Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
These are the screen-by-screen guides for using Coverbase. Each one is written for someone with the product open in another tab who wants to finish a specific job today. There are 29 guides plus a country reference covering 109 countries. This page is the directory for all of them. Nothing below needs prior Coverbase experience, and you can read any guide start to finish on its own.
Every guide below is in the sidebar under User guides. This page is the directory if you would rather scan the whole set at once.

Start here

Pick the guide that matches your role. Most people only ever need one of these three.

I am setting up Coverbase

Admin and setup guide. Import your vendors, build tags and the intake questionnaire, tune scales and control sets, then set templates, monitoring, and integrations. This is where the AI gets its instructions.

I run vendor risk day to day

Analyst and reviewer guide. Triage requests, launch assessments, review and correct what the AI found, engage vendors, and close the loop with findings and reports.

I just need a tool approved

Requesting a new vendor. The short one, for the business requester. What you will be asked, how to file it, and why submitting a request is not approval.
An admin configures the environment once. After that, analysts run assessments against that configuration every day, and every correction a reviewer makes carries forward into future assessments.

The complete directory

All 32 pages in this section, in one place. The sections below break the same set out by job, with links into the parts of each guide people look for most.

Setting up the platform

Do this once, in order. The setup guide is the spine. The notifications guide beside it covers the settings people most often discover too late.

Admin and setup guide

Eleven steps from an empty environment to a running program. Vendors, tags, the intake questionnaire, scales, control sets, assessment plans, templates, Radar, obligations, and integrations.

Email and notifications

The full catalog of what Coverbase sends to your team and to your vendors, how each person controls their own delivery and digest schedule, and how your logo and brand colour flow into emails and vendor portals.

White-labeling your vendor-facing domain

Sending vendor email and hosting the portal on your own subdomain instead of coverbase.ai and coverbase.app, and choosing between Coverbase-managed and organization-managed DNS.

Configuring your data model

What an admin changes without a professional-services engagement: custom fields, statuses, approval options, scales, risk domains, terminology, relationships and automations.

Reviews, approvals and gates

The decision points. Configurable outcomes including approve with finding, policy exception and return for rework; parallel domain reviews; multi-approver and threshold logic; rework loops with reasons, comments and round counts.

Assignment, delegation and out of office

How a gate reaches a person: user groups, round-robin and assign-to-all routing, out-of-office windows that skip a member automatically, and the attributed assignment log.
Jump straight to a step: setup checklist · import your vendors · tag structure · build and weight the IRQ · control sets · assessment plans and cadence · configure Radar · integrations and Export API · admin quick reference Or jump into notification settings: choosing a layout · applying your branding · who receives what · the notification catalog Or set up your own domain: why white-label · Coverbase-managed DNS · organization-managed DNS

Getting a vendor in

Most vendors arrive through intake, filed by someone outside the risk team. The requester guide is deliberately short. The analyst guide picks up where it ends.

Requesting a new vendor

For the business requester, not the risk team. What you will be asked, how to file in the portal or in chat, how to get through it faster, and the thing people most often get wrong: submitting a request is not approval.

Analyst and reviewer guide

The receiving end. Nine steps covering triage, launching assessments, reviewing results, correcting the AI, vendor follow-up, disposition, contracts, Radar signals, and obligations.
Jump straight to a step: two ways to file a request · getting through it faster · triage new requests · review the results · correct the AI · follow up with the vendor · work Radar alerts

Assessing a vendor

The assessment is the centre of the platform, so it gets four pages: the full walkthrough, a cheat sheet to keep open beside it, the guide to how web evidence is vetted, and the lightweight run for vendors that do not warrant the full treatment.

How to run an assessment

The complete lifecycle, screen by screen. Getting the vendor in, creating the assessment from a plan, collecting evidence five different ways, working the issues, follow-up cycles, domain reviews, and the final export.

Assessment quick reference

The cheat sheet. Five steps, quick tips, common scenarios, a troubleshooting table, and the control frameworks at a glance.

Evidence quality and source credibility

Send this to anyone who asks how web evidence is vetted. How every page is graded for publisher accountability, where you set the minimum bar, what appears on evidence cards and in the Excel export, and exactly which parts of the platform this covers.

Zero Touch Assessment guide

A triage run assembled entirely from open-source research, with no outreach. How to run one across a portfolio, read the composite and its components, correct a run that bound the wrong company, and read the audit trail.
Jump straight to a part: get the vendor in · create the assessment · collect the evidence · work the issues · follow-up cycles · complete and export On evidence and Zero Touch: the credibility scale · where you set the bar · choosing a threshold · running a Zero Touch assessment · reading the result · reviewing a run · choosing a template

Document library

Where the Coverbase library documents on every vendor came from, how they are reviewed before they appear, and why nothing your organization uploads is ever added to them. This one sits in the product documentation rather than here.

Checking a vendor without contacting them

Five tabs sit in every vendor’s Vendor Intelligence section, each assembled from public sources without contacting the vendor, and each designed to be checked rather than trusted. There is one guide per tab, plus the older combined walkthrough the first four replaced.

Corporate registrations guide

Whether there is a real, currently registered company behind the vendor, and whether it is the one you think it is. How to read a match verdict, and what a dissolved status means on a vendor you are paying.

People intelligence guide

Who runs the vendor, and what adverse-media screening found about them. Why confirmed and unconfirmed names are counted differently, and why “not screened” is never the same as “nothing found”.

Financial health guide

How likely the vendor is to still be trading. Why the confidence tier matters more than the number, and when two scores are not comparable.

Security intelligence guide

The outside-in security rating measured against the vendor’s own infrastructure. What each factor covers, and what a not-measured factor does and does not tell you.

Sanctions screening guide

Whether the vendor or its people appear on a sanctions, watchlist, criminal or legal source, re-checked on a schedule rather than once at onboarding. Why the confidence score measures identity and not severity, and how to clear a false positive.

Financial health and security intelligence

The older combined walkthrough, covering the Financial Health Score and Security Posture cards as they appear on the fact sheet. The two dedicated guides above go deeper.
Jump straight to an answer: read the registry verdict first · a dissolved status · confirmed and unconfirmed people · no findings versus not screened · what the financial tier is worth · runway and burn · the rating is a floor · lookalike domains · identity confidence is not severity · deciding a match · screening settings

Monitoring between assessments

Radar watches your vendors in the gap between reviews. If you already pay for a ratings service, its findings can feed the same signal queue.

Black Kite monitoring guide

How to connect your Black Kite portfolio, choose which vendors are watched, and turn known exploited vulnerabilities and focus tags into alerts. Covers the two settings that decide whether monitoring keeps up with a large portfolio, and why a source on its own does not raise anything.
Jump straight to a step: connect your credentials · decide which vendors are watched · create a detector · fix a vendor that will not match · turn it off Radar signals land in the analyst’s queue, and working them is step 8 of the analyst guide. Setting Radar up in the first place is step 9 of the admin guide. Concentration is the other thing to watch between reviews. It reads off a map rather than a queue.

Risk geography map

Where your suppliers are, which metros they pile up in, and how to narrow the map with the same vendor filters you use on the vendor list. Also covers why archived suppliers are hidden by default and how a shared address lists every supplier on it.
Jump straight to an answer: what the two map layers mean · filtering the map · archived suppliers · many suppliers at one address · what the map does not tell you

Contracts

Start with the workspace guide to learn the screens. Everything else splits three ways: what a contract is (components and dates), what its language says (Contract Guardian), and what values to pull out of it (Document Insights).

Contracts workspace

The screens you work in every day. The key statistics row, the renewal runway and how to hide or restore it, and the cards on a contract record including how to add and remove fields on the details card.

Contract components

The catalogue. Every component Coverbase reads a contract into, what it interprets each one as, which contract fields it is allowed to answer, and what happens when two documents claim the same one.

Contract dates and reminders

The contract timeline. What each date means, which ones Coverbase calculates and why they cannot be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.

Contract Guardian guide

Language-level review. Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable, and unacceptable language, then run reviews and triage the deviations.

The clause set library

The 12 packaged clause standards Coverbase ships, from Enterprise SaaS to HIPAA to Payments. What each one covers, how many clauses it carries, which ones would block a signature, and how to choose a starting point.

Generate a clause set from your own contract

Upload your template MSA or DPA and let Coverbase extract a clause set from it. What extraction gives you, why it drops language it cannot quote, and the tiering you still have to write yourself.

Import and export clause sets as spreadsheets

Already have your clause playbook in Excel? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.

Document Insights guide

Field-level extraction. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract versus Synthesize.
Jump straight to an answer: the contracts list page · the contract record · the component catalogue · correcting what a document carries · fixed versus calculated dates · who gets reminded · mute one contract On clause review and insights: build your clause set · write risk-tier variants · run a review · work the results · a workable rollout · Extract versus Synthesize · a starter library · auditing coverage · backfilling history

Getting it signed

Coverbase signs agreements in the same place it stores them, so the executed copy and the evidence that it happened land on the contract and the vendor without anyone filing them.

E-signature overview

Start here. The four moving parts, the shape of a signing, the envelope statuses, and the organization-wide settings worth doing once before your first send.

Signature templates

Build an NDA or order form once: the source document, the signing parties as roles rather than people, and the fields each role fills. Plus what freezes a template, and why it is the first send rather than publishing.

Sending for signature

The four-step send wizard, routing order and access codes, tracking what is out, correcting or voiding an envelope, and the hash-chained audit trail an auditor reads.

The signing experience

The counterparty’s side: consent, filling, adopting one signature that covers every block, and the executed copy they keep. Plus how to brand the portal as yours.
Jump straight to an answer: an envelope’s statuses · before your first send · what the field types do · versioning · the recipients step · nudging, correcting, cancelling · the audit trail · what to tell a signer who is stuck

Reporting on the programme

What the programme looks like from above: portfolio risk, throughput, cycle times, spend and savings, drawn live from your own records.

Dashboards and the chart library

The 10 dashboards and 76 charts Coverbase ships ready to use, each written for a job rather than for a table: a board overview, a cycle-time and SLA view, contract spend and renewals, savings, intake demand, control assurance and tag coverage. Every one is a copy you own and can edit.
Jump straight to an answer: the ten dashboards · every dashboard in detail · what is on each shelf · what you will and will not see · making them yours

Sourcing and RFPs

Vendor selection with risk and compliance evaluation built into it rather than bolted on afterwards. The product page behind this is RFP Platform.

How to run an RFP

One sourcing event end to end. Draft the RFP with the AI wizard, compare the field without contacting anyone, score responses against your rubric with evidence attached, read the pricing side by side, and record the decision in a memo somebody can read a year later.
Jump straight to a part: draft the RFP · run it without outreach · score the responses · compare and decide · run an RFP from chat

Supplier information and payment details

The facts you have to get exactly right before you can pay a supplier: where the money goes, where they are, and what they are registered as.

Supplier information guide

How bank details, addresses, tax registrations and diversity records are collected through a questionnaire, checked against the rules for the supplier’s country, reviewed before they take effect, and handed to your finance system.

Supplier countries

All 109 countries Coverbase validates, with the exact fields, formats, check digits and registers each one uses. Useful before you send a request, and when you are reading a warning on a submitted record.
Jump straight to an answer: the four question types · the review that stops fraud · who can see and do what · configuring it for your organization · getting it into your finance system
Each page lists the exact fields, formats, check digits, and registers for that country.Australia · Brazil · Bulgaria · Canada · China · Colombia · Côte d’Ivoire · Finland · France · Germany · Ghana · Hong Kong SAR · India · Indonesia · Ireland · Italy · Japan · Malaysia · Mauritius · Mexico · Netherlands · Nigeria · Oman · Peru · Philippines · Poland · Portugal · Saudi Arabia · Singapore · South Africa · South Korea · Spain · Sweden · Switzerland · Thailand · Türkiye · United Arab Emirates · United Kingdom · United States

Reference pages that live outside these guides

Three things every guide points at sooner or later. They sit in the main documentation because they are reference rather than walkthrough.

Custom Word report templates

Author the branded .docx: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.

Placeholder reference

Every vendor, assessment, service, review, and finding placeholder, with its resolved value and formatting.

Control Set library

Both halves of the packaged library and what each set measures: 47 vendor frameworks to assess a third party against, and 21 internal sets Inspect evaluates against your own applications.

How Coverbase thinks

A little context makes everything else click.

Document-first, not questionnaire-first

Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor’s actual documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
When someone requests a vendor, their answers to the intake questionnaire apply tags automatically. Tags then decide which control frameworks apply, which documents are required, which team reviews, and how the vendor is scored. A financial-services vendor handling PHI in the EU gets a very different track than a US-only SaaS tool with read-only access, and it happens without manual triage.
A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. In one real case, 111 controls produced 5. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it’s easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
By design, for auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you’ve already signed off on changes underneath you.

Looking something up

The questions people actually arrive with, and the exact place each one is answered.

Need a hand

Product support

Email support@coverbase.ai for technical questions.

Live working sessions

Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding, and configuration.