For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
These are the screen-by-screen guides for using Coverbase. Each one is written for someone with the product open in another tab who wants to finish a specific job today.
There are 29 guides plus a country reference covering 109 countries. This page is the directory for all of them. Nothing below needs prior Coverbase experience, and you can read any guide start to finish on its own.
Every guide below is in the sidebar under User guides. This page is the directory if you would rather scan the whole set at once.
Start here
Pick the guide that matches your role. Most people only ever need one of these three.I am setting up Coverbase
Admin and setup guide. Import your vendors, build tags and the intake questionnaire, tune scales and control sets, then set templates, monitoring, and integrations. This is where the AI gets its instructions.
I run vendor risk day to day
Analyst and reviewer guide. Triage requests, launch assessments, review and correct what the AI found, engage vendors, and close the loop with findings and reports.
I just need a tool approved
Requesting a new vendor. The short one, for the business requester. What you will be asked, how to file it, and why submitting a request is not approval.
The complete directory
All 32 pages in this section, in one place.
The sections below break the same set out by job, with links into the parts of each guide people look for most.
Setting up the platform
Do this once, in order. The setup guide is the spine. The notifications guide beside it covers the settings people most often discover too late.Admin and setup guide
Eleven steps from an empty environment to a running program. Vendors, tags, the intake questionnaire, scales, control sets, assessment plans, templates, Radar, obligations, and integrations.
Email and notifications
The full catalog of what Coverbase sends to your team and to your vendors, how each person controls their own delivery and digest schedule, and how your logo and brand colour flow into emails and vendor portals.
White-labeling your vendor-facing domain
Sending vendor email and hosting the portal on your own subdomain instead of coverbase.ai and coverbase.app, and choosing between Coverbase-managed and organization-managed DNS.
Configuring your data model
What an admin changes without a professional-services engagement: custom fields, statuses, approval options, scales, risk domains, terminology, relationships and automations.
Reviews, approvals and gates
The decision points. Configurable outcomes including approve with finding, policy exception and return for rework; parallel domain reviews; multi-approver and threshold logic; rework loops with reasons, comments and round counts.
Assignment, delegation and out of office
How a gate reaches a person: user groups, round-robin and assign-to-all routing, out-of-office windows that skip a member automatically, and the attributed assignment log.
Getting a vendor in
Most vendors arrive through intake, filed by someone outside the risk team. The requester guide is deliberately short. The analyst guide picks up where it ends.Requesting a new vendor
For the business requester, not the risk team. What you will be asked, how to file in the portal or in chat, how to get through it faster, and the thing people most often get wrong: submitting a request is not approval.
Analyst and reviewer guide
The receiving end. Nine steps covering triage, launching assessments, reviewing results, correcting the AI, vendor follow-up, disposition, contracts, Radar signals, and obligations.
Assessing a vendor
The assessment is the centre of the platform, so it gets four pages: the full walkthrough, a cheat sheet to keep open beside it, the guide to how web evidence is vetted, and the lightweight run for vendors that do not warrant the full treatment.How to run an assessment
The complete lifecycle, screen by screen. Getting the vendor in, creating the assessment from a plan, collecting evidence five different ways, working the issues, follow-up cycles, domain reviews, and the final export.
Assessment quick reference
The cheat sheet. Five steps, quick tips, common scenarios, a troubleshooting table, and the control frameworks at a glance.
Evidence quality and source credibility
Send this to anyone who asks how web evidence is vetted. How every page is graded for publisher accountability, where you set the minimum bar, what appears on evidence cards and in the Excel export, and exactly which parts of the platform this covers.
Zero Touch Assessment guide
A triage run assembled entirely from open-source research, with no outreach. How to run one across a portfolio, read the composite and its components, correct a run that bound the wrong company, and read the audit trail.
Document library
Where the Coverbase library documents on every vendor came from, how they are reviewed before they appear, and why nothing your organization uploads is ever added to them. This one sits in the product documentation rather than here.
Checking a vendor without contacting them
Five tabs sit in every vendor’s Vendor Intelligence section, each assembled from public sources without contacting the vendor, and each designed to be checked rather than trusted. There is one guide per tab, plus the older combined walkthrough the first four replaced.Corporate registrations guide
Whether there is a real, currently registered company behind the vendor, and whether it is the one you think it is. How to read a match verdict, and what a dissolved status means on a vendor you are paying.
People intelligence guide
Who runs the vendor, and what adverse-media screening found about them. Why confirmed and unconfirmed names are counted differently, and why “not screened” is never the same as “nothing found”.
Financial health guide
How likely the vendor is to still be trading. Why the confidence tier matters more than the number, and when two scores are not comparable.
Security intelligence guide
The outside-in security rating measured against the vendor’s own infrastructure. What each factor covers, and what a not-measured factor does and does not tell you.
Sanctions screening guide
Whether the vendor or its people appear on a sanctions, watchlist, criminal or legal source, re-checked on a schedule rather than once at onboarding. Why the confidence score measures identity and not severity, and how to clear a false positive.
Financial health and security intelligence
The older combined walkthrough, covering the Financial Health Score and Security Posture cards as they appear on the fact sheet. The two dedicated guides above go deeper.
Monitoring between assessments
Radar watches your vendors in the gap between reviews. If you already pay for a ratings service, its findings can feed the same signal queue.Black Kite monitoring guide
How to connect your Black Kite portfolio, choose which vendors are watched, and turn known exploited vulnerabilities and focus tags into alerts. Covers the two settings that decide whether monitoring keeps up with a large portfolio, and why a source on its own does not raise anything.
Risk geography map
Where your suppliers are, which metros they pile up in, and how to narrow the map with the same vendor filters you use on the vendor list. Also covers why archived suppliers are hidden by default and how a shared address lists every supplier on it.
Contracts
Start with the workspace guide to learn the screens. Everything else splits three ways: what a contract is (components and dates), what its language says (Contract Guardian), and what values to pull out of it (Document Insights).Contracts workspace
The screens you work in every day. The key statistics row, the renewal runway and how to hide or restore it, and the cards on a contract record including how to add and remove fields on the details card.
Contract components
The catalogue. Every component Coverbase reads a contract into, what it interprets each one as, which contract fields it is allowed to answer, and what happens when two documents claim the same one.
Contract dates and reminders
The contract timeline. What each date means, which ones Coverbase calculates and why they cannot be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.
Contract Guardian guide
Language-level review. Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable, and unacceptable language, then run reviews and triage the deviations.
The clause set library
The 12 packaged clause standards Coverbase ships, from Enterprise SaaS to HIPAA to Payments. What each one covers, how many clauses it carries, which ones would block a signature, and how to choose a starting point.
Generate a clause set from your own contract
Upload your template MSA or DPA and let Coverbase extract a clause set from it. What extraction gives you, why it drops language it cannot quote, and the tiering you still have to write yourself.
Import and export clause sets as spreadsheets
Already have your clause playbook in Excel? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.
Document Insights guide
Field-level extraction. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract versus Synthesize.
Getting it signed
Coverbase signs agreements in the same place it stores them, so the executed copy and the evidence that it happened land on the contract and the vendor without anyone filing them.E-signature overview
Start here. The four moving parts, the shape of a signing, the envelope statuses, and the organization-wide settings worth doing once before your first send.
Signature templates
Build an NDA or order form once: the source document, the signing parties as roles rather than people, and the fields each role fills. Plus what freezes a template, and why it is the first send rather than publishing.
Sending for signature
The four-step send wizard, routing order and access codes, tracking what is out, correcting or voiding an envelope, and the hash-chained audit trail an auditor reads.
The signing experience
The counterparty’s side: consent, filling, adopting one signature that covers every block, and the executed copy they keep. Plus how to brand the portal as yours.
Reporting on the programme
What the programme looks like from above: portfolio risk, throughput, cycle times, spend and savings, drawn live from your own records.Dashboards and the chart library
The 10 dashboards and 76 charts Coverbase ships ready to use, each written for a job rather than for a table: a board overview, a cycle-time and SLA view, contract spend and renewals, savings, intake demand, control assurance and tag coverage. Every one is a copy you own and can edit.
Sourcing and RFPs
Vendor selection with risk and compliance evaluation built into it rather than bolted on afterwards. The product page behind this is RFP Platform.How to run an RFP
One sourcing event end to end. Draft the RFP with the AI wizard, compare the field without contacting anyone, score responses against your rubric with evidence attached, read the pricing side by side, and record the decision in a memo somebody can read a year later.
Supplier information and payment details
The facts you have to get exactly right before you can pay a supplier: where the money goes, where they are, and what they are registered as.Supplier information guide
How bank details, addresses, tax registrations and diversity records are collected through a questionnaire, checked against the rules for the supplier’s country, reviewed before they take effect, and handed to your finance system.
Supplier countries
All 109 countries Coverbase validates, with the exact fields, formats, check digits and registers each one uses. Useful before you send a request, and when you are reading a warning on a submitted record.
Every country page, by name
Every country page, by name
Each page lists the exact fields, formats, check digits, and registers for that country.Australia ·
Brazil ·
Bulgaria ·
Canada ·
China ·
Colombia ·
Côte d’Ivoire ·
Finland ·
France ·
Germany ·
Ghana ·
Hong Kong SAR ·
India ·
Indonesia ·
Ireland ·
Italy ·
Japan ·
Malaysia ·
Mauritius ·
Mexico ·
Netherlands ·
Nigeria ·
Oman ·
Peru ·
Philippines ·
Poland ·
Portugal ·
Saudi Arabia ·
Singapore ·
South Africa ·
South Korea ·
Spain ·
Sweden ·
Switzerland ·
Thailand ·
Türkiye ·
United Arab Emirates ·
United Kingdom ·
United States
Reference pages that live outside these guides
Three things every guide points at sooner or later. They sit in the main documentation because they are reference rather than walkthrough.Custom Word report templates
Author the branded
.docx: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.Placeholder reference
Every vendor, assessment, service, review, and finding placeholder, with its resolved value and formatting.
Control Set library
Both halves of the packaged library and what each set measures: 47 vendor frameworks to assess a third party against, and 21 internal sets Inspect evaluates against your own applications.
How Coverbase thinks
A little context makes everything else click.Document-first, not questionnaire-first
Document-first, not questionnaire-first
Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor’s actual documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
The AI drafts, humans judge
The AI drafts, humans judge
A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. In one real case, 111 controls produced 5. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it’s easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
Configuration changes aren't retroactive
Configuration changes aren't retroactive
By design, for auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you’ve already signed off on changes underneath you.
Looking something up
The questions people actually arrive with, and the exact place each one is answered.Need a hand
Product support
Email support@coverbase.ai for technical questions.
Live working sessions
Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding, and configuration.