> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cimento.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cimento Documentation

> Setup and reference documentation for security administrators deploying Cimento phishing simulation and security training.

Cimento is a human-risk security platform. It runs phishing simulations across email, SMS and voice, and delivers security awareness training and policy acknowledgments.

These docs are written for the security administrator setting Cimento up and for the IT and identity teams they need help from. Every page that asks for access in a vendor console lists the exact permissions involved and what each one is for, so you can hand the link to whoever owns that console.

## Product areas

<CardGroup cols={2}>
  <Card title="Phishing" icon="fish" href="/phishing/overview">
    Connect Google Workspace or Microsoft 365 for inbox delivery, enroll employees for SMS and voice simulations, and run campaigns.
  </Card>

  <Card title="Training" icon="graduation-cap" href="/training/overview">
    Build or import courses, publish policies for acknowledgment, and assign them to employees through campaigns.
  </Card>
</CardGroup>

## How setup works

<Steps>
  <Step title="Connect your employee directory">
    Every product area targets people, departments and groups, so the directory comes first. Okta and Microsoft Entra ID send employees to Cimento over SCIM, and Cimento reads Google Workspace with read-only scopes. See [Employee directory](/getting-started/employee-directory).
  </Step>

  <Step title="Connect your tools">
    Follow the guide for each tool your organization uses: [Okta](/integrations/okta), [Microsoft Entra ID](/integrations/microsoft-entra-id), [Google Workspace](/integrations/google-workspace), [Microsoft 365](/integrations/microsoft-365), the [Phish Alert Button for Outlook](/integrations/outlook-phish-alert-button) and [Slack](/integrations/slack). Each guide follows the same steps as the setup wizard in Cimento. [Integrations](/integrations/overview#who-you-will-need) lists the admin each tool needs.
  </Step>

  <Step title="Pilot, then roll out">
    Start small: one group of employees for a phishing campaign and one course for training. Widen once you have confirmed results in the admin console.
  </Step>
</Steps>

## How Cimento handles access

* **Least privilege.** Every integration asks for a dedicated credential scoped to what that deployment does, never an administrator account.
* **No admin credentials.** Cimento never receives or stores your Google, Microsoft or Okta administrator passwords. Any API key or client secret you do provide is stored encrypted per tenant and never displayed again.
* **Revocable in one place.** Removing the delegation, consent or app integration you set up for Cimento removes its access.
