FlowRunner
PricingContact
Theme
Start Free

Watch security awareness posture from your workflows. Agents pull KnowBe4 users with Phish-Prone Percentages, report training campaign completion, flag risky clicks in phishing security tests, and surface account-level risk scores through the read-only Reporting API.

10 actions API key available
KnowBe4 website ↗ Platform Documentation ↗ Capability data verified 2026-07-28
The weekly security posture sweep starts on schedule
List Phishing Security Tests pulls recent tests with their Phish-Prone Percentages and click counts
The agent flags tests where clicks or data-entry events exceed the team's threshold
Get Security Test Recipients retrieves per-user results for the flagged tests, who clicked, who entered data, who reported
Get User enriches each flagged person with their risk score, group memberships, and training history
The security lead reviews the named list and decides who gets follow-up training, who gets a quiet heads-up, and whether anything becomes an incident
Approved follow-ups go out as tickets and reminders in the systems the team already runs

What This Integration Enables

Security awareness programs fail in a predictable way: the platform generates the data, and nobody operationalizes it. The phishing test runs, the Phish-Prone Percentage updates, and the follow-up that should happen the same day happens at the quarterly review, if at all. This connector puts KnowBe4's Reporting API inside your workflows so the data starts moving the day it exists. It is read-only by design, which makes it a clean fit for the watching half of an orchestration: KnowBe4 measures, FlowRunner routes, and the systems where work happens receive it. - Sync users, groups, and Phish-Prone Percentages into spreadsheets, warehouses, and BI dashboards - Alert security staff when a phishing test shows high-risk click or data-entry activity - Chase training campaign completion automatically, with escalation for repeat stragglers - Reconcile KnowBe4 group membership against your identity provider - Feed account-level Risk Score into the metrics pack leadership actually reads

Without FlowRunner

Reporting happens at renewal time Phish-Prone Percentages get looked at when the KnowBe4 invoice arrives, not when the numbers move
Test results stay in the console Someone exports a CSV after each phishing test, and the follow-up depends on that person's calendar
Training completion is chased by hand The security lead pings stragglers one by one, campaign after campaign, forever

With FlowRunner

Posture is watched continuously Agents sweep tests, enrollments, and risk scores on a schedule and surface only what crossed a line
Click events become routed work High-risk results turn into tickets and reminders within the hour, with a person deciding the sensitive ones
The dashboard fills itself Risk scores and completion rates land in the warehouse and the BI layer without a monthly export ritual

Use Case Scenarios

The phishing test that gets a same-day response

A phishing security test wraps up. The sweep finds it via List Phishing Security Tests, sees the click count, and calls Get Security Test Recipients for the roster: who opened, who clicked, who entered data, who reported. Reporters get an automated thank-you nudge through [Slack](/integrations/slack), because reporting is the behavior you want more of. The click list goes to the security lead, and approved follow-ups become tickets in [ServiceNow](/integrations/servicenow). The loop that used to take a month closes in an afternoon.

Training completion without the nagging job

A compliance-mandated campaign is running. Twice a week, List Training Enrollments filtered to the campaign returns who has not completed, and the agent sorts them by deadline proximity. First pass: a friendly reminder in [Microsoft Teams](/integrations/microsoft-teams). Second pass: manager copied. Final pass: the list goes to the security lead with each person's enrollment history, and a human decides what escalation is fair. The campaign hits its deadline without the program owner spending evenings as a collections agent.

The risk trendline the board can see

Monthly, the agent calls Get Account for the organization-wide Risk Score and average Phish-Prone Percentage, List Users for per-department scores via group membership, and List Phishing Security Tests for the quarter's test results. Everything lands in [Google Sheets](/integrations/google-sheets) as a running series. When the board asks whether the security training budget is working, the answer is a trendline, not an anecdote.

Human-in-Loop Highlight

Get Security Test Recipients returns something unusually sensitive: a named list of colleagues and whether each one clicked a simulated phish or typed credentials into a fake login page. Every downstream action taken on that list, a ticket with their name on it, a note to their manager, enrollment in remedial training, reaches into someone's professional standing, and a false move is hard to walk back. An employee flagged to their manager over a test they clicked while triaging a real incident does not forget it, and neither does the program's reputation. So FlowRunner workflows draw the line cleanly: aggregate numbers flow automatically, and thank-you nudges to reporters flow automatically, but any action attached to a named clicker waits for the security lead. The agent assembles the context, risk score, prior tests, training record, and the lead decides what response fits the person. Awareness programs run on trust. The gate is what keeps the automation from spending it.

Agent processes routinely
Detects exception requiring judgment
Clear match Continues automatically
Ambiguous Routes to human via preferred channel
Human decides
Agent resumes with decision

Agent Capabilities

10 actions

Users

2
  • List Users Pages through the account's users with profile details, group memberships, and current Phish-Prone Percentage, filterable to active or archived. The roster read behind every sync and per-department report.
  • Get User Retrieves one user by ID with full profile, groups, and risk scoring. The enrichment step before any flagged name goes in front of a human.

Groups

2
  • List Groups Lists KnowBe4-managed and Active Directory Integration groups with member counts, type, and provisioning source. The map for department-level reporting and IdP reconciliation.
  • Get Group Members Returns the full user objects belonging to a group. Used to scope sweeps and completion chases to the teams that matter.

Training

2
  • List Training Campaigns Lists training campaigns with status, schedule, completion percentage, assigned groups, and content. The campaign-level view for program reporting.
  • List Training Enrollments Pages through individual enrollments, optionally scoped to one campaign, with learner, module, status, completion date, and time spent. The action behind every straggler chase.

Phishing

3
  • List Phishing Campaigns Lists phishing test campaigns with status, schedule, frequency, targeted groups, and their security tests. Supplies the test IDs that per-user detail hangs off.
  • List Phishing Security Tests Lists phishing security tests across the account with targets, Phish-Prone Percentage, and aggregate clicks, replies, attachment opens, and reports. The sweep's first read.
  • Get Security Test Recipients Returns per-user results for one test: opened, clicked, replied, entered data, reported, with timestamps. The most sensitive read in the connector, and the one whose downstream actions this page gates.

Account

1
  • Get Account Retrieves account-level metrics: subscription level and end date, purchased and used seats, organization Risk Score, and average Phish-Prone Percentage. The single call behind the leadership trendline, and a quiet way to catch seat-count drift before renewal.

Frequently Asked Questions

What can FlowRunner do with KnowBe4?

FlowRunner agents can run List Users, Get User, and List Groups in KnowBe4, plus 7 more actions.

Does connecting KnowBe4 to FlowRunner require OAuth?

No. KnowBe4 connects to FlowRunner with an API key, no OAuth flow required.

Can KnowBe4 trigger a FlowRunner workflow automatically?

KnowBe4 doesn't currently expose triggers in FlowRunner. It connects as an action step inside workflows started by another trigger.

Start building with KnowBe4

$100 in credits. No card required. Connect in minutes.