They Asked Us To Build An LMS.
We Ended Up Building A Platform That Proves Training Actually Works.
And completing a course doesn't necessarily make someone more security-aware.
5
Core modules
2
Integrations
RBAC
Four-level roles






Project Snapshot
- Industry
- Cybersecurity Training
- Platform
- Enterprise Learning Management System
- Focus
- Automated Security Awareness & Behavioral Validation
- Integrations
- GoPhish · Colossyan
- Core Modules
- • Course Management• User Management• Security Training• Analytics• Role Management
The brief
At first, it sounded like a standard Learning Management System.
Create courses. Manage users. Track progress. Generate reports.
But after understanding the client's business, we realized they weren't selling courses.
They were selling safer employees.
And completing a course doesn't necessarily make someone more security-aware.
The platform had to answer one question: Did the training actually change behavior?
Watching Videos Isn't The Same As Learning
Most LMS platforms stop at completion certificates.
Someone watches a few videos. Clicks "Complete." Receives a certificate. Everyone assumes the training worked.
But cybersecurity doesn't work that way.
People only learn if they recognize threats when they encounter them in the real world.
That completely changed how we designed the platform.
Instead of measuring course completion, we built a system that measures behavioral change.
Engineering Note
We built a full course management system with lesson delivery, progress tracking, completion monitoring, and automated lifecycle management to support enterprise-scale learning.

Instead of measuring course completion, we built a system that measures behavioral change.
The Real Test Starts After The Course Ends

This became the most interesting part of the project.
As soon as a training program finishes, the system automatically prepares a phishing simulation.
Employees receive a realistic phishing email without knowing it's a test.
Their actions become measurable outcomes. Did they ignore it? Report it? Or click the malicious link?
Now administrators know whether the training actually worked instead of simply assuming it did.
What would normally require weeks of manual coordination happens automatically in the background. The platform schedules campaigns, launches them, and associates results with the completed training lifecycle.
Behind The Scenes
Integrated GoPhish, automated campaign scheduling with cron jobs, synchronized user groups, and built rollback mechanisms to keep both systems in sync.
Training Hundreds Of Employees Shouldn't Mean Managing Hundreds Of Accounts
Large organizations don't onboard users one at a time.
They work with departments. Teams. Business units. Different managers. Different responsibilities.
So instead of creating a flat user list, we designed a hierarchical permission system.
Administrators oversee the entire platform. Contributors manage organizations. Group leaders manage their own teams. Subscribers simply focus on learning.
Every person sees only the information relevant to their role, making the platform significantly easier to manage as organizations grow.
Engineering Note
Designed a four-level RBAC system with dedicated dashboards, scoped permissions, protected routes, and role-aware APIs.


Subscription management with partners, organizations, groups, and employees across a four-level role hierarchy.
Courses Should Run Themselves
Course lifecycle automation


Campaign details with launch dates, time zones, group assignments, and automated lifecycle tracking.
Engineering Note
Built scheduled automation services that activate courses, expire content, sequence training, and trigger follow-up simulations without manual intervention.
Another problem appeared during discovery.
Training coordinators were manually launching courses, closing enrollments, and scheduling follow-up activities.
The work was repetitive. And mistakes were common.
So we automated the course lifecycle.
Courses automatically become available on launch dates. They expire when training windows end. Follow-up phishing simulations are scheduled automatically.
Administrators spend their time improving training instead of managing calendars.
Great Content Deserves Great Delivery
The client already used Colossyan to produce interactive training videos.
Rather than forcing content creators to upload files into another system, we integrated directly with their existing workflow.
Training creators simply paste a Colossyan lesson link. The platform embeds the lesson automatically.
Employees enjoy a seamless learning experience without ever leaving the LMS.
Sometimes the best integration isn't adding another feature. It's removing unnecessary work.
Engineering Note
Replaced the previous H5P upload flow with embedded Colossyan lessons using secure iframe integration and responsive rendering across devices.

Measuring Progress Is Only Half The Story
Enterprise customers needed more than completion percentages.
They wanted visibility. Which departments are improving? Which teams repeatedly fail phishing tests? Which managers need additional coaching?
The platform combines learning progress, campaign performance, and behavioral results into one reporting system, allowing organizations to continuously improve their security awareness programs instead of treating training as a yearly checkbox.
Behind The Scenes
Built centralized reporting backed by React Query, real-time progress tracking, campaign analytics, and organization-wide learning insights.

The Outcome
Organizations create courses.
Employees complete interactive learning.
The platform automatically validates that learning through real phishing simulations.
Managers receive meaningful insights.
Administrators oversee the entire training lifecycle from one place.
What started as another Learning Management System became a complete cybersecurity training ecosystem.
Instead of measuring who finished a course, the platform measures whether the training actually made employees safer.
Explore The Demo
Experience the platform from the perspective of administrators, managers, and learners, and see how training, automation, phishing simulations, and analytics work together inside one connected cybersecurity learning platform.