Welcome. This is a shareable home for Coverbase’s getting-started guides. It doesn’t show up in the main documentation navigation, so anyone you send the link to can read it, and you can bookmark it for your team. We’ll add more here over time (Radar and the rest).
Two ways in, depending on your role
The work splits cleanly into two jobs. Pick the guide that matches what you’re here to do, or read both if you wear both hats.Admin and setup guide
For the program owner or administrator standing up the environment. You’ll import your vendors, build your tag structure and intake questionnaire, tune scales and control sets, and set up templates, monitoring, and integrations. This is where the AI gets its instructions.
Analyst and reviewer guide
For the analysts and reviewers doing the daily work. You’ll triage new vendor requests, launch assessments, review what the AI found, correct it where it’s wrong, engage vendors, and close the loop with findings, reports, and monitoring.
Asking for a new vendor
Most people who touch Coverbase touch it exactly once: to request a tool their team wants. That guide is deliberately short and assumes nothing.Requesting a new vendor
For the business requester, not the risk team. What you’ll be asked, how to file in the portal or in chat, how to get through it faster, and the thing people most often get wrong: submitting a request is not approval.
Running an assessment
The assessment is the centre of the platform, so it gets two pages of its own: a full walkthrough and a cheat sheet.How to run an assessment
The complete lifecycle, screen by screen: getting the vendor in through intake or the New Vendor wizard, creating the assessment from a plan, collecting evidence five different ways, working the issues, running follow-up cycles, domain reviews, and the final export.
Assessment quick reference
A one-page cheat sheet: the five steps, quick tips, common scenarios, and a troubleshooting table. Keep it open in a tab while you work.
Controlling the quality of evidence
Assessments lean on the public web when documents run out. This guide is the one to send anyone who asks how that evidence is vetted.Evidence quality and source credibility
How every web page is graded for publisher accountability before it can be cited, where you set the minimum bar (per control set or per control), how credibility, relevance, and freshness are kept separate, what shows up on evidence cards and in the Excel export, and exactly which parts of the platform this covers.
Financial health and security intelligence
Two cards in every vendor’s Vendor Intelligence section carry a score rather than a description. Both are assembled without contacting the vendor, and both are designed to be checked rather than trusted. The product pages behind them are Financial Health Score and Security Intelligence.Financial health and security intelligence guide
How to read the Financial Health Score and Security Posture cards: why the confidence tier matters more than the number, how to open the rationale behind any score, what “unmeasured” means and why it isn’t a failing grade, and how to turn a finding into a question a vendor can actually answer.
Contracts
Contract intelligence has two halves, and they’re set up separately. Read both if you own the contracts module.Contract Guardian guide
Language-level. Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable, and unacceptable language, then run reviews and triage the deviations.
Document Insights guide
Field-level. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract vs Synthesize.
Baseline contract extraction
Turn your own template MSA or DPA into a clause set. What extraction gives you, and the tiering you still have to write.
Clause set spreadsheet import and export
Already have your clause playbook in a spreadsheet? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.
Contract dates and reminders
The contract timeline: what each date means, which ones Coverbase calculates and why they can’t be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.
Building your report template
Both guides touch report templates: the admin builds one, the analyst exports against it. The authoring detail lives in its own reference, which sits in the main documentation rather than here.Custom Word report templates
Author the branded
.docx: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.Placeholder reference
Every vendor, assessment, service, review, and finding placeholder, with its resolved value and formatting.
The order things happen
Starting from a blank environment, the two guides run in sequence. An admin configures the platform once. After that, analysts run assessments against that configuration every day.1
Set up the environment (admin)
Import vendors, create tags, build and weight the intake questionnaire, configure scales and control sets, and set your templates, monitoring, and integrations. Follow the Admin and setup guide.
2
Run the work (analyst and reviewer)
Triage requests, launch assessments, review and correct AI findings, follow up with vendors, and disposition results. Follow the Analyst and reviewer guide, or How to run an assessment for the screen-by-screen version of a single assessment.
3
Keep improving
Every correction a reviewer makes teaches the platform, so the issue count falls with each cycle. Monitoring keeps working in the background. The program gets sharper over time.
How Coverbase thinks
A little context makes everything else click.Document-first, not questionnaire-first
Document-first, not questionnaire-first
Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor’s actual documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
The AI drafts, humans judge
The AI drafts, humans judge
A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. In one real case, 111 controls produced 5. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it’s easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
Configuration changes aren't retroactive
Configuration changes aren't retroactive
By design, for auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you’ve already signed off on changes underneath you.
What you’ll be able to do
Automated vendor intake
Route requests to the right teams automatically, with most intake questions already answered by the platform’s research agent.
AI-powered assessments
Cut review time sharply. The AI reads the evidence and surfaces only the gaps that need a human.
Continuous monitoring
Get alerted within hours of a material risk event across your third and fourth parties, instead of waiting for the next annual review.
Branded vendor portals
Vendors interact with a portal that carries your logo and your voice, not ours.
Need a hand?
Product support
Email support@coverbase.ai for technical questions.
Live working sessions
Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding, and configuration.