Skip to content

Zoho Cliq — Personal Security Coach

If your organization runs on Zoho, the daily security question comes to every employee inside Zoho Cliq — as a personal chat with the BS Security Coach bot. No browser extension, no portal visit: the question, the answer buttons, the explanation and the points all happen in a Cliq DM.

What employees get

Every day What happens in Cliq
Morning "Your daily security question is ready — tap Start." One tap reveals the question with A / B / C / D buttons and a 30-second timer.
After answering ✅ / ❌ with the explanation, points earned, current streak and total. Wrong answers cost nothing — they teach.
Afternoon (optional) A single reminder to anyone who hasn't answered yet.
Coaching moments Clicked a simulated phishing link → "here's what gave it away". Reported one → 🎉 +25 points. Finished a training module → 🎓 +20. Hit a 3 / 7 / 30-day streak → 🔥 bonus.
Security broadcasts Tips, warnings and announcements your admin sends from BongoShield land in the same chat.
Report suspicious From the bot menu, /bongoshield report, or Report to BongoShield on any Cliq message — paste the text, tick what looked wrong, done.

The bot's Actions menu offers Today's question · My score · Leaderboard · My training · Report suspicious. Typing help lists the same.

Set-up (about ten minutes, once)

You need to be both a Zoho Cliq org admin (to install org-wide and to generate a webhook token) and a BongoShield Owner or Admin (to pair). All of this is done once per organization.

1 — Install the extension. In BongoShield open Settings → Integrations → Zoho Cliq and use the Install BS Security Coach link there. (The link lives inside your BongoShield admin — it is not posted publicly.) On the Zoho screen, choose Install for the entire organization and leave Auto-update ticked. Zoho shows a "not verified by Zoho" note for private extensions — that is expected; continue.

2 — Pair with BongoShield. On the same Zoho Cliq card click Generate pairing code (valid 15 minutes, single use). Open the coach in Cliq and type:

/bongoshield connect ABCD-1234

You'll get "✅ Paired with BongoShield for <your company>." Only a BongoShield Owner/Admin can mint a code, so nobody else can re-point your organization.

3 — Let the coach message people (webhook token). In Cliq: your profile picture → Bots & Tools → Webhook Tokens → Generate New Token (Zoho asks for 2-factor). Copy it, paste it into the Cliq webhook token field on the BongoShield card, pick your Cliq region (.com, .eu, .in, .com.au, .jp) and Save. Treat this token as a secret.

4 — Send test to me. Click it on the card. A card from BS Security Coach lands in your Cliq DM within seconds. (It is sent to the email of whoever is signed in to BongoShield, so sign in as a person who is also in Cliq.)

5 — Roll out to staff. Zoho only lets a bot DM people who are subscribed to it:

  • New joiners — Cliq Admin Panel → Organization → Configurations → Integrations → Set Default Bots → add BS Security Coach. Everyone who joins afterwards is subscribed automatically.
  • Existing staff — post the bot's link in a company channel and ask people to tap Subscribe (one click). Anyone who hasn't shows as unreachable on the BongoShield card until they do; it clears itself once they subscribe.

6 — Tune. On the same card: daily send time + timezone, the afternoon reminder, which coaching nudges to send, and whether broadcasts go to Cliq. You can pause everything any time with the Coach enabled switch.

Announcements channel (optional)

Point the coach at one Cliq channel and it will post your admin broadcasts and a weekly top-10 leaderboard there — on top of, not instead of, the personal daily question in each employee's DM.

  1. Create an incoming webhook. In Cliq, open the channel you want → ⋯ (More info) → Bots & Tools → Webhook Tokens → Generate New Token (a token belongs to a user; that user must be a member of the channel). Easiest: type the channel name and click Use my push token** — the token from step 2 works for channels too. URL it gives you (it looks like https://cliq.zoho.com/api/v2/channelsbyname/<channel>/message?zapikey=…).
  2. Paste it into BongoShield. Go to Settings → Integrations → Zoho Cliq → Announcements channel, enter a channel name and paste the webhook URL, then Save and Send test post to confirm it landed. The webhook's zapikey is stored encrypted and is never shown again — use Replace token if you ever need to rotate it (paste a new webhook URL or a bare zapikey).
  3. Tune it. On the same section: toggles for Post broadcasts here and Post weekly leaderboard, plus the weekday and time the leaderboard goes out (default Monday 09:00, org timezone). Remove stops both and deletes the stored token.

The weekly leaderboard shows first names only, the top 10 by points for the current month's season, and how many people played this month — never a full name list or individual answers.

What is posted there / what never is

Posted to the channel Never posted to the channel
Admin broadcasts (no Got it button — acknowledgement stays in the personal chat) The daily question, or anyone's answer
Weekly top-10 leaderboard (first names, monthly season) Individual scores, streaks or risk data
— Nudges (streak, sim click/report, training)

@BS Security Coach score, training, today or leaderboard typed in a channel or group chat is answered with a private DM to the person who asked, plus a short one-line reply in the channel pointing them to it. Only help and report reply directly in the channel. Report to BongoShield on a channel message works the same as it does everywhere else.

Broadcasts sent from Popup Broadcast default to "Also post to the announcements channel" switched on — turn it off per-broadcast for anything that shouldn't go beyond personal chats.

Existing installs: re-publish the mention handler

This feature needs bot_mention.dg to tell BongoShield whether an @mention came from a channel, a group chat or a 1:1 DM. If your extension was installed before this shim shipped, ask BongoShield (or your Cliq admin, if you self-host the extension) to re-publish it in the Zoho console. Until then, mentions in channels are treated like DMs — a @BS Security Coach score in a public channel would answer with the asker's personal data instead of routing it privately.

Good to know

  • The question, scoring, streaks and risk score are the same as every other BongoShield channel. If someone already answered today in Outlook or the portal, the coach doesn't ask again.
  • Reporting a BongoShield phishing simulation credits the campaign and the employee; reporting a real suspicious message files it for your security team. The employee sees the same acknowledgement either way, so the tests stay realistic.
  • Disconnect on the card revokes the pairing and stops all messages.

Who the posts appear from

Channel posts appear as BS Security Coach (name and icon), even though Zoho technically sends them with the admin's webhook token. Personal questions and scores are never posted in a channel.