Corporate Training Manager
Training assignments, compliance tracking, completion reporting
Collaborators
philcal (project owner)
How do I use this software?
This software runs wherever suits you — you just need somewhere to host it. Pick the option that fits your team:
| Option | What it means |
|---|---|
| Self-hosting | Set up the environment and run it yourself, on your own infrastructure. |
| Tooltwist hosting | Tooltwist can host and run it for you. |
| Other providers | Find a host in the provider directory — or, if you already have a support company, we're happy to give them the tools to deploy the application for you. |
Licensing
This variant is open source — you're free to use it and modify it at no cost. Hosting and support arrangements are provided separately and are not covered by this licence.
Who can help me?
Plenty of people can help you get the most from this software — browse the provider directory. Some providers can host it for you, others can customise it to your needs, and others again offer technical support and a helpdesk.
Tooltwist can host and customise the software for you, and Twist Teams provides technical support services.
Already have a support provider? We're happy to give them the tools to fully support the platform.
Not sure who to ask? Feel free to .
How can I help?
If you would like to help develop or test this project, go to the Collaborators tab (after you log in) and request to join. Your help will be appreciated!
Read me first
A plain-English introduction to Corporate Training Manager. If you have just been handed this project and you are not a software developer, start here.
This document describes what the software actually does today, not what is planned. Where something is not built yet, or does not work in the trial version, it says so.
1. Who this is for
This is for the person in an organisation who has to be able to answer the question: "Can you prove everyone who needed that training has done it?"
Typically that is:
- Compliance managers and Learning & Development managers in regulated industries — financial services, healthcare, manufacturing, energy — who are accountable when a regulator, auditor, or board asks for evidence.
- Operations leaders in multi-site organisations who need the same induction and safety training to happen consistently across every site.
- HR teams responsible for making sure new starters complete mandatory training, and that existing staff renew it before it lapses.
It is also used, day to day, by line managers watching their own team's progress and by employees completing the training itself — but those two groups are not the buyers. The buyer is the person carrying the risk.
You do not need to be technical to use this software. You will need somebody technical to install it and connect it to your systems the first time.
2. What it does
In one sentence: it works out who in your organisation needs which training, assigns it automatically, tracks whether they did it, and produces evidence you can hand to an auditor.
Concretely:
- You write a rule once — for example, "everyone working at the London site must complete Fire Safety within 30 days of joining, and again every year."
- The software finds everyone who matches that rule and assigns the training to them, immediately and from then on. New starters who match are picked up automatically. Nobody maintains a spreadsheet.
- Employees see a short list of what they owe and when it is due, and complete the training in the browser.
- Managers see how their team is doing, and can open any individual's record.
- Administrators can produce a compliance export — a file listing who completed what, when, and with what score — that can be reproduced identically later, which is what makes it usable as audit evidence.
- Everything that happens is written to a permanent record that cannot be edited afterwards.
Two things it deliberately does not do: it does not chase people with alarms and warnings, and it does not reward employees for doing something they were obliged to do anyway. It states facts plainly and stays out of the way.
3. The domain: mandatory workplace training
If this field is new to you, this is the shape of it.
Most organisations of any size are legally or contractually required to train their people on certain topics — fire safety, manual handling, data protection, anti-bribery, modern slavery, safeguarding, information security, and so on. The specific obligations come from regulators, from legislation, from industry bodies, or from a customer's contract terms.
Three characteristics make this different from ordinary training:
It is not optional. The employee did not choose it. It is an interruption to their real job. Often it is done on a shared computer on a factory or warehouse floor, not at a comfortable desk.
It expires. Most compliance training is only valid for a period — commonly a year — after which the person must do it again. This is called re-certification. A large part of the work is simply keeping track of who is due to renew, and when.
The evidence matters as much as the training. When something goes wrong — an accident, a data breach, an investigation — the organisation must show that the person involved had been trained, and prove it with dated records. "We think they did it" is not a defence. This is why the record-keeping in this software is deliberately strict: entries cannot be quietly edited or deleted, and exports are reproducible.
The software that manages this is called a Learning Management System, or LMS. The established products in this space are expensive, slow to roll out, and generally unpleasant to use. That is the reason this project exists.
4. Where it fits
The organisations it suits. Small to mid-sized organisations, and departments inside larger ones, that have real compliance obligations but cannot justify a six-figure enterprise platform and a six-month implementation. It works for a single site or many.
How your people sign in. The software does not store passwords and never shows a password box. Signing in is delegated to a separate identity service, so your people use an account they already have. Connecting it directly to your own corporate directory — Microsoft Entra, Okta, and similar — is planned but not built yet.
The training content itself. This is important, and it is one of the main reasons to choose this product. Corporate Training Manager does not force you to re-create your existing courses. It plays training packages built to the common industry standards — known as SCORM (both the 1.2 and 2004 versions), xAPI, and cmi5 — which is the format most off-the-shelf compliance courses are sold in. If you already own a library of courses, they should work here without being rebuilt. Two older or more specialised standards, AICC and LTI, are not supported yet.
Other systems. Today the software is self-contained: you tell it who your people are, and it manages training for them. Automatic staff syncing from an HR system (Workday, BambooHR, SAP SuccessFactors), selling courses to external customers, and a skills-and-competency framework are all planned but not built. If your HR system is the master list of employees, expect to keep the two in step yourself for now.
Where it runs. It is designed to run either as a trial on a single computer, or hosted properly for real use. It is not a service you sign up to; it is software your organisation runs.
5. First run — the very first thing to do
Try the demo before you set anything up. There is a self-contained trial version — a single package containing the application and its database, with a fictional company called Northwind already loaded: around fifty employees, a dozen courses, existing assignments, completions, failures, overdue items, and an audit history. Nothing needs to be connected. You can click around a realistic system in a couple of minutes rather than staring at an empty one.
Ask whoever set this up to start the trial version for you — the exact commands
are in preview/README.md in the project. Two practical points they will need to
know:
- Sign-in on the trial version needs a decision. The trial ships with real sign-in switched on, but it is not connected to an identity service out of the box, so it will not let you in as delivered. For evaluation there is a documented switch that lets you sign in as any of the demo employees without a password. It is deliberately off by default, only works on your own machine, and cannot be turned on for a real deployment.
- Nothing you do in the trial is permanent. Stop the trial and everything resets to the same starting state. Create rules, break things, explore freely.
What to look at first, in this order — it takes about ten minutes:
- Sign in as an ordinary employee and look at Assigned to me. This is what most of your workforce will ever see.
- Sign in as a manager and open the team dashboard. Note that every percentage shows the figures it was calculated from.
- Sign in as an administrator, open Assignment rules, and create one. Then go back to an employee's list and see the new course already there.
- Open the Audit trail and see your rule, and every assignment it created, recorded with timestamps.
If those four things make sense to you, you understand the product.
6. Setting up for real
This section describes preparing a genuine environment for your organisation. Steps marked (technical) need someone comfortable with servers; the rest are yours.
a. Have it installed and initialised. (technical) A production environment is prepared by an initialisation step that creates exactly one organisation and one administrator — you — and nothing else. It refuses to run against a database that already has data unless explicitly forced, so it cannot quietly destroy an existing system. The full procedure is in PRODUCTION-SETUP.md.
b. Sign in for the first time. You will be asked for the email address given during initialisation. That first successful sign-in permanently links your account to your identity. The email must match exactly and must be verified. If it fails, PRODUCTION-SETUP.md lists the three usual causes.
c. Describe your organisation. Build out your departments and sites. This structure is what rules target later, so it is worth getting roughly right before you add people — though it can be changed at any time.
d. Add your people. Each person needs an email address, a department, a site, a role in the system, and — importantly — who they report to. Manager dashboards are built entirely from that reporting line: if it is wrong or missing, managers see the wrong team or no team at all. There is no automatic import from an HR system yet, so this is a deliberate exercise.
e. Load your courses. (technical for the first one) Upload the training
packages you already own, in SCORM, xAPI, or cmi5 format — usually a single ZIP
file per course from your content supplier. Guidance is in
collateral/integration/scorm-xapi-content-onboarding.md.
f. Write your rules. This is the step that makes everything else work. For each obligation, create one rule saying which course, who it applies to (any combination of job role, department, and site), how long people have to complete it, how often it must be renewed, and who should be told if it goes past due. You can also record which regulation the rule exists to satisfy — useful when somebody later asks why this training is mandatory.
Start with one rule, confirm it assigns the people you expect, and then write the rest. A rule that is too broad will assign training to people who do not need it, and they will do it.
g. Set up your reports. Schedule the recurring reports the organisation actually reads — for example a weekly overdue summary to department heads. Choose the recipients, the format, the day, and the time.
7. Day to day
Once running, the software needs much less attention than the setup implies. Ordinary weeks look like this.
For employees. They sign in and see one list: what is assigned to them, its status, and when it is due. They open a course, complete it, and it is recorded. If they stop halfway through, they resume where they left off. There is nothing else for them to learn.
For managers. They open their team dashboard: what proportion of their team's required training is complete, how many items are past due, how their people are doing on assessments, and how many people report to them. Every figure shows the numbers behind it. Clicking a person opens their individual record — every course they have been assigned, its status, the due date, when they completed it, and what they scored. The usual weekly job is to look at the overdue count and have a conversation with anyone in it.
For administrators. Most days, nothing. The rules keep assigning; the reminders keep going out. The recurring work is:
- Adding new starters and updating people who change department or site, so their training follows them.
- Adding or replacing courses when content is updated.
- Adjusting rules when an obligation changes.
- Answering the occasional "did this person do that training?" — which is a lookup, not an investigation.
When something is disputed or wrong. If a completion record turns out to be incorrect, it is corrected, not edited: the original stays in the history and a new record supersedes it. Certificates can be revoked the same way. This is deliberate — an audit trail that can be rewritten is worthless.
8. Ongoing care
Weekly. Glance at overdue figures. This is the number that tells you whether the system is working socially as well as technically — a rising overdue count usually means a rule is assigning training to people who should not have it, or a manager is not looking at their dashboard.
Monthly. Check that your people list still matches reality — leavers removed, movers moved, reporting lines correct. Everything downstream depends on it.
Quarterly. Re-read your rules against your actual obligations. Regulations change and rules quietly go stale. Confirm the renewal periods still match what your regulator or insurer expects.
Annually, and before any audit. Produce a compliance export covering the period and keep it. It is worth doing this before you are asked, so that the first time you run one is not under pressure.
Continuously, by someone technical. Back up the database — it is the system of record and the only irreplaceable thing here; everything else can be rebuilt. Keep the software updated. Watch that scheduled reports are actually being delivered, since a silently failing report is indistinguishable from good news.
User roles
Four roles, deliberately few:
| Role | What they can do |
|---|---|
| Learner | See and complete their own assigned training. Nothing else. |
| Manager | Everything a learner can, plus their own team's figures, individual drill-down, and scheduled reports. They see only their own reports — this is enforced by the system, not by hiding a menu. |
| Content author | Upload and manage training content. |
| Administrator | Everything: rules, people, the audit trail, and compliance exports. |
What ships with the trial version
The trial contains a fictional company, Northwind, with about fifty employees, a dozen compliance courses, a set of assignment rules, and a year of history — completions, failures, overdue items, certificates, and audit entries. The data is realistic on purpose: dashboards show numbers that are neither perfect nor alarming, which is what a real organisation looks like.
To start fresh, simply restart the trial: it resets to the same starting state every time, because it deliberately keeps nothing. That is also why you should never put real data into it. A genuine environment is created empty by the initialisation step described in section 6 — the demo company is never installed into a real deployment.
Glossary
| Term | Meaning |
|---|---|
| Assignment (or enrolment) | One person being required to complete one course, with a due date. |
| Assignment rule | A standing instruction — this course, for these people, within this many days, renewed this often. Rules do the assigning; people do not. |
| Audit trail | The permanent, unchangeable record of everything that happened: who did what, to what, and when. |
| cmi5 | A newer standard that combines xAPI's tracking with the structure of a formal course. |
| Compliance export | A file (spreadsheet or PDF) listing who completed what training, when, and with what result — the evidence you hand to an auditor. |
| Escalation | Telling someone else — usually the manager — when training goes past its due date. |
| Grace period | Extra days after the due date before something is formally treated as overdue. |
| LMS | Learning Management System — the category of software this belongs to. |
| Overdue | Assigned, past its due date, and not complete. A fact, not an emergency. |
| Re-certification | Having to redo training periodically because the previous completion has expired. |
| SCORM | The long-established packaging standard for e-learning content. Most bought-in compliance courses come as SCORM. |
| Transcript | The full history of one person's training. |
| xAPI | A modern standard that can record learning activity from outside a formal course. |
Common questions and gotchas
Nobody was assigned anything when I created my rule. The rule matched no one. The usual cause is that the job role, department, or site you typed does not exactly match what is recorded against your people. Leaving a field empty means "everyone" — which is usually not what you want.
A manager says their dashboard is empty. Manager dashboards are built from the reporting line. If nobody is recorded as reporting to that person, they will correctly see nothing.
Why can't I play any courses in the trial version? The trial has course records but no actual course files, and no file storage attached, so opening a course shows an error rather than content. Everything built on the record of training — assignment, tracking, reporting, audit, export — works fully. Content playback needs a properly configured environment with file storage.
Why did my export come out identical to last month's? If you gave it the same filters and the same point-in-time cut-off, that is correct and intentional. Reproducibility is the feature: an auditor can re-run your export and confirm it matches.
Can I edit a completion record? No — deliberately. You can issue a correction that supersedes it. The original stays visible in the history.
Can I delete an employee who has left? Their personal details can be removed on request — the software supports erasure for data-protection purposes. The training record itself is retained in anonymised form, because deleting it would destroy the evidence the system exists to hold.
Emails are not arriving. Reminders and scheduled reports need a mail server configured. This is not set up in the trial version, and is a setup step for a real environment.
Is any of this in another language? Not yet. The interface is English only, though it is built so that translation can be added later. Dates and overdue calculations do respect each person's timezone.
Where the other documents are
In user-docs/ — for people running the software:
- PRODUCTION-SETUP.md — how to prepare a real environment for first use, what safeguards exist, and what to check afterwards. Read this before setting anything up for real.
Elsewhere in the project:
preview/README.md— how to run the self-contained trial version, and its known limitations.collateral/user-guide/— a getting-started guide and a fuller user guide.collateral/integration/— connecting content, identity, and other systems.collateral/technical/— architecture, security posture, and standards support, for a technical evaluator.collateral/white-papers/— background reading on compliance automation, data protection for training records, and e-learning standards.docs/— notes for developers and operators.
Where to get help
This software is part of the World's Biggest Software Project, a community building AI-generated applications in the open.
Go to wbsp.ai. You can ask questions, suggest changes, and find people who will adapt this to your organisation if you would rather not do it yourself. It is also worth browsing what else the community has built — other people have solved problems close to yours, and one of their versions may fit you better than this one does.
If you have the domain knowledge and are willing to work with AI tools, you can change this software yourself. That is the point of it: it is a solid, honest core, built to be shaped into what you actually need rather than sold to you as finished.










