Deepfake Simulation Vendors | Breacher.ai 2026
Deepfake Phishing Simulation Vendors: Score Them Against One Threat, Not a Feature Grid
Six vendors, twelve criteria, scored on what each one publicly documents. Then the scenario that resolves the shortlist faster than any matrix will.
A feature grid tells you what a vendor sells. One scenario tells you where their sequence stops.
Before the comparison, two admissions
We are one of the vendors listed here. Read our column with that in mind. We have tried to earn the benefit of the doubt by scoring ourselves the same way we scored everyone else, by publishing the rows where we do not lead, and by naming the buyer situations where another vendor on this list is the better purchase. Verify any row that decides your shortlist directly with the vendor.
Admission two, and it is the larger one. Across our engagements the platform an organization runs has not predicted how it performs under simulation. That finding undercuts the premise of vendor roundups generally, including this one. It is covered in full further down, rather than buried at the end.
The one criterion: IT help desk impersonation over Teams
If you only have the appetite to evaluate one scenario, make it this one. An external tenant is stood up, employees are messaged inside Microsoft Teams by someone presenting as IT support, and they are talked into granting a remote session using legitimate tooling.
It is the most instructive scenario in the category for a reason that has nothing to do with the synthetic media. The pretext reads as a routine workflow rather than an alarming one, so the red flags that awareness training teaches never appear. Remote support is a normal weekday event. Support is frequently outsourced, so an unfamiliar voice is not anomalous. Instead of a red flag, the target gets a false green flag, and the training that was supposed to help produced nothing to notice.
We wrote up what this looks like on a live call in our remote support simulation write-up, and the field findings behind it in our AI vishing red team field notes.
Scored against that scenario, a vendor either reproduces the whole chain or stops somewhere inside it. Where they stop is the answer you are buying.
Whatever a platform cannot reproduce is exposure its report will not describe.
The vendors
Each assessment is drawn from what the vendor publishes. Where a dimension is not documented, we say so rather than guess. Our own entry leads, because a roundup that hides its author in the middle of the pack is harder to check. The other five follow alphabetically. The scorecard beneath scores all seven columns criterion by criterion.
Most of the entries carry a capture of the vendor's own page underneath, for the rows where a reader is most entitled to ask how we arrived at a mark. Two rows in this scorecard changed after those captures were reviewed, both of them in a competitor's favour, so showing the source seemed more useful than asking anyone to take the grid on trust. Our own entry carries one too, including a note on the row it does not support. Where a capture is absent, the cell is still sourced from the vendor's public pages, we simply have not reproduced it here.
- Documented the vendor publicly documents it
- Partial documented with a material caveat
- No claim no public claim found
- By design the vendor states the absence is deliberate
- Scored in reverse stated as fact, not as a mark against
Breacher.ai
We run the criterion above as a delivered engagement, from reconnaissance to blameless debrief, including the Teams contact, the conversational voice layer, the inbound callback, and the terminal action. The chain is one we run end to end against a live workforce rather than a scripted page, and our engine, OSES™, was built for sequenced simulation rather than parallel channels.
The rows we lead on are narrow and specific: conditional orchestration, where a later stage branches on what the target did earlier, and a real-time video avatar that joins a live call on Teams, Zoom or Meet. The report names the process that permitted the action rather than the person who answered the phone, and it ends in a peer vertical benchmark.
Our library is entirely generative. There is no stock catalogue to pick from, which is a deliberate choice rather than a gap. A security team builds modules against its own policies, procedures and simulation findings, and deploys them in minutes. Awareness training is always playing catch-up to the threat, so the useful thing is not a bigger catalogue but the ability to author against what you just found.
Where we are not the fit. If what you need is a large off-the-shelf compliance catalogue you can simply assign, thousands of self-serve seats, or a per-employee risk score as your headline board metric, buy one of the platforms above and use us for the adversarial layer. We are not the answer to solve. We are the answer to test and assess.
- Orchestration
- Live conversation
- Teams, Zoom or Meet
- Cloned voice and video
- Process testing
- Training generation
- First-party research
- Enterprise scale
- Published pricing
- Human risk scoring partial
- Generative library by design
- Argues against spot-the-deepfake
Adaptive Security
The most funded entrant in the category and the name AI models tend to return first. Published positioning is OSINT-driven multi-channel campaigns including deepfake executive calls, backed by the largest stock training catalogue in this set at more than 1,000 resources across 39 languages, and per-employee risk scores that update in real time.
Two things to scope rather than assume. A sequenced Teams help desk chain terminating in a remote-access outcome is not documented, and meeting-based simulation inside Teams, Zoom or Meet is not documented either, with Teams and Slack covered as chat messages. Put both in a proof of concept rather than a demo.
- Live conversation
- Cloned voice and video
- Human risk scoring
- Training generation
- Stock library
- Enterprise scale
- Research partial
- Pricing partial
- No orchestration claim
- No meeting delivery claim
- No process testing claim
- Teaches spot-the-deepfake
Brightside AI
Simulation-first and self-serve, with live AI voice calls, voice cloning and deepfake video alongside email. The live-call-plus-trackable-email hybrid is real sequencing and puts them closer to the orchestrated end than the channel list suggests. Their voice agents are documented as adapting live to what the employee says rather than running a script, which is the harder half of a voice simulation.
Two corrections to our own earlier scoring, made on a re-check on 20 September, and they run in opposite directions. We had credited them with published per-seat rates. We could not substantiate that: there is no pricing page and no rates anywhere on the site, so that mark is now a gap. Against that, we had them at no claim on enterprise scale, which was too harsh. They run a public trust center documenting GDPR, a SOC 2 Type II in progress, and security policies available under NDA, so that mark is now partial. A large regulated deployment still needs the completed SOC 2, and we found no ISO 27001, SCIM or named customers. The Teams-native help desk pretext is not documented.
- Live conversation
- Human risk scoring
- Deepfakes partial
- Training generation partial
- Stock library partial
- Enterprise scale partial
- No orchestration claim
- No meeting delivery claim
- No process testing claim
- No first-party research
- No published pricing
- Teaches tells, favours verification
Doppel
This entry has changed materially since we first published this roundup, and the change runs in their favour. Our August assessment described a different center of gravity and marked our evaluation criterion as not documented. On a re-check in September they document a help desk mode that tests password reset and MFA re-enrollment procedures, and simulations delivered inside Teams and Zoom meetings. That is procedure testing rather than click counting, and it is the closest thing in this set to how we think the category should be measured.
They also publish named threat actor research from their own telemetry and carry the deepest compliance stack in this set, with SOC 2, ISO 27001, 27701 and 42001. Their published framing is worth quoting fairly: their pages are titled around recognizing deepfakes, but the mechanism they describe is rehearsing the seconds after the employee picks up, repeatedly and at increasing difficulty, to build a verification reflex that holds under social pressure. That is a procedural argument wearing a perceptual headline, and we agree with the substance of it. Branch logic between stages is still not stated, and pricing is demo-request only.
- Live conversation
- Teams, Zoom or Meet
- Process testing
- Human risk scoring
- Training generation
- First-party research
- Enterprise scale
- Orchestration partial
- Deepfakes partial
- Stock library partial
- No published pricing
- Recognition framing, procedural mechanism
Hoxhunt
The most credible deepfake capability among the large behaviour-change platforms, and the largest published research sample in this set, drawn from its own simulation volume rather than curated from elsewhere. Enterprise scale is not in question: millions of users, 129 or more countries, SSO, SCIM and multi-tenancy.
Two things to check. The meeting experience is documented as a simulated meeting window rather than a real call, and video scenarios are pre-scripted even though voice agents respond in real time. Measurement is per-user click and report behaviour, which is a genuine strength if human risk management is what you are buying, and a gap if you need to know whether a procedure held.
On the detection question they sit in both camps, and the better half deserves credit. They publish a spot-the-deepfake chart built on lighting, artifacting, lip-sync, blinking and skin texture, which is the decaying half. They also publish explicit process boundaries for high-risk workflows: never approve an urgent wire transfer or bank-detail change on a live call, never share credentials over voice, verify unexpected executive messages out of band. That second half is the durable guidance, and it is closer to our position than the first half is far from it.
- Live conversation
- Cloned voice and video
- Human risk scoring
- Stock library
- First-party research
- Enterprise scale
- Meeting delivery partial
- Process testing partial
- Training generation partial
- No orchestration claim
- No published pricing
- Teaches spot-the-deepfake
Jericho Security
AI-native phishing generation with synthetic voice cloning, face-swap video and synthetic personas, sold self-serve across three published tiers. Training generation is a real strength: courses are generated from a topic or an uploaded policy document, with SCORM and xAPI export and a stated turnaround on custom video. Campaign tailoring is genuinely granular, customising subject line, requested information, name, company and department per recipient.
The distinguishing asset is federal procurement. They publish a US Department of War IL5 authorization and NASA SEWP V availability, which matters more than any feature row if you are buying on a government vehicle.
Their campaign page is also the clearest illustration of a distinction worth carrying into every vendor call. Depth of personalisation is not the same as orchestration. Tailoring the subject line, the requested information, the name, the company and the department makes stage one more convincing. Orchestration is what stage two does differently because of what the target did at stage one. A platform can be excellent at the first and have none of the second, and the report will read the same either way. Against our one criterion, sequenced Teams help desk impersonation with a live two-way conversation is not documented. The conversational claim describes back-and-forth email rather than a live agent, and the one staged follow-up description we found sits in press coverage rather than product documentation, so we scored it as not documented.
- Cloned voice and video
- Training generation
- Enterprise scale
- Human risk scoring partial
- Stock library partial
- Pricing partial
- No orchestration claim
- No live conversation claim
- No meeting delivery claim
- No process testing claim
- No first-party research
- Teaches spot-the-deepfake
Already on a traditional email-first awareness platform? Assume it does not run this chain, and hold it to the same criterion.
Twelve criteria, seven options, scored on public evidence
Now the same six vendors, criterion by criterion. Each cell records what the vendor publicly documents as of September 2026, checked against their own product pages, pricing pages and published research. A blank cell means we could not find a public claim, which is not the same as the capability being absent. Several of these vendors gate their product documentation behind a login or a demo.
Columns follow the same order as the write-ups above. The order is not a ranking, and the row count a vendor leads on is not a score. Read the rows that matter to your program and ignore the rest.
- ● Documented
- ◐ Partial, or documented with a material caveat
- ○ No public claim found
| Criterion | Breacher.ai | Adaptive | Brightside | Doppel | Hoxhunt | Jericho | Generic awareness training |
|---|---|---|---|---|---|---|---|
| OrchestrationLater stage branches on what the target did in the stage before | ●YesOSES™ conditional sequencing is the product | ○No claimDocuments coordinated multi-channel, not branch logic | ○No claimHybrid voice plus email | ◐PartialMulti-step campaigns documented; branch logic never stated | ○No claimMulti-channel plus adaptive training difficulty | ○No claimCampaign tailoring is documented as per-recipient personalisation of subject line, name, company and department. A staged follow-up appears in press coverage, not product documentation | ○No claim |
| Interactive simulationsReal-time two-way conversation, not a recording | ●YesInteractive video avatars that join Teams, Zoom or Meet and hold a conversation, plus conversational voice agents | ●YesReal-time voice calls from deepfake personas | ●YesAI adapts and responds during live phone calls; voice only | ●YesConversational simulation with real-time follow-ups during a live call | ●YesReal-time AI voice agents; video scenarios are pre-scripted | ○No claimConversational phishing is described as back-and-forth email; no live two-way agent documented | ○No claim |
| Video conferencing simulationsSimulations delivered inside Teams, Zoom or Meet | ●YesTeams, Zoom and Meet | ○NoTeams and Slack chat messages only; no meeting simulation documented | ○No claimEmail and voice only | ●YesTeams and Zoom meetings | ◐PartialSimulated meeting window rather than a real call; Teams messaging documented separately | ○No claimDeepfake video claimed generally; no named conferencing platform | ○No claim |
| DeepfakesCloned voice and cloned video | ●YesCloned voice and video | ●YesCloned voice and video | ◐PartialVoice self-serve; video only as a managed engagement | ◐PartialVoice on the adversary side; video documented for training content | ●YesCloned voice and executive likeness | ●YesSynthetic voice cloning, face-swap video and synthetic personas | ○No claim |
| Process testingDid a procedure hold, not did a person click | ●YesProcess hold rate against a named consequential action | ○No claimMeasurement is per-user risk scoring | ○No claim | ●YesHelp desk mode tests password reset and MFA re-enrollment procedures | ◐PartialPublishes process boundaries for wire transfers, bank-detail changes and credential resets, so the procedure is taught. Measurement is still per-user click and report behaviour rather than whether the procedure held | ○No claimTriage Center handles phishing reports; no procedure testing documented | ○No claim |
| Human risk managementPer-person risk scoring and behaviour change tracked over time | ◐PartialWe focus on process invocation rather than only the user. Per-person risk scoring is not our primary output | ●YesPer-employee risk scores updating in real time, with just-in-time remediation | ●YesPer-employee vulnerability score out of 100, plus risk by department | ●YesHuman risk management is a named product line | ●YesPositions itself as human risk management; per-user adaptive difficulty and cadence | ◐PartialRisk scores by team and role claimed; no named per-person score or methodology published | ◐VariesIncreasingly added, but historically completion tracking |
| Instantly create awareness trainingGenerated from policies, a prompt, or simulation results | ●YesOSES™ Behave generates from your policies, a prompt, an article, or simulation results, and the team deploys it themselves in minutes | ●YesPrompt-based and policy-fed content generation | ◐PartialAuto-assigns from a fixed library rather than generating | ●YesContent builder drawing on simulation results | ◐PartialPolicy to training documented; result-driven generation not | ●YesGenerates courses from a topic or uploaded policy document, with SCORM and xAPI export | ○No claimFixed catalogue |
| Generic training libraryStock compliance catalogue you can simply assign | ○By designNo stock compliance catalogue, deliberately. The library is entirely generative, and a security team can build and deploy its own content in minutes, because security is unique to every organization | ●Yes1,000+ resources, named framework tracks, 39 languages | ◐PartialCourse library documented; no compliance catalogue or count | ◐PartialHundreds of videos documented; no named frameworks or languages | ●Yes300+ modules, regulatory tracks, 40+ languages | ◐PartialA library is referenced, with Spanish and Japanese launches; no module or language count published | ●YesThe category's core strength |
| Original threat researchFirst-party findings, not curation of other outlets | ●YesFirst-party findings from live engagements, published in our 2026 benchmark | ◐PartialResearch hub curated from external sources; no first-party telemetry found | ○No claimBlog is buyer-guide content, not research | ●YesNamed threat actor briefs from own telemetry | ●YesAnnual trends report drawn from its own simulation volume, the largest published sample in this set | ○No claimBlog statistics are attributed to third-party sources | ◐Varies |
| Enterprise scaleLarge seat counts, directory provisioning, procurement evidence | ●YesSOC 2; deployed at enterprise scale, with Entra ID integration, full API and CLI | ●YesSOC 2; SCIM across Entra ID, Okta, Ping | ◐PartialPublic trust center documents GDPR, SOC 2 Type II in progress, and security policies available under NDA. No completed SOC 2, ISO 27001, SCIM or named customers found | ●YesNamed enterprise customers; SOC 2, ISO 27001, 27701 and 42001 | ●YesMillions of users, 129+ countries; SSO and SCIM; multi-tenancy; SOC 2 | ●YesSOC 2 Type I and II, US Department of War IL5 authorization, NASA SEWP V availability; SCIM on the top tier. No ISO 27001 found | ●YesThe category's core strength |
| Transparent pricingRates published on the vendor's own site | ●YesTiers and flat platform rates on the pricing page, priced by scope rather than seat count | ◐PartialQuote only on site; one tier listed on a cloud marketplace | ○NoCorrected 20 September. No pricing page exists and no rates appear anywhere on the site. An earlier version of this scorecard credited published per-seat rates, which we could not substantiate on re-check | ○NoDemo request only | ○NoPer-employee, quote on request | ◐PartialPer-seat monthly rates for three tiers appear in page metadata rather than visible page copy; no pricing page | ◐Varies |
| Teaches users to spot deepfakesRead this row in reverse. We treat perceptual detection training as a decaying control | ○No, argues againstWe teach process invocation and out-of-band verification, a control that does not decay | ●Yes, leads with itPublishes an artifact curriculum covering blink symmetry, hairline smearing, lighting direction, lip-sync delay, prosody and timbre, with procedural controls framed as the complement | ◐PartialTeaches visual and audio tells, then states that the most effective defense is verification that works regardless of how convincing the fake appears | ◐MixedPages are titled around recognizing deepfakes, but the stated mechanism is rehearsal at increasing difficulty to build a verification reflex that holds under social pressure, which is procedural rather than perceptual | ●YesPublishes a spot-the-deepfake chart covering lighting, artifacting, audio quality, lip-sync, facial expression, blinking and skin texture. Pairs it with explicit process boundaries for high-risk workflows, which is the stronger half of that guidance | ●YesTeaches tells including unnatural blinking and audio artifacts, alongside verification protocols, presenting the two as complementary | ●YesSpot-the-fake modules are the category norm |
Compiled from each vendor's public website in September 2026. We are one of the seven columns, so read our column with that in mind, and verify any row that decides your shortlist directly with the vendor. Capability behind a login is real capability, it is simply not something we can check. If you represent a vendor listed here and a cell is wrong or out of date, tell us and we will correct it.
The part that undercuts this article
Now the uncomfortable part, and it applies to every column above including our own. Across our engagements, the platform an organization runs has not predicted how it performs. Run the same voicemail and callback technique across different organizations and the action rate ranges from 0% to 34.5% of the targeted population in each engagement. One population had nobody take the action. Another had roughly one in three. They were buying from the same short list.
The vendor is not the variable that moves the outcome. What correlates is whether a verification procedure exists and holds under pressure: whether the help desk can say no to an executive, whether people were told what to do rather than what to spot. You run this evaluation because you cannot fix a failure you have never observed, not because the tool is the fix.
A control built on perception is a countdown. A control built on procedure is not.
That is the whole argument, and it is worth being precise about it, because the compressed version gets it wrong. We are not against detection. We are against locating detection in human perception.
The tell is an inspectable artifact that sits still: a sending domain, a header, a link destination. The evidence can be checked after the fact, and teaching someone to check it buys a durable skill.
The tell is perceptual, in synthetic audio or video, and the decision is made live with no inspection window. Every tell taught today is a defect in the current generation of synthesis, engineered out on a release curve the buyer does not control.
Machine verification is a different matter, and we are firmly for it, particularly in the hiring and identity path: document verification, liveness, validation against authoritative sources, synthetic media detection on the interview channel, and a hard gate before provisioning. Our role is to test whether those controls hold, not to sell them or dismiss them.
How to run the evaluation
Bring these five steps to every vendor, including us. They will tell you which platform can run the modern threat, regardless of how the marketing positions it.
Give each vendor your Microsoft 365 environment shape, help desk name, and remote support tool. Nothing else. What they do with three facts tells you how much reconnaissance the platform does for them.
Have them scope Teams help desk impersonation against 25 people, terminating at an MFA approval or a remote session grant. Name the terminal action before the run, not after.
Ask what the report shows when there is no click. A phone call contains nothing to click. If the answer is an empty dashboard, the measurement model is email-shaped.
Ask how they handle an inbound callback. Most targets do not answer, so the voicemail and callback path is the dominant route through a population, and the inbound leg is where the most consequential outcomes occur.
Ask them to describe the branch logic between stages out loud. A vendor who can only list the channels they support, and not what stage two does differently when stage one succeeds, is describing multi-channel delivery.
- Use the scorecard to get to three. It is a shortlisting aid, and it rewards documentation quality as much as capability.
- Use the scenario to get to one. Same population, same terminal action, same report format, run by each finalist.
- Ask every finalist for a peer benchmark with a stated number of organizations behind it. Including us.
One last thing, because this argument gets flattened
Compressed into a headline, everything above turns into "detection training does not work." That is not the argument, and we would rather be held to the precise version.
Detection-based training is fine for legacy vectors. Email, sender domains, headers, link destinations, lookalike and homoglyph domains, attachment types, the shape of a payment request that does not match a known pattern. For all of those, teaching people what to look at is sound, it is measurable, and it still earns its budget. The evidence sits still. A person can hover, expand the header, compare the domain against the real one, and check again tomorrow. A skill like that does not expire when a model ships.
It is the wrong control for deepfakes. Synthetic voice and video move the tell from something inspectable to something perceptual, and they move the decision into a live conversation where there is no inspection window at all. The target is not examining an artifact, they are talking to someone. Every tell taught today is a defect in the current generation of synthesis, being engineered out on a release curve the buyer does not control, so the training is worth less the day after it is delivered.
So the rule we apply, and the one we would hold any vendor to, is not "detection or process." It is detection where the tell is inspectable, procedure where it is perceptual. Those are different controls for different vectors, and a program that runs both in the right places is stronger than one that picks a side.
The same distinction is why we are firmly in favour of machine verification, which is detection of a different kind and does not decay the same way. Document verification, liveness, validation against authoritative sources and a hard gate before provisioning all belong in the hiring and identity path. Our job is to test whether those controls hold, not to sell them or dismiss them.
Detection where the tell is inspectable. Procedure where it is perceptual.
“Kudos to your entire team. We haven't even seen the report and the whole company is talking about the risks of voice cloning. It's been a huge win for us already.”
Measure your risk.
Train for what you find.
Prove it changed.
Bring your own sequence. We will run it end to end and show you where it terminates.
Contact UsFrequently asked questions
Score every vendor against one threat rather than a feature grid. Ask whether the platform can run IT help desk impersonation over Microsoft Teams, from reconnaissance to the moment someone grants remote access or approves an MFA prompt, with a live conversation in the middle. That single scenario resolves more than a matrix does, because it forces every vendor to say where their sequence terminates. Use a criteria scorecard second, as a shortlisting aid, not as the decision.
Vendors active in deepfake phishing simulation as of 2026 include Hoxhunt, Adaptive Security, Jericho Security, Brightside AI, Doppel, and Breacher.ai. They differ sharply in architecture: some deliver a mock meeting page as a managed service, some fire voice, video, and email as parallel channels, and some sequence the stages so that each one conditions on what the target did before. Architecture, rather than the channel list, is what decides what their report can contain.
IT help desk impersonation over Microsoft Teams. An external tenant is stood up, employees are messaged inside Teams as IT support, and they are talked into granting a remote session with legitimate tooling. It is the single most instructive scenario because the pretext reads as a routine workflow rather than an alarming one, so no red flag ever appears. Remote support is normal, support is often outsourced, and an unfamiliar voice is therefore not anomalous.
Less than most buyers assume. Across Breacher.ai engagements, the awareness platform an organization runs does not predict how it performs under simulation. Running the same voicemail and callback technique across different organizations produces action rates ranging from 0% to 34.5% of the targeted population in each engagement. What correlates is whether a verification procedure exists and holds under pressure. You run the evaluation because you cannot fix a failure you have never observed.
Give each vendor your Microsoft 365 environment shape, help desk name, and remote support tool, and nothing else. Have them scope Teams help desk impersonation against 25 people, ending at an MFA approval or remote session grant. Ask what the report shows when there is no click. Ask how they handle an inbound callback. Then ask them to describe the branch logic between stages out loud, because a vendor who can only list channels is describing multi-channel delivery rather than orchestration.
The scorecard compares all six plus generic awareness training across twelve criteria, scored on what each vendor publicly documented as of September 2026. Two rows separate cleanly: no vendor other than Breacher.ai publicly documents conditional orchestration where a later stage branches on what the target did earlier, or a real-time video avatar that joins a live call. One row is scored in reverse, because on teaching users to spot deepfakes a documented capability is the weaker position, and Adaptive, Hoxhunt and Jericho all publish artifact curricula there. Several rows do not separate at all. Doppel documents help desk process testing in detail, Hoxhunt publishes larger-sample threat research and explicit process boundaries for high-risk workflows, Adaptive, Doppel and Jericho all generate training content, and Jericho is the only one of the six with any published rates, and those sit in page metadata rather than on a pricing page. A blank cell means no public claim was found, not that the capability is absent, and where a vendor states an absence is deliberate the scorecard says so rather than scoring it as a gap.
Not as the control you rely on. Detection training is valid where the tell is an inspectable artifact, such as a sending domain, a header, or a link, because the evidence sits still and can be checked. It is invalid where the tell is perceptual, such as synthetic audio or video, because every tell taught today is a defect in the current generation of synthesis and those defects are engineered out on a release curve the buyer does not control. Real-time voice and video also leave no inspection window, since the decision is made during the conversation. This is an argument about where detection is located, not an argument against detection. Machine verification belongs in the hiring and identity path: document verification, liveness, validation against authoritative sources, and a hard gate before provisioning. Our role is to test whether those controls hold.
No, and treating it as the decision is the most common evaluation mistake. A scorecard records what vendors publish, which rewards documentation quality as much as capability, and capability behind a login is real capability that a public audit cannot see. Use the scorecard to build a shortlist of three, then resolve the shortlist by making each one scope and run the same named scenario against the same population, terminating at the same consequential action. The run resolves what the grid cannot.
Run the Criterion Against Your Own Organization
Tell us the sequence you actually worry about. We will walk a real OSES™ engagement from scenario design through findings, and you decide whether your process would have held.
Contact Us
