This guide describes how to configure Smart Banners for your company, from verifying the initial state through banner activation. When complete, your email provider (Google Workspace or Microsoft 365) is connected, at least one mailbox has received a test banner, and mailboxes are progressively activated (engaged), so recipients begin seeing risk banners (gray, yellow, red) on incoming messages. All operations take place in Smart Banners › Setup, in the Setup Checklist tab.
Prerequisites
- Smart Banners is enabled for your company with an email provider already assigned (Google Workspace or Microsoft 365). This operation is performed by LibraCyber and is not self-service: until it is completed, the Smart Banners area shows an introductory screen instead of the checklist.
- LibraCyber already has general authorization to process your company's mail, granted once in General Settings › Users provisioning. Without it, the Setup Checklist does not load and redirects to that page.
- For the historical analysis and sample email sending steps, the CEO / Key People field in your company is filled in Company Scan.
- You need the Smart Banners permission in the LibraCyber console: it is an assignable and revocable permission, and your company decides who holds it.
Before You Start
- WARNING: the email provider (Google Workspace or Microsoft 365) is assigned only once by LibraCyber and is not chosen on this page. Changing it later requires first disengaging all users and is not a self-service operation.
- WARNING: Test Deployment and Send sample emails send real emails to real mailboxes. They are not previews. Instructions on actions that are difficult to undo (safelist, Auto Engage) are provided at the respective steps.
Detailed Procedure
The seven steps do not need to be executed in order: the checklist on the left allows you to jump directly to any step.
1. Company Setup — Status Verification
This step is a read-only indicator: there is nothing to click. The Controller row shows the assigned provider (the label "GMAIL", "OFFICE", or "DEMO") with a green checkmark if present, or a warning triangle if missing. The Company is setup for Banners row shows a green checkmark when the LibraCyber-side configuration is complete, or a triangle while in progress. If a warning appears, contact LibraCyber support: there is nothing you can correct on your own.
2. API Access Setup — Provider API Access
What is displayed depends on the provider detected in step 1.
Google Workspace: if the dedicated Gmail service account is not yet ready, User Service Account not setup appears with a warning triangle: contact LibraCyber support. When ready, the service account's Account ID and the How to grant Consent button are shown, which opens the tutorial for granting domain-wide delegation in your Google Admin console. You need a Google Workspace administrator with sufficient privileges to grant domain-wide delegation (typically a Super Admin). After granting it, select the I confirm I have given access to the service account checkbox.
NOTE: this confirmation is a self-declaration. The checkbox does not re-verify access on the Google side: if the delegation was not actually granted in the Google Admin console, banners will not work even with the checkbox checked. The checkbox is reversible at any time.
Microsoft 365: this step may already be completed (status It works!) or show a Not connected status with the Grant Provisioning Permissions button. Check the status actually displayed: if not connected, click Grant Provisioning Permissions and complete the Microsoft consent screen with an administrator account able to grant tenant-level consent (typically a Global Administrator). Unlike Google Workspace, there is no separate confirmation checkbox.
NOTE: LibraCyber obtains only the access necessary to read and modify incoming mail to detect risks and prepend the banner. The permissions requested are visible in the Google or Microsoft consent screen and can be revoked from your provider's console.
3. Test Deployment — Sending a Test Banner
Prerequisite: at least one mailbox activated (engaged). If there are none, click Engage one User to go to the Users page; you also need general authorization to process mail (see Prerequisites). Click Test deployment: LibraCyber sends a test email to your mailbox with a green test banner. When complete, a message indicates the address to which it was sent; after verifying receipt, select I confirm I have received an email with a green banner in my inbox. The test can be repeated at any time.
NOTE: the test banner is green, different from the three colors (gray, yellow, red) that recipients normally see. This is expected behavior, specific to this step.
4. Run historical analysis — Historical Analysis
Select up to 100 mailboxes (the selector does not allow more) and click Analyze. LibraCyber analyzes approximately the last 3 months of mail for each selected mailbox. Processing occurs in the background and may take several minutes; the analysis list allows you to download each report when ready. The report lists senders that would have triggered at least one banner, with a count by color (gray, yellow, red); senders that would not have triggered any banner are not listed. Analysis never adds a real banner to messages: it only produces a report and is repeatable.
5. Define your safe lists — Safe List Definition
This step redirects to the Preferences tab via the Safe Lists button: adding and removing senders and domains is managed there. The step is marked complete when the company has at least one sender or domain in the safelist.
WARNING: a safelist disables banners for all users until its removal, so its effect is difficult to undo. Carefully verify an address before adding it. Removal is done from the Preferences tab, not from this checklist.
6. Send sample emails — Sending Sample Emails
Select one or more phishing scenarios and one or more already-activated recipients, then click Send sample emails. Each scenario is available in English and French and is designed to trigger a specific signal, in addition to the first-time sender signal (First Time Sender). The step shows Test emails already sent with a green checkmark when at least one send has succeeded. The operation is repeatable.
WARNING: if the CEO / Key People field (in Company Scan) is empty, sending fails with an error indicating the missing field. Fill in Key People and try again.
7. Engage Company — Company Activation
Toggle Enable Auto Engage to automatically and progressively activate each new mailbox; activation occurs periodically and manually deactivated users are always excluded. The chart shows the current distribution between activated, deactivated, and disabled mailboxes. After activation, the toggle remains on when you reload the page and new mailboxes are activated over time. The operation is reversible: disabling the toggle keeps already-activated mailboxes active and only stops future automatic activation. To activate a single mailbox immediately without waiting for the automatic cycle, use the Users page.
Verification
At this point the configuration is working when you have received the Test Deployment email with the green banner and/or a sample email has correctly triggered a yellow or red banner, and at least one mailbox is activated. In the following days, the Dashboard counters (processed emails and emails with banners) begin to increase, confirming that real mail is being analyzed. For company-wide verification, use the chart in the Engage Company step, the Dashboard, or the Users page.
Troubleshooting
| Symptom | Probable Cause | Solution | Escalation |
| An introductory screen appears instead of the Setup Checklist | Smart Banners is not yet enabled for your company, or no email provider is assigned | Request activation of Smart Banners and confirmation of the email provider | Contact LibraCyber support |
| Controller or Company is setup for Banners show a warning triangle | LibraCyber-side configuration is not yet complete | No action required on your part | Contact LibraCyber support |
| User Service Account not setup warning (Google Workspace) | The dedicated Gmail service account has not yet been created | No action required on your part | Contact LibraCyber support |
| Not connected status, or Grant Provisioning Permissions button that does not disappear (Microsoft 365) | Administrative consent for the mail processing app has not been granted in the Microsoft 365 tenant | Click Grant Provisioning Permissions and complete the Microsoft consent screen with a Global Administrator account | — |
| The Test Deployment email does not arrive | No mailbox is yet activated, general mail processing authorization is missing, or the message ended up in spam | Activate at least one mailbox, verify permissions in General Settings › Users provisioning, check spam, and try again | Contact LibraCyber support if sending continues to fail |
| Sample email sending fails with an error related to the "ceo" field | The CEO / Key People field is empty in Company Scan | Fill in Key People and try again | — |
| A sender or domain in the safelist still triggers a banner | Some bulk sending services rewrite the sender header, so the displayed address does not match the actual technical address checked by the safelist | Add all addresses and domains that appear for that sender to the safelist | — |
| The historical analysis selector does not allow choosing other mailboxes | Selection is limited to 100 mailboxes per run | Run multiple successive analyses for the remaining mailboxes | — |
Periodic Maintenance
- After modifying or renewing your Google Workspace or Microsoft 365 administrative credentials, first recheck the API Access Setup step: a broken consent appears there.
- Periodically review Engage Company (or the Users page) to ensure new hires are activated, especially if Auto Engage is disabled.
- Periodically re-run historical analysis to keep the safelist updated as new legitimate bulk senders appear.