I wonder if phishing simulations are allowed. There's nothing explicit in the code of conduct (at least none that I could find with a quick search). Smishing sims are a great way to train staff on phishing, and disallowing them would be somewhat antithetical to their explicit mission here of protecting they users.