Overview
The KnowBe4 integration syncs your organization’s security awareness training data: training campaigns, completion status, phishing simulation results, and user risk scores. LowerPlane uses read-only access via the KnowBe4 Reporting API.Prerequisites
How to Get Your Reporting API Key
Log in to KnowBe4
Log in to the KnowBe4 console with your admin account.
Enable the Reporting API
Under Reporting API, toggle Reporting API Access to enabled, then click Create New API Token.
Connecting in LowerPlane
- Go to Settings > Integrations in LowerPlane
- Find KnowBe4 under Security Awareness Training
- Enter your Reporting API Key and select your Server Region
- Click Connect
What LowerPlane Collects
Training Campaigns
All training campaigns with enrollment counts, completion rates, and due dates.
User Enrollments
Per-user training enrollment status: assigned, in progress, completed, or overdue.
Phishing Simulations
Phishing campaign results including click rates, report rates, and failure counts per user.
User Risk Scores
KnowBe4 risk scores per user, used to identify high-risk individuals for targeted training.
Compliance Mapping
The KnowBe4 integration provides evidence for:| Framework | Controls | What It Proves |
|---|---|---|
| SOC 2 | CC1.4, CC1.5 | Security awareness training is provided to personnel |
| ISO 27001 | A.6.3, A.7.2.2 | Information security awareness, education, and training |
| HIPAA | 164.308(a)(5) | Security awareness and training program |
| PCI-DSS | 12.6 | Security awareness training for all personnel |
| GDPR | Art. 39(1)(b) | Awareness-raising and training of staff involved in processing |
| NIST CSF | PR.AT-1, PR.AT-2 | All users and privileged users are informed and trained |
Tests Powered by This Integration
Once connected, LowerPlane automatically evaluates:- Infosec training should be completed — Verifies all employees have completed required security training
- Annual security training completion rate should meet threshold — Checks org-wide completion rates
- Phishing simulation training should be conducted — Confirms phishing campaigns are run periodically
FAQ
Which KnowBe4 API does LowerPlane use?
Which KnowBe4 API does LowerPlane use?
LowerPlane uses the Reporting API (read-only). It does not use the User Event API or KMSAT API. No write access is required.
How often does LowerPlane sync?
How often does LowerPlane sync?
Training data syncs every 24 hours by default. You can trigger a manual sync from the integration settings page.
What if some users don't have email matches?
What if some users don't have email matches?
LowerPlane matches KnowBe4 users to your personnel directory by email. If a KnowBe4 user’s email doesn’t match any person in LowerPlane, the enrollment is still tracked but won’t appear in the person’s compliance profile. Ensure emails are consistent across both systems.
Can I connect multiple KnowBe4 accounts?
Can I connect multiple KnowBe4 accounts?
Yes. If you have separate KnowBe4 accounts for different regions or subsidiaries, you can connect each one as a separate integration instance.