Hook SecurityHook Docs

Understand and configure Autopilot

See what Phishing Autopilot is running, turn it on, and tune how often simulations go out, who receives them, and who gets a preview.

Autopilot runs your phishing program for you. Instead of building a campaign every month, it sends recurring simulations, sometimes called the Campaign of the Month (COTM), on a cadence you choose: Monthly, Bi-monthly, or Quarterly. You come to these pages to see what's running, check what's queued next, and adjust the timing, the audience, and who gets a preview.

Training Autopilot isn't available yet. It appears on the overview as coming soon and isn't clickable, so everything below is about the phishing program.

Read the Autopilot overview

Open Autopilot in the sidebar. The top of the page gives you a readout for each program: whether it's off, running on its cadence, paused, or running but set to sit out the next cycle. Click the phishing readout to open its settings.

Below that, an Upcoming strip lists the next few scheduled simulations with their send date, campaign name, template, and status. Click one to open its preview, or open the full list to see everything queued. See View campaign previews for what a preview shows you.

The Autopilot overview with phishing active, training coming soon, and two scheduled simulations

Turn Phishing Autopilot on

If Autopilot isn't running yet, the phishing page offers a button to enable it, and org admins can use it directly. If your organization is managed by a service provider, you may instead see a message pointing you back to them, and they'll turn it on for you.

The same split applies to editing. Org admins can change the settings below without asking anyone. Under a service provider, they decide whether you get to change settings yourself; when they haven't handed that over, every value is still visible but the controls are inert.

Set how simulations run

Open Autopilot, then Phishing. The How simulations run section holds three settings.

Frequency is how often a simulation goes out: Monthly, Bi-monthly, or Quarterly.

The send and tracking window reads as a sentence with two steppers in it: how many days to spread the sending over, and how many days to keep tracking clicks afterward. Each accepts 1 to 14 days. Out of the box, Autopilot sends everything in a single day and tracks for 3 days after. Widen the send window when a burst of identical mail arriving at once would give the game away.

Audience is either all users or specific groups. There's no "everyone except" option, so to leave a team out, pick the groups you do want. Group member counts are listed to help you judge the size, and a group-based audience needs at least one group checked before it will save.

Autopilot audience settings with specific groups selected

Nothing here saves until you use the Save changes bar

Frequency, the send and tracking window, and the audience are all staged together and committed by the single Save changes bar. Changing a value does not apply it. If you navigate away first, your edits are gone.

Choose who gets notified

The Preview notifications card holds two lists of email addresses: the people who should see each campaign before it sends, and the report contacts for afterward. Both lists are editable.

Type an address and add it, and it appears as a chip you can remove again. These lists behave differently from the settings above: adding or removing an address saves on the spot, so there's no separate button and nothing to commit. Addresses have to be valid and can't be repeated, and a list holds up to 50.

Preview contacts are worth setting up even if you never change anything else. They're your chance to catch a template that lands badly with your workforce before it reaches a few hundred inboxes.

Skip the next cycle

Underneath the settings is a Skip the next cycle switch. Turn it on and Autopilot sits out the next campaign, then picks the cadence back up on its own for the cycle after. It's the right control for a quiet week, a company shutdown, or an incident you don't want to add noise to.

While a skip is set, the campaign it would have sent drops off your upcoming previews, so an empty preview list right after skipping is expected.

A skip only covers that one campaign. Pausing the program outright isn't something you do from these pages, so if your program shows as paused and you want it running again, contact whoever manages your Hook account.

On this page