There is a wrong way to run phishing simulations, and a lot of programs do it. They treat the test like a trap. They send a tricky email, they catch people clicking, and then there is a list, and the people on the list feel singled out and stupid. That approach trains one thing reliably, and it is resentment. People learn to hate the security team, not to spot phishing.
I think about it the opposite way. A simulation is a teaching moment, and the whole point is the moment right after the click. That is why Edventory's security awareness side is built around what happens next, not just the catch. When someone clicks, they land on a teachable page and get training, in the moment, when the lesson actually sticks. The content library has email templates, landing pages, and training lessons, so you can run a real program with a teaching arc instead of a one off gotcha.
The goal is not to produce a list of people who failed. The goal is staff who are a little harder to fool next month than they were this month. Phishing is relentless in schools because attackers know we are busy and trusting. The answer is not to shame busy people for being human. It is to give them quick, repeated, low stakes practice at recognizing the thing, so that when the real one lands, some part of their brain pauses.
Test your people, absolutely. But test them to teach them. A program that makes staff feel hunted will not make them safer. A program that makes them a little sharper every month will.