For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
The ERM risk register connector is part of the Integration Hub. It is for an enterprise risk register with a REST API and no dedicated Coverbase connector. You describe the register’s create and update endpoints, and Coverbase pushes a risk per rated vendor. It writes only; it reads nothing back.
What it pushes
- Vendor risk: every vendor with a residual or inherent risk level, plus every vendor already pushed.
Every value is written as text. A value with a blank target is not written.
Status read back
This connector does not read anything back.Authentication
The register takes an API token in a header you name.- Create an API token for Coverbase in the register.
- Note the path that creates a risk (for example
/risks), the path that updates one with{id}in it (for example/risks/{id}), whether updates usePUTorPATCH, and the key in the create response that holds the new risk’s ID (a dot path reaches into nested objects). - Note the JSON key for each value Coverbase should send.
Set up in Coverbase
- Open Configuration → External Integrations and click ERM Risk Register, or open it from the GRC and ERM category of the Integration Hub.
- On Authentication, enter the Instance URL and API Token. Under Risk Register Endpoint, set the Token Header (Authorization sends the token as a bearer token), the Create Path, the Update Path, the Update Method and the ID Field. Paths start from the instance URL’s host.
- Turn on Push findings and vendor risk to ERM Risk Register, set the Sync Interval (Minutes), click Save, then Test connection.
- On Field Mappings, check the JSON key for each value under Vendor Risk (dot paths nest), and Save mappings.
- Click Sync now and read the Sync Log.
When a response is not what Coverbase expects
A create response without an ID at the key you named fails that record, with the reason in the sync log.Related
Integration Hub guide
Field mappings and the sync log.
Integration platforms
Building your own sync on the API instead.
Findings and remediation
The findings pushed as issues.
Integration credentials and signing
How the credentials are stored.