather than recreating it — the name must match exactly for scoring to work.
Step 3 — Build or confirm your Target Group
Console: Users & Groups. Record each person's department in the Position field — this powers the Department Risk Matrix in Reports & Admin.
Step 4 — Run pre-flight checks
- Rotation check — has this group already seen this exact template recently?
- Cadence check — has this group been simulated too recently, on any template?
Step 5 — Launch
Console: Campaigns → New Campaign. Choose a name, template, matching landing page, sending profile, and target group, then click Launch.
Step 6 — Point Reports & Admin at your campaign
Reports & Admin: Campaign Selection. Pick the campaign you just launched so the Dashboard and Live Risk Report start tracking it. This is self-service — you no longer need to ask AegisIntel Advisory which campaign is being watched.
Never launch against a group that has not given the informed consent your pilot or program agreement requires. If you're unsure a group is cleared, check with AegisIntel Advisory before launching, not after.
Section 07
Understanding results
Everything in this section lives in the Reports & Admin app, reached via the Hub. Log in and you'll land on the Dashboard, with five other pages in the sidebar: Campaign Selection (Section 6, Step 6), Live Risk Report, Board Compliance Report, Export CSV, and Data Retention — plus a link back to the Console for managing exercises.
Dashboard & Live Risk Report
The Dashboard gives you an at-a-glance summary of your selected campaign; the Live Risk Report is the detailed, auto-refreshing view — leave the tab open and it updates on its own as responses come in, no manual refresh needed.
What each status means
| Status | Scoring | Meaning |
|---|---|---|
| Email Sent / Opened | Neutral | No action yet, or opened without clicking. Never counted against anyone. |
| Clicked Link | Negative | Shown the learning landing page immediately, and queued for the matching video. |
| Submitted Data | Negative (higher) | Clicked through and entered information. Weighted more, still a learning moment, never disciplinary. |
| Email Reported | Positive | Correctly flagged as suspicious. Faster reports score better — but any report is a good outcome. |
Hesitation is never punished, and reporting is always rewarded. Someone who hasn't acted yet is treated exactly the same as someone still deciding — neither is a failure. Only a click or a data submission moves a risk score up.
Reading the Department Risk Matrix
The matrix cross-references departments against the four triggers. A department that scores high on Urgency is more likely to click a same-day-deadline lure than an one — useful when deciding which template to run next, and when briefing leadership on where awareness effort should focus.
Board Compliance Report
Reports & Admin: Board Compliance Report. Generates a formatted summary built for your BRMC or board pack — click rate trend, report rate trend, and department breakdown — without you having to assemble it by hand. This is the same evidence AegisIntel Advisory previously had to run for you from the command line; it's now a button.
Export CSV
Reports & Admin: Export CSV. Exports the full results of your selected campaign for audit evidence — CBN, NDPA, or your own internal records. Also self-service now; run it as often as your record-keeping requires rather than requesting it from AegisIntel Advisory.
Data Retention
Reports & Admin: Data Retention. Lets you purge old campaign data once it's past the retention period your institution's data policy sets. This is destructive and irreversible, so it sits behind a genuine two-step confirmation — read the confirmation screen carefully, and export first (above) if you need to keep a copy.
Section 08
What staff see
Staff never see the Hub, Console, or Reports & Admin app. Their entire experience is the lure email and, depending on what they do next, one of two short web pages.
If they click the link
They land on a page that immediately explains: this was a simulated exercise, no real data was collected, and exactly which trigger was used against them — followed by a short (60–80 second) video going deeper on that trigger. The tone is deliberately constructive: "Nice catch — almost," never "You failed."
If they report the email
Anyone who reports a lure through the normal channel is shown explicit, specific recognition — not a generic "thanks." It reinforces that reporting is exactly the behaviour BaitCheck is training for.
What staff should be told beforehand
- That simulated phishing exercises happen periodically, as part of the security awareness program.
- That results are used to improve training, not to discipline individuals.
- How to report a suspicious email through the normal channel.
Your consent and communications requirements are set out in your institution's Pilot Plan / Program Agreement — check there for the exact wording to use.
Section 09
Awareness videos
Each trigger has a matching short video, identified as due whenever someone clicks or submits data on that trigger's template.
| Video | Trigger | Length |
|---|---|---|
| "When the Regulator Really Calls" | ~72 sec | |
| "The 4-Minute Deadline Trick" | Urgency | ~65 sec |
| "Too Good, Too Fast" | Reward | ~80 sec |
| "Everyone Else Clicked — Did They?" | ~68 sec |
In this MVP phase, BaitCheck identifies who is due which video after each results sync, but does not send it automatically. You, or AegisIntel Advisory on your behalf, email the flagged list their video link. Automatic sending is on the near-term roadmap — this page will update once it ships.
Section 10
Operator tools
Some of what used to require AegisIntel Advisory now lives directly in Reports & Admin (Section 7). The rest is still run by your technical contact or AegisIntel Advisory from the command line. Listed here so you know what's self-service and what to ask for.
Now self-service, in Reports & Admin
| Page | What it's for |
|---|---|
| Campaign Selection | Point the Dashboard and Live Risk Report at the campaign you want to watch. |
| Board Compliance Report | Generate a board/BRMC-ready compliance summary on demand. |
| Export CSV | Export full campaign results for CBN/NDPA audit evidence. |
| Data Retention | Purge old campaign data past your retention period, behind a two-step confirmation. |
Still CLI-only — ask your technical contact or AegisIntel Advisory
Quick reference — 5 tools
| Tool | What it's for |
|---|---|
| Sync results | Pull the latest responses from a campaign and update everyone's risk score. |
| Rotation check | Before sending, check who in the group has already seen that template recently. |
| Cadence check | Check who in the group has been simulated too recently, on any template. |
| Plan send | Get a randomised per-recipient send-time spread, so a batch doesn't land all at once. |
| Set role | Tag a person's role for future role-based template targeting. |
Section 11
Good practice & guardrails
- Never launch without confirmed, current consent for the target group.
- Run a rotation check and a cadence check before every send.
- Keep every follow-up communication constructive — match the tone BaitCheck's own pages already model.
- Treat campaign data like any staff personal data — restrict Console and Reports & Admin access, follow retention rules.
- Export results regularly so you always have audit-ready evidence.
- Route template, landing page, or credential changes through AegisIntel Advisory — scoring depends on exact name matches.
- Export before you purge — Data Retention's two-step confirmation is destructive and irreversible, so use it deliberately.
Section 12
Frequently asked questions
The Live Risk Report page looks blank or stuck.
It shows data only once a campaign is being actively watched. Go to Campaign Selection in Reports & Admin and confirm the right campaign is picked — this is self-service now, no need to contact AegisIntel Advisory.
I can get into the Console but not Reports & Admin (or the other way around).
That's expected, not a bug — the Console and Reports & Admin have separate logins (Section 3). Make sure you completed the first-login password-change step for both, and check your password manager has an entry for each. If either is genuinely lost, contact AegisIntel Advisory to reset it.
My browser warns a Console or Reports & Admin connection isn't secure.
On the addresses AegisIntel Advisory gave you at onboarding, this shouldn't happen — real certificates are in place on all three. If you do see a warning there, stop and contact AegisIntel Advisory before logging in, rather than clicking through it.
A staff member says they didn't receive the simulation email.
Check their entry in Users & Groups for a correct email address, and confirm the campaign's Sending Profile is healthy. If both look right, flag it to AegisIntel Advisory — it may be a delivery issue on the receiving mail system.
Someone is upset about being "tested."
Point them to Section 8 and your institution's staff communication about the program. BaitCheck's design is built specifically so no individual outcome is punitive — that message is worth repeating directly.
I need a new template, department, or login for a colleague.
These go through AegisIntel Advisory rather than being self-service in this version of BaitCheck — see Section 13.
Section 13
Getting help
For anything not covered here — access issues, new templates, new target groups, or general questions about running your program — contact your AegisIntel Advisory engagement lead.
| Contact | Details |
|---|---|
| AegisIntel Advisory Program Support | Your assigned engagement lead (contact details provided at onboarding). |
Section 14
Change log
This guide is updated as BaitCheck's Console, scoring engine, and workflows change on the technical thread. Newest first — check here before relying on step-by-step instructions elsewhere.
-
v1.1 July 2026 Current
Updated for the new Hub, and the Reports & Admin app replacing the old static Live Report page.
- New Hub landing page (Section 3) as the single starting point, routing to the Console and Reports & Admin.
- Reports & Admin app introduced — its own login, and a Dashboard, Live Risk Report, Campaign Selection, Board Compliance Report, Export CSV, and Data Retention (Sections 6–7).
- Campaign Selection, Board Compliance Report, Export CSV, and Data Retention moved from AegisIntel-only operator tools to self-service (Sections 7 & 10).
- FAQ and Good Practice updated for the two-login model and the destructive Data Retention purge.
-
v1.0 July 2026
Initial release of the BaitCheck User Guide.
- Console and Live Report access, first-login and password guidance.
- The four trigger templates (Authority, Urgency, Reward, Social Proof).
- Full campaign launch workflow, results scoring, and the Department Risk Matrix.
- Employee-facing experience, awareness videos, and the manual video-assignment process.
- Operator tools reference, good practice guardrails, and FAQ.