Skip to content
English
  • There are no suggestions because the search field is empty.

Why was an employee assigned specific training?

This article explains the logic behind Moxso's risk-based training assignment. It's written for admins, since employees don't have access to the risk profile, competence gap, or category detail this logic is based on. Use it to explain an assignment when an employee asks why they received a specific piece of training.

This applies to the Defend plan, where Human Risk Intelligence (HRI) runs.

The short answer

Every video and course is tagged to a risk category. When choosing what to assign an employee next, Moxso picks from the risk category where that employee currently has the biggest gap between what they should know and what they've completed, weighted by their risk profile, which is built from their role, access level, and responsibility tier. Most of the time, that's the entire explanation: a specific video or course might look unrelated to the employee's daily work, but it's assigned because of the risk category and gap it covers, and how that lines up with the employee's role and access level, not because it matches a specific incident or a tool they use.

How risk profile affects assignment

An employee's risk profile is based on things like their role, their access level, their responsibility tier (for instance, individual contributor versus manager), and how relevant each risk category is to their day-to-day work. Two employees in different roles can have different risk profiles, so they won't always get the same training, even if they joined on the same day.

If an employee's role isn't set up in Moxso, their risk profile is less precise, and their training looks more generic and varies less.

Why the same risk category shows up more than once

If several videos or courses in a row cover the same risk category for one employee, that's expected. Moxso only moves to a different category once the gap in the current one narrows. After that, the next assignment comes from wherever the largest remaining gap is.

Note: Competence in a category naturally decays over time unless it's maintained. That's part of why training keeps getting assigned even to employees who've completed everything assigned to them so far.

Reviewing why a specific assignment was made

  1. Go to Human Risk Intelligence > Overview > Assignments.
  2. Click the assignment you want to review.
  3. In the panel that opens, select the Signals tab.
  4. Check Associated risk categories for the risk category tied to that video or course, and Contextual risk factors for the role, access level, responsibility tier, and frameworks (such as NIS2 or ISO 27001) used to select it.

The panel currently doesn’t spell out "this employee's competence gap in this category is currently the largest," since that's true for the vast majority of assignments and would repeat on nearly every item. It's worth knowing that's almost always the underlying reason, so you have an answer ready if an employee asks.

Common questions

Can employees see this reasoning themselves? No. In the Hub, employees can see their own resilience score and a breakdown of it by quizzes, videos, simulations, and skills, but not the risk profile, competence gap, or risk category detail that decides what gets assigned to them. If an employee asks why they received a specific training item, they'll need to ask you or another admin.

Can employees choose their own training? No. Assignment is based on risk profile and competence gaps, not personal preference. Admins can exclude specific content from being assigned at all.

Will training stop once everything assigned has been completed? Not permanently. Competence gaps can reopen over time if there's no ongoing activity, so new training keeps getting assigned as needed.