Playbook ┬╖ 6 minute read
How to Build a Phishing Triage Agent for Reported Email
A phishing triage agent analyses user-reported messages in an isolated environment, produces a verdict with calibrated confidence, replies to the reporter within minutes, detects whether the message is part of a broader campaign, and proposes remediation. Mailbox removal and user-impacting actions stay under human authority.
User-reported phishing is one of the few security controls that depends entirely on voluntary human behaviour, and organisations reliably degrade it by responding slowly. Reports queue, users hear nothing, and reporting rates fall over a year until the channel is decorative. An agent that analyses safely, responds in minutes, and hunts for campaigns addresses both the queue and the behaviour. This guide covers building one, drawing on FISTA Solutions' AI agents work in security operations. It complements how to build a security alert triage agent and the AI security operations whitepaper. This article is general guidance, not legal advice.
Why is reporter feedback the design centre?
Because the control is behavioural. Users report because they believe it matters. A report acknowledged by an automated receipt and then answered four days later тАФ or never тАФ teaches the opposite, and the lesson spreads through teams faster than any awareness campaign counters it.
Response within minutes, saying specifically what the message was and what was done, sustains reporting. It also produces a second effect: users who receive specific explanations get better at recognising the next one.
| Element | Manual reality | With an agent |
|---|---|---|
| Time to verdict | Hours to days | Minutes |
| Reporter feedback | Often none | Immediate and specific |
| Campaign search | Rarely performed | Automatic |
| Analysis depth | Varies by analyst | Consistent |
| Remediation proposal | Manual | Assembled, human approved |
| Reporting rate trend | Declining | Sustained |
What does safe analysis require?
Isolation. Attachments detonated in a sandbox with no route to production. Links followed from infrastructure that does not identify the organisation. Nothing rendered in a context where content can execute against real credentials.
Careless analysis causes real harm: following a tracking link confirms the address is live and increases targeting, and opening an attachment in a convenient environment is how an analysis workstation becomes the initial access. The isolation requirement is absolute and it should be verified, not assumed.
Why is campaign detection the highest-value step?
Because one report means many deliveries. The user who reported is rarely the only recipient, and the others either did not notice or have already clicked. Searching the estate for related messages тАФ same sender infrastructure, similar content, matching indicators тАФ converts one person's diligence into estate-wide protection.
This is the step manual triage skips first when the queue grows, and it is the step that determines whether a campaign is contained or discovered later through its consequences.
What makes classification genuinely hard?
Legitimate marketing email. It uses tracking links, redirect chains, urgency language, unfamiliar sending infrastructure, and requests for action тАФ the identical signal set. Classifying it as phishing blocks business communication and erodes trust in the system; classifying real phishing as marketing is worse.
This is where calibrated confidence earns its place: ambiguous cases should route to an analyst with the ambiguity stated rather than resolving to a confident guess in either direction.
What about targeted attacks?
Business email compromise and spear phishing frequently contain none of the technical indicators the analysis relies on. No attachment, no malicious link, no suspicious infrastructure тАФ just a plausible message from a plausible sender asking for a payment change.
Detection here depends on relationship and behaviour context: has this sender corresponded before, is the request consistent with their role, does the reply-to differ from the sender. Those checks must be explicit, because the technical pipeline will return clean.
What remediation stays human?
Bulk removal from mailboxes, blocking domains with business relationships, and anything affecting large populations. A wrong bulk action removes legitimate correspondence at scale, and the recovery is worse than the original risk.
The workable pattern has the agent assemble the remediation тАФ the exact message set, the recipients, the proposed action тАФ for a human to authorise in one step. That preserves speed without handing over the destructive capability.
How is confidence calibrated?
Against analyst decisions and outcomes, tracked continuously. The verdict set should be small and meaningful тАФ malicious, suspicious, legitimate, marketing тАФ with confidence that has been measured rather than asserted. Calibration drift is a signal that the threat mix has changed and the system needs attention.
How does it integrate?
With the reporting mechanism users already have, the email security platform for search and remediation, the sandbox for analysis, and the case management system for anything escalated. Users should keep using the report button they know.
How is it evaluated?
On time from report to reporter response, time from report to campaign containment, verdict accuracy against analyst review, calibration error, reporting rate trend over time, and click rate on messages reported by someone else. That last metric captures whether campaign detection is working.
What does the build sequence look like?
Two weeks on safe analysis infrastructure, which must be right before anything else. Two weeks on verdict generation with a calibration harness. One week on reporter feedback, which delivers the behavioural benefit immediately. Two weeks on campaign search. Remediation proposal and authorisation workflow last.
What goes wrong?
Analysis in an insufficiently isolated environment. No reporter feedback. Skipped campaign search. Confident classification of ambiguous marketing. No behavioural checks for business email compromise. Automated bulk removal. And measuring reports processed rather than reporting rate sustained.
What does it cost to run?
Low per report; sandbox capacity is the main variable cost and it is predictable. The programme cost that matters is analyst time on the ambiguous minority and on calibration review, which should be budgeted rather than assumed away by the automation.
What should you do first?
Plot your reporting rate over the last two years against your median time to respond. In most organisations the two are visibly related, and that chart is a more persuasive business case than any projection of analyst hours saved.
What does good look like after six months?
Median time from report to reporter response measured in minutes rather than days, campaign search running on every report without exception, reporting volume stable or rising, and analyst attention concentrated on the ambiguous minority and on targeted attacks that carry no technical indicators at all.
How FISTA Solutions helps
FISTA Solutions builds phishing triage systems with verified isolated analysis, calibrated verdicts, minute-scale reporter feedback, estate-wide campaign search, explicit behavioural checks for business email compromise, and human-authorised remediation, through AI agents, AI enablement, and forward deployed engineers. The record behind the approach is 150+ projects for 50+ companies with 99.9% uptime.
To keep your users reporting and your campaigns contained, message FISTA on WhatsApp, or read how to build a security alert triage agent.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01Why does reporter feedback matter so much?
Because reporting is voluntary and users calibrate on response. A report acknowledged after four days teaches the user that reporting achieves nothing, and reporting volume declines quietly. Fast, specific feedback sustains the behaviour the whole programme depends on.
02What does safe analysis require?
Isolated execution: detonating attachments and following links in a sandboxed environment with no path to production, using infrastructure that does not reveal the organisation. Analysis performed carelessly can confirm an address is live or trigger the payload it was examining.
03Why is campaign detection the key output?
Because one report usually means many deliveries. Searching the estate for related messages converts a single user's diligence into estate- wide protection, and it is the step manual triage most often skips under queue pressure, which is exactly when a campaign is spreading fastest.
04What makes marketing email hard to classify?
Legitimate marketing uses tracking links, redirect chains, urgency language, and unfamiliar sending infrastructure тАФ the same signals as phishing. Getting this wrong in either direction is costly, and it is where calibrated confidence earns its place.
05What remediation should stay human?
Bulk removal from mailboxes, blocking senders or domains with business relationships, and anything affecting large user populations. A wrong bulk action deletes legitimate business correspondence at scale, and recovering from it is worse than the original risk. This is general guidance, not legal advice.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. WeтАЩll map the fastest credible path from intent to verified production.