# KnowBe4 (KMSAT Reporting) MCP for AI Agents AI Agent Connect

> KnowBe4 (KMSAT Reporting) MCP lets you audit security awareness training and monitor phishing simulation results. Use it to track user enrollment, pull risk scores for executive reports, and check compliance across departments. It turns your security data into actionable insights for your AI agent.

## Overview
- **Category:** human-resources
- **Price:** Free
- **Endpoint:** https://edge.vinkius.com/vk_preview_zGcORaFEFka2yAMni65cIDmyeR0LkrwfV2N3ARHe/ai-agent-connect
- **Tags:** phishing-simulation, security-awareness, risk-assessment, compliance-training, user-auditing

## Description

You're likely tired of jumping between different tabs to see who actually finished their security training or how many people clicked that last phishing test. This Connector changes that by giving your AI agent a direct line into your security awareness platform. Instead of manually exporting CSVs or digging through the dashboard to find a specific risk score, you can just ask your agent to pull the latest data. It handles the heavy lifting of gathering user enrollment statuses, phishing results, and training progress. Because it's part of the Vinkius catalog, you can connect it to your existing workflow and start getting real-time updates on your security posture. You get to spend less time on data entry and more time actually addressing the vulnerabilities your team faces. It turns your security data into a conversational stream. You can ask about specific departments, check if a new hire is enrolled, or get a summary of the latest simulation results without ever leaving your chat interface. It's about moving from manual reporting to instant answers. Security posture is only as good as your visibility into it. If you don't know who's lagging on their training or which departments are falling for the same phishing tricks, you can't fix the problem. This Connector bridges that gap. It allows your agent to act as a security analyst that's always on call. You can request a summary of risk scores for the board, identify high-risk users who need extra attention, or verify that your entire workforce is compliant with the latest regulations. It takes the friction out of security oversight.

## Tools

### get_account_risk_score
Pull the overall risk score for your account. This is a key metric for executive security reporting.

### list_user_groups
See which groups a specific user belongs to. This helps you understand how security policies are applied.

### list_groups
List all groups in your KnowBe4 account. Use this to audit training assignments and see team organization.

### list_users
List all users in KnowBe4 KMSAT with their names and emails. This is the best way to audit user enrollment.

### get_user_details
Get the specific details for an individual user. This is useful for checking the status of a single team member.

### list_phishing_tests
Get a list of your phishing security tests. It shows the IDs, names, and high-level results for each test.

### get_phishing_test_details
See the specific results for a single phishing test. This includes detailed data on click and report rates.

### list_training_campaigns
Audit your security awareness training campaigns. This helps you check completion rates across the entire organization.

### get_training_campaign_details
Get the specifics for a single training campaign. Use this to see the exact progress of a specific program.

### list_phishing_store_results
See the results for items in your phishing store. This helps you track the performance of various simulation assets.

## Prompt Examples

**Prompt:** 
```
What's our current risk score?
```

**Response:** 
```
Your overall account risk score is **42.5 (Medium)**. This reflects your current phishing performance and training completion rates across the organization.
```

**Prompt:** 
```
Who hasn't finished the Q1 training?
```

**Response:** 
```
I've identified **12 users** who haven't completed the 'Q1 Security Awareness' campaign. Would you like me to list their names and departments?
```

**Prompt:** 
```
How did the last phishing test go?
```

**Response:** 
```
The 'September Phishing Test' had a **4% click rate** and an **81% report rate**. This is a 2% improvement over the previous month.
```

## Capabilities

### Track phishing test results
Get click and report rates for specific simulations.

### Audit training completion
See which departments finished their security awareness courses.

### Pull risk scores
Fetch individual and organizational risk metrics for reporting.

### Verify user enrollment
Check the status of all users in your training programs.

### Manage group assignments
View how security policies are applied to different teams.

## Use Cases

### Auditing training gaps
A security manager needs to know who hasn't finished training. The agent uses list_users to find un-enrolled people and list_training_campaigns to see which ones are lagging.

### Executive risk summaries
An executive wants a risk overview. The agent calls get_account_risk_score and summarizes the current security posture for a monthly report.

### Team policy verification
A team lead wants to see if their group is safe. The agent uses list_user_groups to see who is in the group and then checks their training status.

### Phishing performance analysis
Reporting on a recent test. The agent pulls the click rates from get_phishing_test_details to show the team's improvement compared to last month.

## Benefits

- Get instant risk scores for executive reporting using get_account_risk_score without manually calculating data.
- Track phishing performance across the company by pulling results from list_phishing_tests.
- Verify training coverage for every department by checking enrollment with list_users.
- Monitor compliance progress across different teams using list_training_campaigns.
- Identify high-risk individuals quickly by pulling specific data with get_user_details.
- Audit group assignments to ensure security policies reach the right people using list_groups.

## How It Works

The bottom line is you get a direct conversational interface to your security awareness metrics without leaving your AI client.

1. Subscribe to the Connector on Vinkius.
2. Create an API Key in your KnowBe4 Account Settings under Reporting API.
3. Paste that key into the configuration panel for your AI client.

## Frequently Asked Questions

**Can I use KnowBe4 (KMSAT Reporting) to see who finished their training?**
Yes, it lets your agent check completion status for all users. You can quickly identify which departments or individuals are lagging.

**How does KnowBe4 (KMSAT Reporting) help with executive reports?**
It pulls your overall risk score directly so you can report it without manual math. This makes it easy to provide high-level security updates to leadership.

**Can I track phishing results with KnowBe4 (KMSAT Reporting)?**
Yes, you can get click and report rates for specific simulations. This helps you measure the effectiveness of your security awareness programs.

**Is KnowBe4 (KMSAT Reporting) good for compliance audits?**
It allows you to audit training progress across all departments to ensure you meet regulatory requirements. It provides a clear audit trail of completion rates.

**Does KnowBe4 (KMSAT Reporting) show user groups?**
Yes, it lets you see which groups users belong to. This helps you understand how security policies are applied to different teams and departments.

**Can I get specific user details with KnowBe4 (KMSAT Reporting)?**
Yes, you can pull individual user info to check their specific enrollment status. This is useful for targeted follow-ups with specific team members.

**How do I find my KnowBe4 Reporting API Key?**
Log in to your KnowBe4 console, go to **Account Settings**, find the **Reporting API** section, and click **Enable Reporting API** to generate your token.

**What metrics can I see for phishing tests?**
You can see the number of users who clicked, reported, opened, or entered data in a specific simulation.

**Can I see the risk score for a single department?**
By listing groups and then auditing the risk scores of users within those groups, you can aggregate the security posture of specific teams.