Skip to main content
Welcome. This is a shareable home for Coverbase’s getting-started guides. It doesn’t show up in the main documentation navigation, so anyone you send the link to can read it, and you can bookmark it for your team. We’ll add more here over time (Radar and the rest).
Coverbase is your AI-powered platform for third-party risk and procurement. These guides take you from an empty environment to a running program: importing vendors, telling the platform what “good” looks like, and then doing the daily work of assessing vendors and acting on what you find. You don’t need any prior Coverbase experience. Each guide reads start to finish, with real screenshots of the platform along the way.

Two ways in, depending on your role

The work splits cleanly into two jobs. Pick the guide that matches what you’re here to do, or read both if you wear both hats.

Admin and setup guide

For the program owner or administrator standing up the environment. You’ll import your vendors, build your tag structure and intake questionnaire, tune scales and control sets, and set up templates, monitoring, and integrations. This is where the AI gets its instructions.

Analyst and reviewer guide

For the analysts and reviewers doing the daily work. You’ll triage new vendor requests, launch assessments, review what the AI found, correct it where it’s wrong, engage vendors, and close the loop with findings, reports, and monitoring.

Asking for a new vendor

Most people who touch Coverbase touch it exactly once: to request a tool their team wants. That guide is deliberately short and assumes nothing.

Requesting a new vendor

For the business requester, not the risk team. What you’ll be asked, how to file in the portal or in chat, how to get through it faster, and the thing people most often get wrong: submitting a request is not approval.

Running an assessment

The assessment is the centre of the platform, so it gets two pages of its own: a full walkthrough and a cheat sheet.

How to run an assessment

The complete lifecycle, screen by screen: getting the vendor in through intake or the New Vendor wizard, creating the assessment from a plan, collecting evidence five different ways, working the issues, running follow-up cycles, domain reviews, and the final export.

Assessment quick reference

A one-page cheat sheet: the five steps, quick tips, common scenarios, and a troubleshooting table. Keep it open in a tab while you work.

Controlling the quality of evidence

Assessments lean on the public web when documents run out. This guide is the one to send anyone who asks how that evidence is vetted.

Evidence quality and source credibility

How every web page is graded for publisher accountability before it can be cited, where you set the minimum bar (per control set or per control), how credibility, relevance, and freshness are kept separate, what shows up on evidence cards and in the Excel export, and exactly which parts of the platform this covers.

Financial health and security intelligence

Two cards in every vendor’s Vendor Intelligence section carry a score rather than a description. Both are assembled without contacting the vendor, and both are designed to be checked rather than trusted. The product pages behind them are Financial Health Score and Security Intelligence.

Financial health and security intelligence guide

How to read the Financial Health Score and Security Posture cards: why the confidence tier matters more than the number, how to open the rationale behind any score, what “unmeasured” means and why it isn’t a failing grade, and how to turn a finding into a question a vendor can actually answer.

Contracts

Contract intelligence has two halves, and they’re set up separately. Read both if you own the contracts module.

Contract Guardian guide

Language-level. Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable, and unacceptable language, then run reviews and triage the deviations.

Document Insights guide

Field-level. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract vs Synthesize.

Baseline contract extraction

Turn your own template MSA or DPA into a clause set. What extraction gives you, and the tiering you still have to write.

Clause set spreadsheet import and export

Already have your clause playbook in a spreadsheet? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.

Contract dates and reminders

The contract timeline: what each date means, which ones Coverbase calculates and why they can’t be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.

Building your report template

Both guides touch report templates: the admin builds one, the analyst exports against it. The authoring detail lives in its own reference, which sits in the main documentation rather than here.

Custom Word report templates

Author the branded .docx: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.

Placeholder reference

Every vendor, assessment, service, review, and finding placeholder, with its resolved value and formatting.

The order things happen

Starting from a blank environment, the two guides run in sequence. An admin configures the platform once. After that, analysts run assessments against that configuration every day.
1

Set up the environment (admin)

Import vendors, create tags, build and weight the intake questionnaire, configure scales and control sets, and set your templates, monitoring, and integrations. Follow the Admin and setup guide.
2

Run the work (analyst and reviewer)

Triage requests, launch assessments, review and correct AI findings, follow up with vendors, and disposition results. Follow the Analyst and reviewer guide, or How to run an assessment for the screen-by-screen version of a single assessment.
3

Keep improving

Every correction a reviewer makes teaches the platform, so the issue count falls with each cycle. Monitoring keeps working in the background. The program gets sharper over time.

How Coverbase thinks

A little context makes everything else click.

Document-first, not questionnaire-first

Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor’s actual documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
When someone requests a vendor, their answers to the intake questionnaire apply tags automatically. Tags then decide which control frameworks apply, which documents are required, which team reviews, and how the vendor is scored. A financial-services vendor handling PHI in the EU gets a very different track than a US-only SaaS tool with read-only access, and it happens without manual triage.
A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. In one real case, 111 controls produced 5. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it’s easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
By design, for auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you’ve already signed off on changes underneath you.

What you’ll be able to do

Automated vendor intake

Route requests to the right teams automatically, with most intake questions already answered by the platform’s research agent.

AI-powered assessments

Cut review time sharply. The AI reads the evidence and surfaces only the gaps that need a human.

Continuous monitoring

Get alerted within hours of a material risk event across your third and fourth parties, instead of waiting for the next annual review.

Branded vendor portals

Vendors interact with a portal that carries your logo and your voice, not ours.

Need a hand?

Product support

Email support@coverbase.ai for technical questions.

Live working sessions

Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding, and configuration.