What it is
The Security Champions program designates employees as multipliers of the security culture in each department or group. They carry out missions, go through a training track, send signals to the security team, and appear on a wall. The program has a maturity index (mapped to the SANS Awareness Maturity Model), goals, and a visibility policy that protects privacy.
It lives in Security Champions (/champions), organized into tabs. It depends on the feature being enabled for the tenant.
Concepts
- Champion: a designated employee, with a scope (department or group), a tier based on program XP (rookie → champion → senior → lead), and a status.
- Suggested candidates: the platform ranks candidates by department based on behavior (who reports, who aces quizzes, who keeps a streak).
- Maturity index combines coverage, activity, and training into a score from 0 to 100, with monthly history.
- Missions: tasks assigned to champions, with an evidence submission that you validate.
- Training is a track of modules that, once completed, produces a certificate.
- Signals — a direct line from the champion to the security team (risk observations, culture notes, or suggestions).
- Visibility is the policy that controls what the champion can see about their group. Small groups are aggregated so no one gets de-anonymized.
How an employee becomes a champion
- In Candidates or Champions, you designate the employee by choosing the scope.
- They receive an invitation and, in the portal (
/c/champion), accept (or decline). - Once accepted, they start running missions, doing the training, sending signals, and counting toward coverage and maturity.
Appointment is opt-in: no one becomes a champion without confirming.
The dashboard tabs
| Tab | What it shows |
|---|---|
| Dashboard | Maturity index, monthly trend, program report in PDF |
| Champions | The list, with tier, status, XP, and activities; designate/edit/remove |
| Candidates | Suggestions ranked by department |
| Goals | Program goals with metrics |
| Missions | Create missions and validate the submitted evidence |
| Signals | The signals received from champions |
| Settings | Visibility policy and program members |