Role-Based Learning is a way to deliver security awareness training that fits each employee’s job. Instead of giving everyone the same general course, it matches the depth of training to the level of risk each role carries.
People who can approve payments, grant access to systems, or handle sensitive data face more targeted attacks than most coworkers. Role-Based Learning gives these people training built around the specific attacks most often aimed at them. Nimblr sums up the idea in one line: high risk roles demand high impact training.
Attackers do not target every employee the same way. They go after the people who can move money, open access to systems, or expose data quickly. Training that ignores these differences leaves the highest risk roles underprepared.
Consider three common examples:
Finance: An accounts payable clerk receives an invoice from a known supplier with new bank details. The invoice is fake.
IT Helpdesk: A support agent gets a call from someone who claims to be a coworker locked out of their account and asks for a Multi Factor Authentication (MFA) reset.
Executives: A finance manager receives a voice message that sounds exactly like the CEO, asking for an urgent transfer. The voice is a deepfake.
A general course cannot cover each of these scenarios in depth. Role-Based Learning can, because each person receives the training that matches the attacks they are most likely to face.
Learn more about our role-based training →
Employees answer two short questions at the end of a regular Nimblr course. Nimblr uses the answers to assign one or more learning tracks. From that point on, training adapts to the employee automatically.
Question 1: What best describes your day to day work? (choose one)
Options include finance, accounting, or procurement; sales or business development; customer service or support; operations, logistics, or production; HR, people, or payroll; marketing, communications, or PR; IT, engineering, or technical operations; leadership, management, or strategy; and something else.
Question 2: Which of these are part of your job? (choose all that apply)
Options include approving payments or invoices, handling personal or customer data, dealing with suppliers or vendors, leading a team, admin access to IT systems, writing code or accessing production, being a public face of the company, and none of these options.
Nimblr Role-Based Learning includes six tracks, each built for a role that attackers target often: Finance, Executives, HR & Payroll, IT Helpdesk, IT Admins, and DevOps.
Together, the tracks include more than 25 courses that cover real attack methods such as invoice fraud and deepfake voice and video scams. Nimblr adds new role specific courses as attack methods change.
| Track | Who is it for? | Example course topics |
| Finance | Accounting, procurement and anyone who can approve or start payments | Business E-mail Compromise (BEC), invoice fraud and payment redirection, phone fraud aimed at finance teams |
| Executives | Senior leaders, directors, and top executives | NIS2 accountability for leaders, ISO 27001 for management, spear phishing, deepfake voice and video fraud, protecting your digital footprint |
| HR and Payroll | People operations, payroll, and anyone who manages employee records | Direct deposit change fraud, new hire onboarding as an attack path, protecting employee data |
| IT Helpdesk | Support staff who handle password resets and identity checks | Vishing and social engineering on the helpdesk, MFA reset fraud, remote access tool abuse |
| IT Admins | System administrators and anyone with privileged or cloud access | Device code phishing and OAuth token theft, attacks on privileged accounts, spotting privilege escalation and lateral movement |
| DevOps | Developers, engineers, and anyone with access to code repositories or pipelines | Secure coding, cloud security, secure backend development, secrets management, supply chain attacks, CI/CD pipeline security |
More relevant training. Employees see content that matches their daily risk, which makes training more engaging.
Stronger protection where it matters most. The highest risk roles receive the deepest and most targeted training.
No added admin work. Role-Based Learning runs in the background and is on by default.
Content that keeps up with threats. New role specific courses are added as attackers change their methods.
Full visibility and control. Admins and employees can view and update role answers at any time.
No. Role-Based Learning is included in the Nimblr Base Package at no extra cost.
No. Role-Based Learning is on by default. Admins do not need to prepare or activate anything.
No. Both questions are required. The second question includes a "None of these options" choice for employees whose job does not match any listed item.
Yes. In the Nimblr Admin Portal, go to Users, then Edit for the employee. The Role section shows their answers, which admins can update and save.
Yes. Employees can update their answers at any time in the Nimblr End User Portal.
There are more than 25 courses across the six tracks, and Nimblr adds new role specific courses on a regular basis.
Security awareness training works best when it reflects the real risks people face at work. Role-Based Learning gives every employee training that fits their job, with the deepest training going to the roles attackers target most. It requires no setup, runs automatically, and is included in the Nimblr Base Package.
Learn more about our role-based training →