Skip to main content
Cimento is a human-risk security platform. It runs phishing simulations across email, SMS and voice, and delivers security awareness training and policy acknowledgments. These docs are written for the security administrator setting Cimento up and for the IT and identity teams they need help from. Every page that asks for access in a vendor console lists the exact permissions involved and what each one is for, so you can hand the link to whoever owns that console.

Product areas

Phishing

Connect Google Workspace or Microsoft 365 for inbox delivery, enroll employees for SMS and voice simulations, and run campaigns.

Training

Build or import courses, publish policies for acknowledgment, and assign them to employees through campaigns.

How setup works

1

Connect your employee directory

Every product area targets people, departments and groups, so the directory comes first. Okta and Microsoft Entra ID send employees to Cimento over SCIM, and Cimento reads Google Workspace with read-only scopes. See Employee directory.
2

Connect your tools

Follow the guide for each tool your organization uses: Okta, Microsoft Entra ID, Google Workspace, Microsoft 365, the Phish Alert Button for Outlook and Slack. Each guide follows the same steps as the setup wizard in Cimento. Integrations lists the admin each tool needs.
3

Pilot, then roll out

Start small: one group of employees for a phishing campaign and one course for training. Widen once you have confirmed results in the admin console.

How Cimento handles access

  • Least privilege. Every integration asks for a dedicated credential scoped to what that deployment does, never an administrator account.
  • No admin credentials. Cimento never receives or stores your Google, Microsoft or Okta administrator passwords. Any API key or client secret you do provide is stored encrypted per tenant and never displayed again.
  • Revocable in one place. Removing the delegation, consent or app integration you set up for Cimento removes its access.