We're SOC 2 Type II certified. Our full-time employees get security training through our HRIS (BambooHR). Contractors come through third-party agencies and aren't in that system. We can't just add them as employees.
Problem: we need to track completion for all personnel, including contractors. Auditors will check.
Current process is a manual email with a PDF and a spreadsheet. It's failing.
- No reliable completion tracking.
- No automated reminders.
- No proof of delivery.
What are you using to solve this? I need a system that can:
- Import a CSV of contractor emails/names.
- Assign a specific training module.
- Send automated enrollment emails.
- Report on completion status (with timestamps).
- Integrate with our IdP (Okta) for SSO if possible.
Bonus: how do you handle contractors whose emails are managed by their agency? We need attestation from the individual, not the agency contact.
I've looked at Secureframe's training module but documentation is thin on external users. Real experiences only.
Metrics don't lie.
Good luck with that CSV import. Most platforms say they do it, but good luck getting it to handle the inevitable bad data or agency email domains without a manual review first.
Secureframe's module is a checkbox feature. Their real focus is selling you more audits. You'll need a dedicated training platform for external users.
On the agency email problem - you can't get attestation if the email goes to a generic inbox. You'll have to mandate individual emails in the contract, or send the training to the agency contact and make them legally liable for individual completion. Adds cost.
Read the contract
That's a good point about the agency emails. I ran into something similar with a vendor list import last year - half the emails bounced because they were role-based or outdated.
> make them legally liable for individual completion
Does that actually hold up in practice? Our legal team is hesitant about pushing liability onto the agency contact. They say it's hard to enforce unless it's a massive contract.
What did you end up doing for the CSV validation piece? We're looking at some Python scripting to pre-check the file, but it's another thing to maintain.
Containers are magic, but I want to know how the magic works.
Yeah, the liability piece is tricky. We got our legal to agree to it, but only by tying it to contract renewal and a financial penalty. The agency's point of contact has to sign an addendum accepting responsibility for their workers' training status. It's a pain, but it works.
For the CSV validation, we actually built a simple CloudFront distribution in front of a Lambda. It validates the file format and email domains against a deny list (like *@agency-generic.com) before it even hits the training platform's import. Cuts down the manual work by about 80%.
The real headache is when the agency sends a new contractor mid-cycle and you have to force a new import. That's where the automated reminders from the training platform save you.
security by default
You're right to be skeptical of Secureframe's module for this specific use case. It works for employees but the external user management is an afterthought.
I solved this exact problem last year. We use KnowBe4 for the training platform, but the critical piece was a custom connector we built between our contractor management system (GUIDEcx) and KnowBe4's API. When a contractor is onboarded in GUIDEcx, a webhook triggers and creates the user in KnowBe4 with the "external contractor" role and assigns the module. This bypasses the need for CSV imports entirely. The attestation comes directly from the individual contractor's email address, because we mandate in the master service agreement that the agency must provide an individual, monitored email for each resource for compliance purposes. We had to get legal to back us, but it's now a non-negotiable line item.
The Okta integration is straightforward on KnowBe4's side, but you'll need to ensure your contractors are in a separate Okta directory that doesn't sync to BambooHR. We use Okta Workflows to provision them into a "Contractors - External" group upon assignment, which grants them the specific app access for training.
RTFM — then ask for the audit
We built a similar process using WorkRamp. It does the CSV import and reminders you mentioned.
The key part, for the agency email issue, was adding a clause to our service agreements. It requires the agency to provide a unique, individual email for each contractor. The training invite goes there, so attestation is direct. Without that, the tracking falls apart.
Did you consider pushing the requirement for individual emails back to your procurement team? It's easier to fix in the contract than in the platform.