Set up PhishTriage for a team
Create a team in the portal, invite colleagues with a link, and connect their browsers, so the team’s scans come together in one place. It takes a few minutes per person.
Before you start
- Google accounts. The portal at https://portal.phishtriage.com signs in with Google only. Each colleague joins with the Google address you invite.
- The extension in Chrome, Edge, Brave or Firefox on each colleague’s computer. It works without an account; the team connection is added on top. See Install PhishTriage.
- One team per person. An account can belong to one team. Someone already in another team cannot accept your invitation until an owner of that team removes them.
- No payment. Teams run on the free tier. The portal’s Billing page says “Paid plans aren’t available just yet — the free tier keeps working either way.”
- A shared limit. Analyses are limited per hour for each network address, so colleagues behind one office internet connection share one allowance. See How verdicts work.
Create the team
Done once, by the person who will own the team.
Open https://portal.phishtriage.com and sign in with your Google account. The Dashboard opens.
On the dashboard, find the card Working with colleagues? and press Create a team.
You become the team’s owner, and the Team page opens. The team is named after your Google display name, or your email address if your Google account has no name; Rename, next to the name, changes it.
The card appears only for an account that is not already in a team.
Invite a colleague
Repeat for each person. Only owners can do this.
On the Team page, open the People tab.
Under Invite a person, type your colleague’s Google address and press Create invitation.
The portal shows “Invitation created for” the address, with a join link and a button to copy it.
Copy the link and send it to your colleague yourself, by email or chat. The portal sends no email, and it does not show the link a second time.
- The link works once and expires after 7 days.
- Only the Google address you typed can accept it. Anyone signed in with another account is refused, so a forwarded link is of no use to someone else.
- Invitations not yet accepted are listed under “Invited, not yet joined”, marked “Invitation pending” or “Expired”. Revoke stops a link working at once.
- An address can have one waiting invitation at a time. To send a fresh link, because one expired or the link was lost, revoke the old invitation first and then create a new one.
Your colleague joins the team
Your colleague opens the link, ideally on the computer where they use the extension, and signs in with Google using the invited address.
The page shows “Join” and the team’s name, the address they are signed in as, and three points about what the team will see (see What members are told).
They press Join this team.
“You have joined the team” appears. If they press Not now instead, nothing changes, and the link keeps working until it expires.
If the page says “This invitation is not for this account”, they are signed in with a different Google account, or they already belong to another team. If it says “This invitation cannot be used”, the link has expired, was revoked or was already used: send a new one.
Connect your colleague’s browser
Joining adds the person to the team. Their browser is connected when they log in from the extension.
If the extension is not installed yet, they add it from the Chrome Web Store (Chrome and Brave), Edge Add-ons or Firefox Add-ons.
They click the PhishTriage icon in the browser’s toolbar, then Settings. Further down, a row reads “Not signed in”, with Log in beside it.
phishtriageReadyPage detectedClick Analyze to triage the current page content.▶ Analyze Current Page⚙ SettingsNot signed inSign in to see your scans in the portal and use your plan on every device.Log inThe account row sits under Settings, below the switches (not shown here). Log in is the small grey word at the right of “Not signed in”. They press Log in. A portal tab opens.
In that tab they sign in with Google if asked, using the account that joined the team. The tab then shows “Device linked”.
They open the PhishTriage window again. The account row now begins “Team ·” or reads “Part of a team”, and offers Leave team.
The tab links the browser to whichever Google account is signed in to the portal in that browser. It does not ask for confirmation. If someone else’s account, or a personal one, is signed in there, the browser is linked to that account instead.
- The link from Log in is valid for a short time. If the tab was left open too long and reports an error, press Log in again.
- If the row already reads “Signed in as” your colleague’s name, the browser is already linked to their account, and it joins the team with them. Nothing more is needed.
- Scans made in a browser before it was linked are not moved into the team. They stay under the browser’s earlier anonymous identity and are deleted on the date each was given when it was recorded, which the team’s period does not change (see How long the team’s scans are kept). The server’s log line for each scan is not deleted automatically; see Data handling.
Roles
- Owner. The person who created the team, and anyone an owner promotes. Only owners can open the Team page: it is not in a member’s menu, and its address sends a member to their dashboard. Owners invite and remove people, change roles, set the reporting mode, set how long the team’s scans are kept and rename the team.
- Member. Everyone else. A member sees the team’s dashboard. In either reporting mode it shows totals for the whole team. When the team reports attributed, its lists also show the whole team’s activity from the switch onward, and for each person from when they joined: scans, with sender and subject or page address and the result (Requested Triages); the sites recorded by Background protection and Send full URLs (Visited URLs); evidence captures (Phishing Evidence); and the team’s browsers (Registered Extensions and Connected Devices). None of these lists has a column naming the person. But the portal sends each member’s browser every scan in the list as it was stored: for an email, that includes the recipient address (normally the colleague’s own), the reply-to address, the text, the links and the attachment names; for a page, its address, title, text and links. So a member can work out whose scan a row is and read what was scanned, for example with the browser’s developer tools. Members cannot manage the team.
In People, Make owner and Make member change a person’s role. A team always keeps at least one owner, so the last owner cannot be made a member or removed.
What the team sees
Aggregate and attributed reporting
The Reporting mode panel above the Team page’s tabs shows the current mode. Every team starts in aggregate.
- Aggregate (the default). No per-person activity is shown anywhere. The scan list, the per-person breakdown, and the person and scan-count columns for devices are withheld, and the portal says so where they would be. Totals, trends and counts by verdict cover the whole team.
- Attributed. An owner presses Turn on attributed reporting, reads what changes, and presses Turn on attributed reporting again. From that moment, scans are shown per person, but only scans recorded from then on. Activity from before the switch is never shown per person, then or later.
- Switch to aggregate hides per-person detail again at once. Turning attributed reporting back on starts a new window from that moment; the time in between is never shown per person.
In either mode, the team’s lists and totals include a member’s scans only from the moment that member joined — for the owner who created the team, the moment it was created. Scans recorded before then are not shown to the team or counted for it, and while the person is in the team they no longer appear on that person’s own dashboard either. In aggregate mode every list on the dashboard, a person’s own scans included, shows “Not shown”.
The mode also covers evidence. The screenshots and page HTML that Keep evidence of phishing sends, for web pages that come back phishing or suspicious, are listed on the dashboard under Phishing Evidence. In aggregate mode that list is withheld from everyone, owners included. In attributed mode every member of the team sees the captures made since the switch, and for each person since they joined; only an owner can confirm or reject each one.
What members are told
Before your colleague presses Join this team, the page sets out three points:
- that scans already recorded on their account become part of what the team can see, and that nothing is copied or deleted, only who the scans are shown to changes;
- that what the team sees depends on its reporting mode: totals only in aggregate, and in attributed, individual rows from the date the team turned that on;
- that they cannot manage the team unless an owner makes them one.
The first point describes more than the portal shows. As set out above, the team sees and counts a member’s scans only from the moment they joined.
The Team page
Owners see four tabs, in this order:
- Scans: the team’s scans since attributed reporting was turned on and since each person joined, with time, type, target, verdict, risk, and device or person. Downloads checked by File protection are listed too, by file name. It can be filtered by verdict, type and device, and searched. An email or page row opens the full result: summary, scores and indicators. In aggregate mode the whole list is withheld.
- Reporting: phishing caught, scans processed, threat rate, fleet coverage, seats in use, a chart of scans by verdict, scan volume by person, and impersonated brands. In aggregate mode, scan volume by person becomes a single figure for the whole team. Periods are 7 days, 30 days, 90 days and 12 months. A period longer than the team keeps scans cannot be chosen, and the tab says why. Scans recorded before 4 October 2026 keep the 90 days they were given, so for now a 12-month report does not reach a full year back; the tab gives the day the team’s scans in the period start. Members can keep their own scans for a shorter time, so their part of older days can be missing; the tab notes this.
- Devices: each browser connected to the team, with browser, enrolment date, last check-in, and a status of Active, Idle or Stale. A browser checks in only when it scans or reports a visit, so one that is installed but unused can show as Stale. Person and scan count appear only in attributed mode. Owners can rename a device in either mode and, in attributed mode, record who uses it; recording a person does not move the device’s scans to them.
- People: members, their roles and pending invitations, as described above.
How long the team’s scans are kept
Above the Team page’s tabs, Scan history shows the team’s period. To change it, an owner presses Change, picks a period next to Keep this team’s scans for, from 7 days to 1 year or the service default, and confirms with the button that names it, for example Keep for 30 days.
- Default. 365 days on the hosted service, for scans recorded since 4 October 2026.
- What it covers. Scan, visit and file-check records of every member of the team, and of every device the team set up. Each record is given its deletion date when it is written, from the period in force at that moment.
- Members. On their dashboard, under Your data, a member can choose the team’s period or a shorter one for their own scans, never a longer one. It covers scans from devices linked to their account; devices the team set up follow the team’s period. If an owner later sets a period shorter than a member’s, the team’s applies to that member’s new records. Owners are not shown the period a member chooses.
- Not retroactive. A change applies to records written after it. A shorter period does not delete stored scans early, and a longer one does not keep them longer. Scans and visit records written before 4 October 2026 keep the 90 days they were given.
- Not covered. Evidence captures keep their own 12-month or 30-day clock. The server’s log is not deleted automatically, and device and account records have no automatic expiry. Each change to a period is recorded (who, from what to what, and when); that record has no expiry, and Delete my scan history does not remove it.
The full rules are under Data handling.
Larger rollouts
For larger rollouts, talk to us about Enterprise: see pricing, or contact us. Two things are offered with Enterprise:
- Managed rollout: installing and configuring the extension through browser policy, with enrolment keys that join devices to your team without anyone signing in. The keys are in the Enrolment keys section of the Devices tab. The steps, browser by browser, are in Roll out PhishTriage by browser policy.
- Self-hosting, on request: running the backend on your own infrastructure.
Leaving and removing
When a member presses Leave team
Leave team, in the extension’s account row, disconnects that one browser:
- It clears the browser’s identity (its device ID, pseudonymous ID, team and sign-in) and at once registers the browser again as a new, anonymous device with no team. The row then reads “Not signed in”. (On a browser given an enrolment key by policy, the new registration joins the team again while that key is still valid.)
- It does not remove the person from the team. Their portal account stays a member until an owner removes it, and any other browser they linked stays connected.
- It deletes nothing on the server. Scans already recorded stay where they are and are deleted on the date each was given when it was recorded (see How long the team’s scans are kept). The server’s log line for each scan is not deleted automatically; see Data handling. The browser’s old entry stays on the Devices tab, where it stops checking in.
- It does not reset the extension’s settings or its on-device list of feedback presses.
A member cannot leave the team from the portal. An owner removes them.
What an owner can do
- Remove a person, in People. This deletes nothing: their sign-in and their scan history stay theirs. Browsers they linked to their own sign-in leave the team with them. From then on the team no longer sees or counts the scans and phishing evidence recorded under their account, including those from while they were a member. Any device assigned to them on the Devices tab is unassigned; one that was not linked to their sign-in stays in the team.
- Revoke an invitation that has not been accepted.
- Change roles with Make owner and Make member.
What the portal cannot do
- Remove a device from a team. The Team page says so: “A device cannot be removed from a team here.”
- Delete another person’s scan history. Each person can delete their own with Delete my scan history on their dashboard. It removes only their own records, at once, and cannot be undone.
- Delete an account or a team. There is no button for either.
For any deletion, write to privacy@phishtriage.com. For a device, include the first eight characters of its Device ID (in the PhishTriage window under Settings, then Advanced), the browser, and roughly when the extension was installed.