> For the complete documentation index, see [llms.txt](https://docs.stoik.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.stoik.io/human-security/how-stoik-report-works.md).

# How Stoïk Report works

Stoïk Report lets your employees flag suspicious emails in one click, directly from their Outlook or Gmail mailbox. Every report appears in Stoïk Protect, where you can triage it from a single page. This article explains how the feature works end-to-end, what you see in Stoïk Protect, and what changes when Stoïk Email Security is activated.

{% hint style="info" %}
For deployment instructions and how to roll out the extension to your team, see [Deploy and roll out Stoïk Report to your team](/human-security/deploy-and-roll-out-stoik-report-to-your-team.md).
{% endhint %}

### Supported clients

<table data-search="false"><thead><tr><th>Client</th><th>Support</th></tr></thead><tbody><tr><td>Outlook on the web</td><td>Supported</td></tr><tr><td>New Outlook on Windows</td><td>Supported</td></tr><tr><td>Classic Outlook on Windows</td><td>Supported from version 2404 (Build 17530.15000)</td></tr><tr><td>Outlook LTSC Professional Plus 2024 (classic Outlook)</td><td>Supported (Mailbox 1.14)</td></tr><tr><td>Outlook on Mac</td><td>Supported from version 16.100 (Build 25072537)</td></tr><tr><td>Gmail (Chrome, Edge, Brave, or other Chromium browser, desktop only)</td><td>Supported</td></tr><tr><td>Outlook LTSC Professional Plus 2021 (classic Outlook)</td><td>Not supported (Mailbox 1.9 maximum)</td></tr><tr><td>Outlook on Android / iOS</td><td>Not supported</td></tr><tr><td>Gmail on Safari or Firefox</td><td>Not supported</td></tr><tr><td>Gmail on mobile</td><td>Not supported</td></tr></tbody></table>

### The Report flow

From the moment an employee receives a suspicious email to the moment you triage it in Stoïk Protect, the flow looks like this:

{% stepper %}
{% step %}
**An employee reports an email**

The employee receives a suspicious email and clicks the **Report Phishing** button in their Outlook or Gmail mailbox.
{% endstep %}

{% step %}
**Stoïk classifies the email**

Stoïk immediately analyzes the email to determine whether it was part of a Stoïk phishing simulation sent by you, or a suspicious email from outside your organization.
{% endstep %}

{% step %}
**The employee gets immediate feedback**

A pop-in appears in their mailbox confirming the report:

* If the email was a Stoïk simulation, the employee sees a short message congratulating them and explaining the warning signs they spotted.
* Otherwise, the employee sees a confirmation that the report has been forwarded for review by the IT team.
  {% endstep %}

{% step %}
**The report appears in Stoïk Protect**

The report is added to the Reported Threats table, accessible in **Human Risk > Report > Results**.
{% endstep %}

{% step %}
**You triage the report**

From the table, you can open the side panel to review the email's full context (sender, recipient, body, attachments, classification) and decide what action to take.
{% endstep %}
{% endstepper %}

### Reviewing reports in Stoïk Protect

All reports are centralized in **Human Risk > Report > Results**.

#### The Reported Threats table

The table shows every email reported across your team, with the following columns:

<table><thead><tr><th width="140.53125">Column</th><th>What it shows</th></tr></thead><tbody><tr><td><strong>Reported at</strong></td><td>When the employee reported the email.</td></tr><tr><td><strong>Reporter</strong></td><td>The employee who reported the email.</td></tr><tr><td><strong>Sender</strong></td><td>The original sender of the email.</td></tr><tr><td><strong>Subject</strong></td><td>The subject of the reported email.</td></tr><tr><td><strong>Source</strong></td><td>Whether the email is a <code>Stoïk Simulation</code> or a <code>Suspicious email</code>.</td></tr><tr><td><strong>Validity</strong></td><td>Whether the report is a <code>True positive</code>, a <code>False positive</code>, or <code>Pending</code> review.</td></tr></tbody></table>

You can filter the table by **Status**, **Reporter**, **Source**, or **Validity**, or use the search bar to find a specific email.

{% hint style="info" %}
By default, the table is sorted by most recent report.
{% endhint %}

#### The side panel

Clicking a row opens a side panel with the full context of the report:

* The reporter (name, email, channel: Outlook or Gmail)
* The email itself (sender, recipients, subject, body preview, attachments)
* The analysis (source, validity, hints when available)
* Recommendations for what to do next, when the report needs your attention

### Source: Stoïk Simulation vs Suspicious email

Each report is classified as one of two sources.

#### Stoïk Simulation

The email was part of a phishing simulation campaign you ran with Stoïk. The employee correctly spotted and reported a fake email designed to test their vigilance.

For these reports:

* The validity is automatically marked as `True positive`.
* No action is required from you. The report is counted in the campaign's stats and contributes to your team's overall awareness metrics.
* The side panel shows the simulation hints (for example, urgency wording, sender mismatch) so you can see what your employee spotted.

#### Suspicious email

The email is not part of any Stoïk simulation. It could be a real phishing attempt, a simulation from another vendor, or a legitimate email that simply looked suspicious to the reporter.

For these reports, the next step depends on whether Stoïk Email Security is active for your organization.

* **Without Stoïk Email Security**: we cannot determine the nature of the email automatically. The validity stays `Pending`. The side panel provides remediation steps to help you investigate (check the sender, check the links, confirm out-of-band).
* **With Stoïk Email Security**: the email is automatically re-analyzed by the Stoïk SOC. The validity is updated based on the SOC verdict and the appropriate action is taken. See the next section.

### Email Security integration

When Stoïk Email Security is active for your organization, every reported `Suspicious email` is automatically re-analyzed by the Stoïk SOC. This means:

* You do not have to investigate the email yourself.
* The validity is updated with the SOC verdict: `True positive` if a real threat is confirmed, `False positive` otherwise.
* If a real threat is confirmed, the SOC takes action directly (quarantine across affected mailboxes, notification to your team).

{% hint style="info" %}
Email Security also blocks the vast majority of real phishing attempts before they reach your team's inbox. The reports that still come through the Report button are the ones that slipped past the first line of defense, plus the legitimate emails employees just want to double-check.
{% endhint %}

If your organization does not have Stoïk Email Security yet, [book a demo](https://stoik.io/contact) to learn more.

### Frequently asked questions

#### What happens if an employee reports a legitimate email by mistake?

Nothing critical. The report appears in your Reported Threats table with `Pending` validity (or `False positive` if Email Security analyzes it and confirms it is safe). Encouraging employees to over-report is safer than encouraging them to under-report.

#### Can I see how many reports each employee has submitted?

Yes. You can filter the Reported Threats table by **Reporter** to see all reports from a specific employee.

#### Can I respond to the employee who reported the email?

Not directly from Stoïk Protect today. We recommend acknowledging valuable reports through your own internal channels (email, Slack) to reinforce the behavior. A short "thank you" message goes a long way for adoption.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.stoik.io/human-security/how-stoik-report-works.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
