empowsec Notifications: Right Alert to the Right Person

Elena Vasquez··8 min read
Managing notification preferences

Notifications are often an afterthought in SaaS products - a system that fires emails at everyone and lets the result land wherever it lands. The outcome is predictable: administrators get buried in low-priority alerts they ignore, managers miss the compliance digest that actually applies to their team, and end users receive reminders for things they already completed. A notification system that does not distinguish between audiences, priority levels, or delivery preferences creates noise rather than information. empowsec is designed differently, with a role-aware notification system that targets each alert to the right person, allows individual delivery preferences, and protects critical notices that the program depends on from being silenced.

This article covers the structure of the empowsec notification system, who receives what, which preferences users can control, why some notifications cannot be disabled, and how the system supports both email and in-app delivery.

Role-Aware Notification Sets

empowsec organizes notifications by role, because the information that matters to a department manager is different from the information that matters to a company admin, and both are different from what a reseller admin or an end user needs. Sending every notification to every role creates confusion and trains people to ignore the alerts from the platform. Role-aware sets prevent this: each notification is associated with the roles that need to see it, and only those roles receive it.

End users - the employees going through training and receiving phishing simulations - receive notifications relevant to their own activity: when a new assignment arrives, when a due date is approaching, when they receive a phishing debrief, and when their account is subject to a change that affects them. Their notification set is deliberately narrower than what an admin sees, because their role is narrower. They need to know what action is required of them; they do not need operational or billing alerts about the organization.

Company admins receive the broader operational picture: phishing campaign summaries, compliance digests, billing events such as invoice generation, payment failure, and seat overage warnings, upcoming true-up previews, and escalation notices when overdue training has been flagged. These are the signals that a platform administrator needs to keep the program running and the organization in good standing.

Department managers receive a scoped version of the admin picture: the weekly department training digest showing completion status and outstanding assignments for their specific team, and escalation alerts for their own employees. They see what they need to manage their department, without the billing or platform-wide operational alerts that are not their concern.

Reseller admins and super admins have notification sets appropriate to their cross-company scope - alerts about the companies they manage, seat usage, and operational events across the platform they oversee.

User-Controlled Preferences: Email or In-App

Within the notifications they are eligible to receive, users can control their delivery preferences. For each notification type, the preference can be set to email delivery, in-app delivery, both, or neither - where 'neither' is an option. This allows individuals to tune the system to their own working style without losing access to the information entirely.

An administrator who prefers to check the empowsec portal daily might turn off email delivery for the weekly digest and read it in-app instead. An employee who is rarely at their desk might prefer email for training reminders so they arrive in the channel they monitor most reliably. A manager who already uses the empowsec app on mobile might set in-app delivery for department alerts and rely on push notifications rather than a separate email.

The combination of email and in-app delivery options is not just a convenience feature - it is a recognition that different people have different communication habits, and a notification that reaches a person through their preferred channel is more likely to be acted on than one that arrives through a channel they check infrequently. Giving users agency over delivery preferences reduces opt-out pressure and improves the signal-to-noise ratio for each individual.

app.empowsec.com / settings / notifications
Notification preferences
Choose how each alert reaches you. Some notices cannot be turned off.
New assignment
Assignment due soon
Phishing debrief Required
Weekly compliance digest
Phishing campaign summary
Payment failed Required
Seat overage warning
The notification preferences panel lets users toggle each alert on or off for their role. Notices marked Required cannot be disabled - they are part of critical program workflows.

Notification Types Across the Platform

The range of notification types reflects the breadth of the empowsec platform. On the training side, the system handles new assignment notifications when a course is assigned, due-soon reminders as deadlines approach, overdue alerts when an assignment has not been completed on time, and training escalation notices that go to managers when their team members fall behind. The weekly compliance digest pulls these together into a summary for admins and department managers.

On the phishing side, the phishing campaign summary notifies admins when a campaign concludes, providing a top-level view of results. The phishing debrief notification is the educational touchpoint that each participant receives after a simulation, explaining the red flags they should have spotted. This one is always delivered regardless of preferences, because it is the educational completion of the simulation exercise.

Billing and operational notifications cover invoice generation, payment failure, seat overage warnings when the number of active users approaches or exceeds plan limits, and upcoming true-up preview alerts so administrators are not surprised by reconciliation charges. These keep the administrative side of the platform running smoothly without requiring admins to log in and check billing status manually.

Account-level notifications cover account deletion requests and their resolution - when a user has requested deletion, and when that request has been processed. Affiliates have their own notification set covering commission events relevant to their activity. The breadth of types reflects the intent that empowsec notifications are a complete operational communication system, not a supplement to external monitoring.

Critical Alerts That Cannot Be Turned Off

Some notifications are designated as required and cannot be disabled through preference settings. The phishing debrief is the clearest example: it is an educational notification that empowsec deliberately prevents users from opting out of, because the debrief is the closing educational step of the simulation program. An employee who opted out of debriefs would receive the simulation but not the learning that is supposed to follow from it, which defeats the purpose of running the simulation.

Payment-failed notifications are required because missing a payment failure alert could result in service disruption that the administrator was not aware of. The same logic applies to account deletion notices: when an account deletion request has been submitted or processed, the relevant parties need to know, and this is not something that can be safely opted out of.

The distinction between optional and required notifications is an architectural choice that reflects the difference between notifications of convenience and notifications of obligation. The platform distinguishes between 'you might want to know this' (optional, user-controlled) and 'you need to know this for the program or the service to function as intended' (required, always delivered). This distinction helps users understand why a notification is present even when they have reduced their other alerts, and it prevents the kind of support issue that arises when someone says they were not aware of a critical event because they had turned off all emails.

Notification Delivery and Reliability

empowsec delivers notifications through two channels: email and in-app. Email delivery uses the platform's mail infrastructure, which is built for reliable transactional delivery. In-app notifications appear within the empowsec portal and, for mobile app users, can be surfaced through push notifications on their device. The combination of channels means that even users who check email infrequently can be reached through the in-app channel, and vice versa.

Delivery is tracked for notifications where tracking matters operationally. Phishing debriefs, for example, have tracked delivery so administrators can confirm the educational loop was closed for each participant. This tracking record serves both operational assurance and compliance documentation purposes - it contributes to the audit trail showing that the educational component of the simulation program ran to completion.

Tip
Review your notification preferences after the first month of using empowsec. The defaults are a good starting point, but tuning delivery channels to match how your team actually works reduces noise and ensures alerts reach the right people reliably.

What This Means for Your Team

  • Role-aware notification sets mean end users, company admins, department managers, reseller admins, and affiliates each receive only the alerts relevant to their role - reducing noise for everyone.
  • Per-type delivery preferences let individuals choose email, in-app, or both for each notification, so alerts arrive through the channel each person actually monitors.
  • Required notifications - including the phishing debrief, payment-failed, and account-deletion notices - cannot be disabled, protecting the educational and operational integrity of the program.
  • Named notification types include new assignment, due-soon reminder, training escalation, weekly compliance digest, phishing campaign summary, billing alerts, seat overage warning, and true-up preview.
  • Tracked delivery for critical notifications provides an audit trail confirming the educational loop was closed for each simulation participant.
Share: