Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
These are the screen-by-screen guides for using Coverbase. Each one is written for someone with the product open in another tab who wants to finish a specific job today. None of them assumes prior Coverbase experience, and each can be read on its own. The guides are grouped the way the left navigation in the product is grouped, so the section a screen sits in is the section its guide sits in. This page is the directory. Use the sidebar to browse, or the complete directory and the lookup table below to jump straight to an answer.

Start here

Pick the guide that matches your role. Most people only ever need one of these three.

I am setting up Coverbase

Admin and setup guide. Import your vendors, build tags and the intake questionnaire, tune scales and control sets, then set templates, monitoring and integrations. This is where the AI gets its instructions.

I run vendor risk day to day

Analyst and reviewer guide. Triage requests, launch assessments, review and correct what the AI found, follow up with vendors, and close the loop with findings and reports.

I need a tool approved

Requesting a new vendor. The short one, for the business requester. What you will be asked, how to file it, and why submitting a request is not approval.
An admin configures the environment once. After that, analysts run assessments against that configuration every day, and every correction a reviewer makes carries forward into future assessments.

Setting up your workspace

Do this once, in order. The setup guide is the spine. The guides beside it cover the settings people most often discover too late.

Admin and setup guide

Eleven steps from an empty environment to a running program: vendors, tags, the intake questionnaire, scales, control sets, assessment plans, templates, Radar, obligations and integrations.

Configuring your data model

What an admin changes without a professional-services engagement: custom fields, statuses, approval options, scales, risk domains, terminology, relationships and automations.

Permissions and roles

The six default roles, how a permission is built from a resource, an action and a scope, and how to build and assign a custom role.

Assignment, delegation and out of office

How a gate reaches a person: user groups, round-robin and assign-to-all routing, out-of-office windows that skip a member automatically, and the assignment log.

Reviews, approvals and gates

Configurable gate outcomes, parallel domain-scoped SME reviews, multi-approver and threshold logic, and return-for-rework loops with reasons and round counts.

Email and notifications

Every email Coverbase sends to your team and your vendors, how each person controls delivery and digests, and how your logo and brand color reach emails and portals.

White-labeling your vendor-facing domain

Sending vendor email and hosting the portal on your own subdomain, and choosing between Coverbase-managed and organization-managed DNS.
Jump straight to a step: setup checklist · import your vendors · tag structure · build and weight the IRQ · control sets · assessment plans and cadence · configure Radar · integrations and Export API · admin quick reference Access and notifications: the six default roles · building a custom role · user groups · out of office · gate outcomes · return for rework · choosing an email layout · applying your branding · who receives what · the notification catalog · two ways to set up your domain

Vendors

The vendor record is where everything else attaches: services, engagements, documents, assessments, contracts, findings, obligations and the supplier’s bank and tax details.

The vendor record

The vendor list and one vendor’s page: tabs and sidebar cards, services and engagements, subprocessors and nth parties, owners and directory contacts, custom fields, tags, and archiving.

Supplier information guide

How bank details, addresses, tax registrations and diversity records are collected through a questionnaire, checked against the rules for the supplier’s country, reviewed before they take effect, and handed to your finance system.

Supplier countries

All 109 countries Coverbase validates, with the exact fields, formats, check digits and registers each one uses. Useful before you send a request, and when you are reading a warning on a submitted record.

Requesting a new vendor

The requester’s side of intake: filing in the portal or in chat, what you will be asked, how to get through it faster, and what happens after you submit.

Centralized supplier portal

One page where a supplier signs in and sees every request you have open with them, keeps their own profile current, and answers your findings. How to turn it on and what each setting decides.

The supplier portal, for suppliers

The page to send a supplier: signing in, everything open with you in one place, keeping their details current, and bringing colleagues in.
Jump straight to an answer: two ways to file a request · getting through it faster · turning on the centralized portal · what a supplier may change without being asked · how a supplier gets in · the four supplier question types · the review that stops fraud · who can see and do what · getting it into your finance system
Each page lists the exact fields, formats, check digits and registers for that country. The country overview has the full table of all 109.Australia · Brazil · Bulgaria · Canada · China · Colombia · Côte d’Ivoire · Finland · France · Germany · Ghana · Hong Kong SAR · India · Indonesia · Ireland · Italy · Japan · Malaysia · Mauritius · Mexico · Netherlands · Nigeria · Oman · Peru · Philippines · Poland · Portugal · Saudi Arabia · Singapore · South Africa · South Korea · Spain · Sweden · Switzerland · Thailand · Türkiye · United Arab Emirates · United Kingdom · United States

Assessing a vendor

The assessment is the center of the platform, so it gets the most pages: the full walkthrough, a cheat sheet to keep open beside it, the questionnaire mechanics, the packaged inherent risk templates, how web evidence is vetted, and the lightweight run for vendors that do not warrant the full treatment.

How to run an assessment

The complete lifecycle, screen by screen. Getting the vendor in, creating the assessment from a plan, collecting evidence five different ways, working the issues, follow-up cycles, domain reviews, and the final export.

Assessment quick reference

The cheat sheet. Five steps, quick tips, common scenarios, a troubleshooting table, and the control frameworks at a glance.

Questionnaires

Build a template, set conditional logic and internal-only questions, write answers back to the record, assign reviewers, send it to a vendor, and work a submission through to a decision.

The IRQ library

The six inherent risk questionnaires Coverbase ships: every question each one asks, how the score is calculated, and how to pick and tailor the right starting point.

Evidence quality and source credibility

How every web page is graded for publisher accountability, where you set the minimum bar, what appears on evidence cards and in the Excel export, and exactly which parts of the platform this covers.

Zero Touch Assessment guide

A triage run assembled entirely from open-source research, with no outreach. How to run one across a portfolio, read the composite and its components, correct a run that bound the wrong company, and read the audit trail.
Jump straight to a part: get the vendor in · create the assessment · collect the evidence · work the issues · follow-up cycles · complete and export · triage new requests · review the results · correct the AI Questionnaires, evidence and Zero Touch: building the template · conditional logic · write-back rules · assigning reviewers · reviewing a submission · choosing an IRQ template · the credibility scale · where you set the bar · running a Zero Touch assessment · reading the result · reviewing a run

Document library

Where the Coverbase library documents on every vendor came from, how they are reviewed before they appear, and why nothing your organization uploads is ever added to them. This page sits with the product pages rather than here.

Findings and obligations

Two records that look alike and answer different questions. A finding is a problem on the vendor’s side. An obligation is work your organization owes because of the vendor.

Findings and remediation

What happens after a finding exists: the Findings page, the statuses and how commitments set them, asking a vendor for a commitment through the portal, verifying the work, findings settings, and where findings show up elsewhere.

Obligations

How obligations are extracted from SOC reports and contracts, the list and the record, what each status means, assigning an owner, asking a business unit to acknowledge one, and where obligations feed the risk register and workflows.
Jump straight to an answer: how a finding gets raised · finding statuses · requesting a commitment · working a commitment · findings settings · turning on automatic extraction · obligation statuses · reviewing extracted obligations · asking a business unit to acknowledge

Checking a vendor without contacting them

The Vendor Intelligence section on a vendor is a set of tabs, each assembled from public sources without contacting the vendor, and each designed to be checked rather than trusted. There is one guide per tab below, plus the older combined walkthrough the first four replaced.

Corporate registrations guide

Whether there is a real, currently registered company behind the vendor, and whether it is the one you think it is. How to read a match verdict, and what a dissolved status means on a vendor you are paying.

People intelligence guide

Who runs the vendor, and what adverse-media screening found about them. Why confirmed and unconfirmed names are counted differently, and why “not screened” is never the same as “nothing found”.

Financial health guide

How likely the vendor is to still be trading. What the confidence tier tells you about the number, and how private companies with no filings are scored.

Security intelligence guide

The outside-in security rating measured against the vendor’s own infrastructure. What each factor covers, and what a not-measured factor does and does not tell you.

Sanctions screening guide

Whether the vendor or its people appear on a sanctions, watchlist, criminal or legal source, re-checked on a schedule rather than once at onboarding. Why the confidence score measures identity and not severity, and how to clear a false positive.

Financial health and security intelligence

The older combined walkthrough, covering the Financial Health Score and External Security Intelligence cards as they appear on the fact sheet. The two dedicated guides above go deeper.
Jump straight to an answer: read the registry verdict first · a dissolved status · confirmed and unconfirmed people · no findings versus not screened · what the financial tier is worth · runway and burn · the rating is a floor · next steps · since last scan · lookalike domains · identity confidence is not severity · deciding a match · screening settings

Monitoring between assessments

Radar watches your vendors in the gap between reviews. Sources collect, detectors decide what deserves an alert, and signals land in a queue for someone to triage.

Working Radar signals

The vocabulary, the signal queue and its statuses, triaging a signal into a case, a finding or a reassessment, keeping sources and detectors tuned, and where a signal goes next.

Black Kite monitoring guide

How to connect your Black Kite portfolio, choose which vendors are watched, and turn known exploited vulnerabilities and focus tags into alerts.

Bills of materials

How to upload a vendor’s SBOM, keep the right version applied, and get an alert when a known exploited vulnerability affects one of its components.

Breach notification monitoring guide

How to watch state attorney general breach registries and SEC cyber incident filings, and turn a filing that names your vendor into an alert.
Jump straight to a step: the vocabulary · the signal queue · triaging a signal · sources · detectors · testing a detector before you enable it · which vendors are watched · connect Black Kite credentials · fix a vendor that will not match · upload an SBOM · how an SBOM is matched · what breach monitoring covers · add the breach sources Radar signals also land in the analyst’s queue, and working them is step 8 of the analyst guide. Setting Radar up in the first place is step 9 of the admin guide.

Risk

The Risk module holds the register, the dependency chain, scenarios, exposure and the board report. The geography map lives under the same entry.

The Risk module: register, signals and scenarios

Score a risk on the 5x5, let findings, contracts and Radar feed it as signals, decide on what the agent proposes, trace the dependency chain, run a what-if scenario, and produce the board pack.

Risk geography map

Where your suppliers are, which metros they pile up in, and how to narrow the map with the same vendor filters you use on the vendor list. Also covers why archived suppliers are hidden by default.
Jump straight to an answer: reading the register · creating a risk · signal sources and thresholds · the agent · the chain · simulate a scenario · the board report · configuring the module · what the two map layers mean · filtering the map · many suppliers at one address

Contracts

Start with the workspace guide to learn the screens. Then it splits four ways: getting a contract in (intake and the repository), what a contract is (components and dates), what its language says (Contract Guardian and negotiation rounds), and what values to pull out of it (Document Insights, under Documents below).

Contracts workspace

The screens you work in every day. The attention cards, the table and renewal runway views of the list, and the cards on a contract record.

Contract intake and approval

Raise a contract request from a vendor, confirm what the AI read off the draft, route it through your approval chain, and send the approved agreement to DocuSign.

The contracts repository

Forward an agreement to your organization’s paralegal inbox, and let Coverbase name, deduplicate, version and file it. The inbox log, the folder schemes and the settings behind the address.

Contract components

The catalog. Every component Coverbase reads a contract into, what it interprets each one as, which contract fields it may answer, and what happens when two documents claim the same one.

Contract dates and reminders

The contract timeline. What each date means, which ones Coverbase calculates and why they cannot be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.

Negotiation rounds

Upload the marked-up contract a vendor sends back, see what they changed, which of your asks they accepted, and what they edited without being asked, without starting the clause review over.

Clause review with Contract Guardian

Contract Guardian guide

Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable and unacceptable language, then run reviews and triage the deviations.

The clause set library

The 12 packaged clause standards Coverbase ships, from Enterprise SaaS to HIPAA to Payments. What each one covers, which clauses would block a signature, and how to choose a starting point.

Generate a clause set from your own contract

Upload your template MSA or DPA and let Coverbase extract a clause set from it. What extraction gives you, why it drops language it cannot quote, and the tiering you still have to write yourself.

Import and export clause sets as spreadsheets

Already have your clause playbook in Excel? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.
Jump straight to an answer: the contracts list page · the contract record · raising a request · the approval chain · sending for signature · forwarding an agreement · how a document is filed · the inbox log · the component catalog · correcting what a document carries · fixed versus calculated dates · who gets reminded · mute one contract On clause review: build your clause set · write risk-tier variants · run a review · work the results · a workable rollout · upload what the vendor sent back · see what changed · choosing a packaged clause set · run an extraction · get the spreadsheet template

Getting it signed

Coverbase signs agreements in the same place it stores them, so the executed copy and the evidence that it happened land on the contract and the vendor without anyone filing them.

E-signature overview

Start here. The four moving parts, the shape of a signing, the envelope statuses, and the organization-wide settings worth doing once before your first send.

Signature templates

Build an NDA or order form once: the source document, the signing parties as roles rather than people, and the fields each role fills. Plus what freezes a template, and why it is the first send rather than publishing.

Sending for signature

The four-step send wizard, routing order and access codes, tracking what is out, correcting or voiding an envelope, and the hash-chained audit trail.

The signing experience

The counterparty’s side: consent, filling, adopting one signature that covers every block, and the executed copy they keep. Plus how to brand the portal as yours.
Jump straight to an answer: an envelope’s statuses · before your first send · what the field types do · versioning · the recipients step · nudging, correcting, canceling · the audit trail · what to tell a signer who is stuck

Documents

Three guides about the documents on a vendor: the values Coverbase pulls out of every one, asking them a question in chat, and the reminders that fire before one lapses.

Document Insights guide

Field-level extraction. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract versus Synthesize.

Asking your documents a question

Ask a plain-English question in chat and get back the passage from a vendor’s documents that answers it: the verbatim quote, its page, a cropped image of the passage, and a link that opens the document with it marked.

Document expiry reminders

How Coverbase reminds you before a vendor document lapses: which dates it fires from, who receives the email, and where to see everything that is expiring.
Jump straight to an answer: Extract versus Synthesize · a starter library · auditing coverage · backfilling history · what you get back from a question · what can and cannot be read · when the expiry reminder fires · who receives it

Workflows and automation

Automations that react when a record changes: the ready-made templates, and building your own from a trigger, conditions and an action.

Workflow templates

The nineteen ready-to-run automations Coverbase ships: what each one does, which modules it needs, what you have to change before turning it on, and how to make one your own.

Building a workflow

Pick a trigger, narrow it with conditions, configure the action, use placeholders, test it, switch it on, then read the runs and the work queue items it produces.
Jump straight to an answer: the nineteen templates · which modules a template needs · applying a template · creating a workflow from scratch · building an automation · placeholders in action text · creating a work queue item · reading the runs page · working the work queue

Dashboards and reporting

What the program looks like from above, drawn live from your own records, and the documents you hand to someone else.

Dashboards and the chart library

The 15 dashboards and 110 charts Coverbase ships ready to use: a board overview, a cycle-time and SLA view, contract spend and renewals, savings, intake demand, control assurance, tag coverage, findings and Radar triage. Every one is a copy you own and can edit.

Reporting overview

The two kinds of assessment deliverable: standard exports, and custom Word report templates filled from live assessment data. Which one to use, and how a custom report is generated.

Custom Word report templates

Author the branded .docx: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.

Placeholder reference

Every vendor, assessment, service, review and finding placeholder, with its resolved value and formatting.

Evidence packaging and the due-diligence file

Produce the complete file for one third party, and assemble an examination package.
Jump straight to an answer: the ready-made dashboards · every dashboard in detail · what is on each shelf · making them yours · which report to use · how a custom report is generated

Sourcing and RFPs

Vendor selection with risk and compliance evaluation built into it rather than bolted on afterwards. The product page behind this is RFP Platform.

How to run an RFP

One sourcing event end to end. Draft the RFP with the AI wizard, compare the field without contacting anyone, score responses against your rubric with evidence attached, read the pricing side by side, and record the decision in a memo somebody can read a year later.
Jump straight to a part: draft the RFP · run it without outreach · score the responses · compare and decide · run an RFP from chat

Internal controls

Coverbase against your own applications, with the same findings, workflows and reporting as third-party risk.

Internal controls monitoring with Inspect

Connect your applications through Okta, Entra or Google, run an inspection against an internal control set, read the result, watch for drift between runs, keep probes and schedules running, and turn what it finds into findings.
Jump straight to a step: connecting an application · running an inspection · reading an inspection · drift between runs · probes · schedules · the accounts directory

The complete directory

Every guide in this section, in one table.

Reference pages that live outside these guides

Pages every guide points at sooner or later. They sit elsewhere in the documentation because they are reference rather than walkthrough.

Control Set library

Both halves of the packaged library and what each set measures: the vendor frameworks to assess a third party against, and the internal sets Inspect evaluates against your own applications.

Field reference

Every filterable field, its path, and where it comes from. The same paths drive saved views, workflow conditions and the query API.

What each product does

A page per capability, from Autonomous Intake to internal controls monitoring, for when you want the what and why before the how.

How Coverbase thinks

A little context makes everything else click.

Document-first, not questionnaire-first

Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor’s documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
When someone requests a vendor, their answers to the intake questionnaire apply tags automatically. Tags then decide which control frameworks apply, which documents are required, which team reviews, and how the vendor is scored. A financial-services vendor handling PHI in the EU gets a different track than a US-only SaaS tool with read-only access, without manual triage.
A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it is easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
For auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you have already signed off on changes underneath you.

Looking something up

The questions people arrive with, and the place each one is answered.

Need a hand

Product support

Email support@coverbase.ai for technical questions.

Live working sessions

Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding and configuration.