Overview

The KnowBe4 integration syncs your organization’s security awareness training data: training campaigns, completion status, phishing simulation results, and user risk scores. LowerPlane uses read-only access via the KnowBe4 Reporting API.

Prerequisites

Ensure you have admin privileges on your KnowBe4 account. Only admins can enable the Reporting API and generate API tokens.

How to Get Your Reporting API Key

1

Log in to KnowBe4

Log in to the KnowBe4 console with your admin account.
2

Open Account Settings

Navigate to the Account Settings page from the top-right menu.
3

Expand Account Integrations

In the left menu, expand the Account Integration section.
4

Enable the Reporting API

Under Reporting API, toggle Reporting API Access to enabled, then click Create New API Token.
5

Copy your API token

Copy the displayed API token. This is your Reporting API Key.
The token is only shown once. Store it securely. If you lose it, you’ll need to generate a new one.
6

Note your server region

Note your KnowBe4 server location — this is the geographic region you selected when your account was created. You can find it on the login page or in Account Settings.
RegionServer
USUnited States
EUEuropean Union
UKUnited Kingdom
DEGermany
CACanada

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane
  2. Find KnowBe4 under Security Awareness Training
  3. Enter your Reporting API Key and select your Server Region
  4. Click Connect
LowerPlane will immediately begin syncing your training data.

What LowerPlane Collects

Training Campaigns

All training campaigns with enrollment counts, completion rates, and due dates.

User Enrollments

Per-user training enrollment status: assigned, in progress, completed, or overdue.

Phishing Simulations

Phishing campaign results including click rates, report rates, and failure counts per user.

User Risk Scores

KnowBe4 risk scores per user, used to identify high-risk individuals for targeted training.

Compliance Mapping

The KnowBe4 integration provides evidence for:
FrameworkControlsWhat It Proves
SOC 2CC1.4, CC1.5Security awareness training is provided to personnel
ISO 27001A.6.3, A.7.2.2Information security awareness, education, and training
HIPAA164.308(a)(5)Security awareness and training program
PCI-DSS12.6Security awareness training for all personnel
GDPRArt. 39(1)(b)Awareness-raising and training of staff involved in processing
NIST CSFPR.AT-1, PR.AT-2All users and privileged users are informed and trained

Tests Powered by This Integration

Once connected, LowerPlane automatically evaluates:
  • Infosec training should be completed — Verifies all employees have completed required security training
  • Annual security training completion rate should meet threshold — Checks org-wide completion rates
  • Phishing simulation training should be conducted — Confirms phishing campaigns are run periodically

FAQ

LowerPlane uses the Reporting API (read-only). It does not use the User Event API or KMSAT API. No write access is required.
Training data syncs every 24 hours by default. You can trigger a manual sync from the integration settings page.
LowerPlane matches KnowBe4 users to your personnel directory by email. If a KnowBe4 user’s email doesn’t match any person in LowerPlane, the enrollment is still tracked but won’t appear in the person’s compliance profile. Ensure emails are consistent across both systems.
Yes. If you have separate KnowBe4 accounts for different regions or subsidiaries, you can connect each one as a separate integration instance.