Overview
RansomLeak for Webex delivers security awareness training reminders where your people already work. When a course or campaign is assigned, falls due, or is completed, the RansomLeak bot sends a direct message with a one-click link to the lesson, so the reminder is one tap from the action instead of one more unread email.
- A direct message, never a space post
- One-click deep link to the lesson
- Nothing for employees to install
- Self-service mute, per person
Only people who actually have training outstanding are messaged. The bot has no reason to contact anyone else, and it never posts to a space, so it adds nothing to team channels.
Connect in one click
One administrator connects the organization. There is no per-user rollout, no app to push through Control Hub, and no manifest to upload.
-
In RansomLeak, go to Settings → Integrations → Webex and select Connect Webex.
-
You are redirected to Webex to sign in and authorize. RansomLeak requests a single least-privilege scope, described below.
-
RansomLeak records which Webex organization you connected and returns you to the integration page. That is the whole setup.
| Scope | Why it is requested |
|---|---|
spark:people_read | Identify which Webex organization is being connected, so reminders stay scoped to it. |
spark:kms | Added automatically by Webex to every authorization. RansomLeak does not request it. |
The administrator token is used once, to read the organization identity, and is then discarded. RansomLeak stores no Webex credential for your tenant.
What triggers a reminder
Reminders follow the training lifecycle an employee is already in. Each one is a card with the relevant detail and a button that opens the lesson directly.
- A campaign or learning path is assigned
- A deadline is approaching
- A deadline is imminent or lands tomorrow
- A campaign or learning path is completed
- A badge is awarded
- A simulated phishing email is reported
Reminder copy follows your tenant's default language, so employees read them in the same language as the rest of RansomLeak.
How employees opt out
Opting out is self-service and immediate. No ticket, no administrator involvement.
muteunmute
Every reminder also carries a Mute reminders button, which does the same thing in
one tap. Muting applies to that one person only, and can be reversed at any time by sending
unmute to the bot.
Permissions and data handling
The integration is deliberately thin. It reads what it needs to reach the right person and stores nothing about your Webex content.
| Data | How it is handled |
|---|---|
| Your Webex organization identifier | Stored so reminders stay scoped to the organization you connected. |
| The employee's work email | Used to address the direct message. It already exists in your RansomLeak tenant. |
| Messages, spaces, meetings, files | Never read. The integration has no scope that would allow it. |
| The administrator's access token | Used once to read the organization identity, then discarded. Never stored. |
- Recipients confirmed to be in your organization
- Never posts to spaces
- Disconnect stops reminders immediately
No data is shared with third parties, and no per-user data beyond the work email is used to deliver a reminder. For how RansomLeak handles data, see the privacy policy and the security and compliance page.
Frequently asked questions
Does RansomLeak integrate with Webex?
Yes. An administrator connects your Webex organization once from RansomLeak, and from then on the RansomLeak bot direct-messages each employee when they have security awareness training assigned or coming due. Every reminder carries a one-click link straight to the lesson. The bot only messages people who have training outstanding, and it never posts to spaces.
Do employees have to install anything?
No. Unlike a Microsoft Teams app, there is nothing to deploy to your users and nothing for them to approve. Webex bots can start a direct message on their own, so once an administrator connects the organization, reminders simply arrive. Employees never see an install prompt.
What OAuth scopes does the connection request?
One: spark:people_read. It is used solely to identify which Webex organization is being connected, so reminders are scoped to your organization and nowhere else. Webex automatically adds spark:kms, its own key management scope, to every authorization. The administrator token is used once to read the organization identity and is then discarded, not stored.
Can the bot message people outside our organization?
No. On first contact with any employee, RansomLeak confirms the recipient belongs to the Webex organization you connected. If they do not, the pairing is refused and no further messages are sent to that address. Reminders are also only ever sent to people who already exist in your RansomLeak tenant with training assigned.
How does an employee stop the reminders?
Two ways, both instant and self-service. Every reminder card carries a Mute reminders button, and an employee can also send the bot the word mute at any time. Sending unmute resumes them. Muting is per person, so one employee opting out never affects anyone else.
How do I disconnect it?
Disconnecting in RansomLeak forgets the stored organization link and stops all Webex reminders immediately. Because the connection stores no per-tenant credential, there is nothing left behind on the Webex side to revoke, though you can also remove the app from your organization in Webex Control Hub.
Need a hand?
Email support@ransomleak.com and we will help you connect Webex to your tenant.