For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It is the reference for what your admins can change themselves. For the order to do it in on a new environment, see Admin and setup.
Custom fields
Add fields of your own to capture what your program tracks and Coverbase does not ship as standard: an internal tier, a regulatory scope flag, a risk-exception owner, a business-line code, a review date.Nine object types
Fields can be defined on vendors, services, assessments, controls, evaluations, contracts, tasks, reviews and engagements. Each object holds one value per field definition.
Seven value types
Text, number, date, yes/no, single select, multi select, and user reference. Select fields carry the option list you define.
Grouped into sections
Fields are organized into named, ordered sections, and a section is applied to the object types it belongs on, so a vendor form and a contract form show different things.
Filterable and reportable
A custom field is a first-class field. It appears in the Add filter menu, in saved views, in sorting, in workflow conditions, and in the query and export APIs, under the same path everywhere. See the field reference.
Record types and lifecycle states
Coverbase’s own objects are the record types, and their vocabulary is configurable.Relationships
The relationship graph is part of the model, not a flat list of vendors.- Vendor → service → engagement → contract. A vendor can hold many services, each with its own risk profile, owners, and assessments; engagements bind a service to a business use; contracts hang off the relationship and resolve into components.
- Legal entities. A vendor is matched to real corporate entities from registries, so the paper, the payments and the screening all attach to the entity that signs.
- Nth-party relationships. A vendor’s own suppliers are recorded as relationships, so concentration and fourth-party exposure are queryable rather than anecdotal.
- Documents, findings, obligations and reviews attach to whichever level they belong to and roll up.
- Your own references. External IDs are carried on records so a Coverbase vendor and its row in your ERP, CMDB or GRC platform stay joined.
Assessment content
Control sets
Fork any of 68 library templates spanning 4,337 curated controls, or author your own from scratch. Your copy is fully editable: add controls, re-section, change weights, attach evidence sources.
Questionnaires
Build the inherent-risk questionnaire and any vendor-facing questionnaire, including branching, scoring, and per-section reviewers.
Clause sets
Your contract playbook: reference clauses with tiered fallback language, authored by hand, forked from the library, or extracted from your own template paper.
Report templates
Upload your own Word deliverable with placeholders and Coverbase fills it per assessment.
Automations
The Workflows section of the dashboard is a no-code designer. You compose a trigger, any number of conditions, and the actions that follow, then activate it. Workflows are versioned, each run is inspectable step by step, and the same definitions are readable and writable over the API. Nothing about the orchestration layer is locked after go-live. A workflow can be edited, disabled, cloned or replaced by an admin at any time, and a running instance can be interrupted or redirected. See Workflow engine.What still involves Coverbase
Where the line sits between self-serve and Coverbase-assisted work, for when you are planning a program:Related
Admin and setup
The setup sequence, in order, for a new environment.
Field reference
Every field, its path, and where it can be used.
Reviews, approvals and gates
Configuring the decision points themselves.
Permissions and roles
Custom roles built from resource, action and scope.