phishtriage

For security teams · 9 minutes

Set up PhishTriage for a team

Create a team in the portal, invite colleagues with a link, and connect their browsers, so the team’s scans come together in one place. It takes a few minutes per person.

Before you start

Create the team

Done once, by the person who will own the team.

  1. Open https://portal.phishtriage.com and sign in with your Google account. The Dashboard opens.

  2. On the dashboard, find the card Working with colleagues? and press Create a team.

    You become the team’s owner, and the Team page opens. The team is named after your Google display name, or your email address if your Google account has no name; Rename, next to the name, changes it.

The card appears only for an account that is not already in a team.

Invite a colleague

Repeat for each person. Only owners can do this.

  1. On the Team page, open the People tab.

  2. Under Invite a person, type your colleague’s Google address and press Create invitation.

    The portal shows “Invitation created for” the address, with a join link and a button to copy it.

  3. Copy the link and send it to your colleague yourself, by email or chat. The portal sends no email, and it does not show the link a second time.

Your colleague joins the team

  1. Your colleague opens the link, ideally on the computer where they use the extension, and signs in with Google using the invited address.

    The page shows “Join” and the team’s name, the address they are signed in as, and three points about what the team will see (see What members are told).

  2. They press Join this team.

    “You have joined the team” appears. If they press Not now instead, nothing changes, and the link keeps working until it expires.

If the page says “This invitation is not for this account”, they are signed in with a different Google account, or they already belong to another team. If it says “This invitation cannot be used”, the link has expired, was revoked or was already used: send a new one.

Connect your colleague’s browser

Joining adds the person to the team. Their browser is connected when they log in from the extension.

  1. If the extension is not installed yet, they add it from the Chrome Web Store (Chrome and Brave), Edge Add-ons or Firefox Add-ons.

  2. They click the PhishTriage icon in the browser’s toolbar, then Settings. Further down, a row reads “Not signed in”, with Log in beside it.

    The account row sits under Settings, below the switches (not shown here). Log in is the small grey word at the right of “Not signed in”.
  3. They press Log in. A portal tab opens.

  4. In that tab they sign in with Google if asked, using the account that joined the team. The tab then shows “Device linked”.

  5. They open the PhishTriage window again. The account row now begins “Team ·” or reads “Part of a team”, and offers Leave team.

The tab links the browser to whichever Google account is signed in to the portal in that browser. It does not ask for confirmation. If someone else’s account, or a personal one, is signed in there, the browser is linked to that account instead.

Roles

In People, Make owner and Make member change a person’s role. A team always keeps at least one owner, so the last owner cannot be made a member or removed.

What the team sees

Aggregate and attributed reporting

The Reporting mode panel above the Team page’s tabs shows the current mode. Every team starts in aggregate.

In either mode, the team’s lists and totals include a member’s scans only from the moment that member joined — for the owner who created the team, the moment it was created. Scans recorded before then are not shown to the team or counted for it, and while the person is in the team they no longer appear on that person’s own dashboard either. In aggregate mode every list on the dashboard, a person’s own scans included, shows “Not shown”.

The mode also covers evidence. The screenshots and page HTML that Keep evidence of phishing sends, for web pages that come back phishing or suspicious, are listed on the dashboard under Phishing Evidence. In aggregate mode that list is withheld from everyone, owners included. In attributed mode every member of the team sees the captures made since the switch, and for each person since they joined; only an owner can confirm or reject each one.

What members are told

Before your colleague presses Join this team, the page sets out three points:

The first point describes more than the portal shows. As set out above, the team sees and counts a member’s scans only from the moment they joined.

The Team page

Owners see four tabs, in this order:

How long the team’s scans are kept

Above the Team page’s tabs, Scan history shows the team’s period. To change it, an owner presses Change, picks a period next to Keep this team’s scans for, from 7 days to 1 year or the service default, and confirms with the button that names it, for example Keep for 30 days.

The full rules are under Data handling.

Larger rollouts

For larger rollouts, talk to us about Enterprise: see pricing, or contact us. Two things are offered with Enterprise:

Leaving and removing

When a member presses Leave team

Leave team, in the extension’s account row, disconnects that one browser:

A member cannot leave the team from the portal. An owner removes them.

What an owner can do

What the portal cannot do

For any deletion, write to privacy@phishtriage.com. For a device, include the first eight characters of its Device ID (in the PhishTriage window under Settings, then Advanced), the browser, and roughly when the extension was installed.