Redflag Labs: Reading the Pattern Behind the Click
This concept project is an AI-powered analytics dashboard designed to help security and L&D teams understand phishing simulation results without hours of manual sorting. Built around a live prototype, admins upload a quarter's simulation data and see results broken down by department, employee, and scenario type. An AI mentor reads the data on demand and recommends differentiated training by behavioral trigger, not just click count, so a workforce with different vulnerabilities doesn't get the same generic module.
Audience: IT and security teams managing corporate phishing simulation programs (concept scenario)
Responsibilities: Instructional design, dashboard UX design, data taxonomy design (scenario categorization by pretext and lure type), AI prompt engineering, front-end development, brand identity design
Tools Used: Claude, Claude Design, Google Docs
The Problem
This project is inspired by a real gap I've seen in how phishing simulation programs typically work. Most platforms report whether someone clicked, rarely why, how many times, or what kind of email they fell for. That gap shows up every quarter on a security team: someone spends hours manually sorting results by department and scenario just to understand who actually needs help. By the time the data is untangled, the training that gets assigned is generic, the same module for someone fooled by a fake IT reset and someone fooled by a fake executive wire request. Different vulnerabilities, same fix, which is really no fix at all.
The Key Decision
This tool exists to give an IT or security team that clarity without the manual sorting. Upload a quarter's CSV and the dashboard rebuilds around it automatically, no filtering spreadsheets by hand, no cross-referencing department lists. It breaks results down by department, by employee, and by scenario type, so a reviewer can see at a glance who clicked, how often, and on what kind of email, then assign follow-up training based on actual click count instead of a gut call.
Working with The AI Mentor
The mentor runs on demand, any time an admin wants a read on the current data, by department, by employee, by click count, instead of waiting on a scheduled report. That live analysis is what makes role-targeted training possible: instead of one generic phishing-defense module for the whole company, the mentor's summary points toward which teams need which fix. Building it also meant treating its output critically rather than shipping it as-is: an early version said "most employees responded appropriately" while the underlying data showed 44 of 50 had clicked at least once. Catching that mismatch and tightening the prompt was as much a part of the design process as the layout was.
Reflection
Manually cross-referencing 336 simulation attempts by department, scenario, and click count takes close to three hours every quarter. This dashboard does it as fast as a CSV can upload, and the summary that used to take the most judgment, and the most time, now runs in seconds. That's the actual case for AI in a workflow like this: not replacing the reviewer's judgment, but giving them a fast, defensible starting point, so their time goes toward deciding what to do about the data instead of toward finding it in the first place.

