For MSPs, an awareness programme only earns its keep when the results land where the client actually looks — and for most MSPs that place is ConnectWise, not another training portal. Cyber Aware connects to ConnectWise Manage through Zapier, so a finished phishing campaign becomes a ticket with the results attached, course completions log as ticket activity, and a newly provisioned client can flow straight into billing. The wiring is a 15-minute job using the platform's template library, and this guide walks through it end to end.
Why ConnectWise reporting matters for MSPs
White-labelled human risk reporting is the deliverable the client sees, but the PSA is the system of record the whole service runs on. When campaign results never leave the training platform, three things go wrong:
- The deliverable is invisible. Monthly reports sit in a portal the client's manager never opens, so the value of the service is undercounted at renewal time.
- Support work goes unticketed. A failed campaign that needs follow-up, a re-run, or an executive conversation becomes an email thread instead of a tracked, time-recorded item.
- Reporting is manual at the worst moment. QBR season means someone copies numbers from one tool into another — and that is the month everything else is due too.
Connecting the two platforms closes all three gaps with one automation: the campaign wraps, the ticket appears with the results, and the record exists whether or not anyone remembers to look.
What the Cyber Aware-to-ConnectWise integration does
Cyber Aware exposes every platform primitive as a Zapier trigger or action — not just a handful. For ConnectWise reporting, the relevant pieces are:
- Two-way sync of companies, contacts, agreements and tickets across the PSA/RMM category (ConnectWise PSA, Autotask, HaloPSA and others).
- Nine event triggers, including
phishing.campaign-completed,course.completed,learner.created,client.created,client.typeandlead.created— the same events that power the platform's webhooks. - A pre-built template flow most MSPs deploy as-is: auto-create a ConnectWise ticket with the results when a phishing campaign wraps up.
- Native directory integrations for Microsoft 365 and Google Workspace running alongside — the PSA wiring handles client reporting while the directory connection handles enrolment.
The distinction matters: ConnectWise connects via Zapier, which is why the setup needs no custom API work — but it also means your Zapier plan is part of the stack. For high-volume automations Zapier's task limits are the constraint to watch, and the platform's documented API is the alternative when a flow outgrows Zapier.
What you need before you start
- ConnectWise Manage with permission to create an API member (Integration level, with the board and company access you want tickets written to).
- A Zapier account — the Cyber Aware app lives at zapier.com/apps/cyber-aware/integrations, and the ConnectWise pairing is at zapier.com/apps/connectwise-manage/integrations/cyber-aware.
- A Cyber Aware admin account with at least one completed phishing campaign, so the trigger has test data to work with.
- A decision on ticket structure before you build: one campaign per client per ticket is the structure that keeps the PSA readable. Per-learner tickets multiply fast and nobody reads them.
Step by step: the campaign-results Zap
- Connect Cyber Aware to Zapier. Authorise the Cyber Aware app and confirm the test account pulls through.
- Set the trigger to
phishing.campaign-completed. Zapier fires it when a simulated phishing campaign finishes for any client in your workspace. - Test the trigger. Pick a recent campaign — Zapier shows the payload: campaign name, client, sends, clicks, reports and the campaign's outcome data.
- Connect ConnectWise Manage. Create the API member in ConnectWise with access to the boards you use for client security work, then authorise the ConnectWise app in Zapier with those credentials.
- Add the Create Ticket action. Map the campaign name to the ticket summary, the client to the ConnectWise company, and the results summary to the initial description. Set the board, status and type to whatever your client-facing security board uses.
- Add a filter for material campaigns if your default cadence is monthly per client and you only want tickets for campaigns that breach a threshold — for example, click rate above 5% or a report rate below target. Zapier filters run before the ticket is created, so quiet months do not clutter the board.
- Test the Zap end to end with the real campaign payload, then check the ticket in ConnectWise: right company, right board, results legible to someone who was not in the training platform.
The second Zap: course completions as ticket activity
Campaign tickets capture the incidents; course completions capture the ongoing work. A second Zap on course.completed adds ticket activity to the client's ongoing service ticket — or to the agreement's activity log — every time a learner finishes a course. This is what turns "we do training" from a claim into a timestamped record in the PSA, which is exactly what a client's cyber insurer or an enterprise vendor-review questionnaire asks to see.
Keep this Zap on activity-only: one ticket per client per service period, with completions appended, rather than a ticket per completion. The difference at 50 clients and 500 completions a quarter is a readable board versus an unusable one.
Billing: turning provisioning into a line item
The template library's billing flow fires on client.created — when a new client is provisioned in Cyber Aware, an automation adds the billing line. The published template targets Autotask or Xero; the ConnectWise equivalent is the same trigger writing an agreement addition, so a new client's subscription appears on the invoice without a manual billing task. If you bill awareness training per seat, the platform's Zapier triggers on user.created and learner.created can keep the per-seat count current the same way.
What to map where
A readable campaign ticket carries five fields, no more:
- Company — mapped from the Cyber Aware client.
- Summary — campaign name and date.
- Results in the initial description — sends, clicks, reports, and any credential-harvest interactions.
- Human risk score trend — this month versus last, so the ticket shows direction, not just a snapshot.
- Type/Board — your existing client-security board, so nothing new to learn for the team.
Everything else — per-learner detail, course-level data — belongs in the white-labelled human risk reporting deliverable, not the ticket. The PSA record proves the work happened; the report proves it mattered.
FAQ
Is the ConnectWise integration native or via Zapier? Via Zapier. Cyber Aware's native directory integrations are Microsoft 365 and Google Workspace; ConnectWise connects through the Zapier app, which exposes every platform primitive as a trigger or action.
Which Cyber Aware events can trigger ConnectWise actions? All nine: phishing campaigns completed, courses completed, learners and users created, clients created, client type changes, health checks completed, framework actions completed, and leads captured.
Does it cost anything beyond the platforms? Zapier pricing applies to the tasks your Zaps consume — a monthly campaign-and-completion setup for a typical MSP is a modest task count. Cyber Aware's API is the documented alternative when a flow outgrows Zapier's limits.
Can it create ConnectWise companies automatically?
Yes — map the client.created trigger to a Create Company action, or pair it with an agreement addition so provisioning and billing land together.
Is the sync two-way? The PSA/RMM category covers two-way sync of companies, contacts, agreements and tickets, so company records maintained in ConnectWise stay consistent with the training platform's client list.
What do most MSPs build first? The campaign-results ticket, then completion activity, then billing. The first two make the service visible in the PSA; the third removes a manual billing task.
One last thing
The most common failure in this wiring is not the connection — it is mapping every learner event into its own ticket until the board becomes unreadable and the team mutes it. One campaign, one ticket, per client: the PSA stays scannable, and the report the client actually receives stays in the branded deliverable where it belongs.