For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
These are the screen-by-screen guides for using Coverbase. Each one is written for someone with the product open in another tab who wants to finish a specific job today. None of them assumes prior Coverbase experience, and each can be read on its own.
The guides are grouped the way the left navigation in the product is grouped, so the section a screen sits in is the section its guide sits in. This page is the directory. Use the sidebar to browse, or the complete directory and the lookup table below to jump straight to an answer.
Start here
Pick the guide that matches your role. Most people only ever need one of these three.I am setting up Coverbase
Admin and setup guide. Import your vendors, build tags and the intake questionnaire, tune scales and control sets, then set templates, monitoring and integrations. This is where the AI gets its instructions.
I run vendor risk day to day
Analyst and reviewer guide. Triage requests, launch assessments, review and correct what the AI found, follow up with vendors, and close the loop with findings and reports.
I need a tool approved
Requesting a new vendor. The short one, for the business requester. What you will be asked, how to file it, and why submitting a request is not approval.
Setting up your workspace
Do this once, in order. The setup guide is the spine. The guides beside it cover the settings people most often discover too late.Admin and setup guide
Eleven steps from an empty environment to a running program: vendors, tags, the intake questionnaire, scales, control sets, assessment plans, templates, Radar, obligations and integrations.
Configuring your data model
What an admin changes without a professional-services engagement: custom fields, statuses, approval options, scales, risk domains, terminology, relationships and automations.
Permissions and roles
The six default roles, how a permission is built from a resource, an action and a scope, and how to build and assign a custom role.
Assignment, delegation and out of office
How a gate reaches a person: user groups, round-robin and assign-to-all routing, out-of-office windows that skip a member automatically, and the assignment log.
Reviews, approvals and gates
Configurable gate outcomes, parallel domain-scoped SME reviews, multi-approver and threshold logic, and return-for-rework loops with reasons and round counts.
Email and notifications
Every email Coverbase sends to your team and your vendors, how each person controls delivery and digests, and how your logo and brand color reach emails and portals.
White-labeling your vendor-facing domain
Sending vendor email and hosting the portal on your own subdomain, and choosing between Coverbase-managed and organization-managed DNS.
Vendors
The vendor record is where everything else attaches: services, engagements, documents, assessments, contracts, findings, obligations and the supplier’s bank and tax details.The vendor record
The vendor list and one vendor’s page: tabs and sidebar cards, services and engagements, subprocessors and nth parties, owners and directory contacts, custom fields, tags, and archiving.
Supplier information guide
How bank details, addresses, tax registrations and diversity records are collected through a questionnaire, checked against the rules for the supplier’s country, reviewed before they take effect, and handed to your finance system.
Supplier countries
All 109 countries Coverbase validates, with the exact fields, formats, check digits and registers each one uses. Useful before you send a request, and when you are reading a warning on a submitted record.
Requesting a new vendor
The requester’s side of intake: filing in the portal or in chat, what you will be asked, how to get through it faster, and what happens after you submit.
Centralized supplier portal
One page where a supplier signs in and sees every request you have open with them, keeps their own profile current, and answers your findings. How to turn it on and what each setting decides.
The supplier portal, for suppliers
The page to send a supplier: signing in, everything open with you in one place, keeping their details current, and bringing colleagues in.
Every country page, by name
Every country page, by name
Each page lists the exact fields, formats, check digits and registers for that country. The country overview has the full table of all 109.Australia ·
Brazil ·
Bulgaria ·
Canada ·
China ·
Colombia ·
Côte d’Ivoire ·
Finland ·
France ·
Germany ·
Ghana ·
Hong Kong SAR ·
India ·
Indonesia ·
Ireland ·
Italy ·
Japan ·
Malaysia ·
Mauritius ·
Mexico ·
Netherlands ·
Nigeria ·
Oman ·
Peru ·
Philippines ·
Poland ·
Portugal ·
Saudi Arabia ·
Singapore ·
South Africa ·
South Korea ·
Spain ·
Sweden ·
Switzerland ·
Thailand ·
Türkiye ·
United Arab Emirates ·
United Kingdom ·
United States
Assessing a vendor
The assessment is the center of the platform, so it gets the most pages: the full walkthrough, a cheat sheet to keep open beside it, the questionnaire mechanics, the packaged inherent risk templates, how web evidence is vetted, and the lightweight run for vendors that do not warrant the full treatment.How to run an assessment
The complete lifecycle, screen by screen. Getting the vendor in, creating the assessment from a plan, collecting evidence five different ways, working the issues, follow-up cycles, domain reviews, and the final export.
Assessment quick reference
The cheat sheet. Five steps, quick tips, common scenarios, a troubleshooting table, and the control frameworks at a glance.
Questionnaires
Build a template, set conditional logic and internal-only questions, write answers back to the record, assign reviewers, send it to a vendor, and work a submission through to a decision.
The IRQ library
The six inherent risk questionnaires Coverbase ships: every question each one asks, how the score is calculated, and how to pick and tailor the right starting point.
Evidence quality and source credibility
How every web page is graded for publisher accountability, where you set the minimum bar, what appears on evidence cards and in the Excel export, and exactly which parts of the platform this covers.
Zero Touch Assessment guide
A triage run assembled entirely from open-source research, with no outreach. How to run one across a portfolio, read the composite and its components, correct a run that bound the wrong company, and read the audit trail.
Document library
Where the Coverbase library documents on every vendor came from, how they are reviewed before they appear, and why nothing your organization uploads is ever added to them. This page sits with the product pages rather than here.
Findings and obligations
Two records that look alike and answer different questions. A finding is a problem on the vendor’s side. An obligation is work your organization owes because of the vendor.Findings and remediation
What happens after a finding exists: the Findings page, the statuses and how commitments set them, asking a vendor for a commitment through the portal, verifying the work, findings settings, and where findings show up elsewhere.
Obligations
How obligations are extracted from SOC reports and contracts, the list and the record, what each status means, assigning an owner, asking a business unit to acknowledge one, and where obligations feed the risk register and workflows.
Checking a vendor without contacting them
The Vendor Intelligence section on a vendor is a set of tabs, each assembled from public sources without contacting the vendor, and each designed to be checked rather than trusted. There is one guide per tab below, plus the older combined walkthrough the first four replaced.Corporate registrations guide
Whether there is a real, currently registered company behind the vendor, and whether it is the one you think it is. How to read a match verdict, and what a dissolved status means on a vendor you are paying.
People intelligence guide
Who runs the vendor, and what adverse-media screening found about them. Why confirmed and unconfirmed names are counted differently, and why “not screened” is never the same as “nothing found”.
Financial health guide
How likely the vendor is to still be trading. What the confidence tier tells you about the number, and how private companies with no filings are scored.
Security intelligence guide
The outside-in security rating measured against the vendor’s own infrastructure. What each factor covers, and what a not-measured factor does and does not tell you.
Sanctions screening guide
Whether the vendor or its people appear on a sanctions, watchlist, criminal or legal source, re-checked on a schedule rather than once at onboarding. Why the confidence score measures identity and not severity, and how to clear a false positive.
Financial health and security intelligence
The older combined walkthrough, covering the Financial Health Score and External Security Intelligence cards as they appear on the fact sheet. The two dedicated guides above go deeper.
Monitoring between assessments
Radar watches your vendors in the gap between reviews. Sources collect, detectors decide what deserves an alert, and signals land in a queue for someone to triage.Working Radar signals
The vocabulary, the signal queue and its statuses, triaging a signal into a case, a finding or a reassessment, keeping sources and detectors tuned, and where a signal goes next.
Black Kite monitoring guide
How to connect your Black Kite portfolio, choose which vendors are watched, and turn known exploited vulnerabilities and focus tags into alerts.
Bills of materials
How to upload a vendor’s SBOM, keep the right version applied, and get an alert when a known exploited vulnerability affects one of its components.
Breach notification monitoring guide
How to watch state attorney general breach registries and SEC cyber incident filings, and turn a filing that names your vendor into an alert.
Risk
The Risk module holds the register, the dependency chain, scenarios, exposure and the board report. The geography map lives under the same entry.The Risk module: register, signals and scenarios
Score a risk on the 5x5, let findings, contracts and Radar feed it as signals, decide on what the agent proposes, trace the dependency chain, run a what-if scenario, and produce the board pack.
Risk geography map
Where your suppliers are, which metros they pile up in, and how to narrow the map with the same vendor filters you use on the vendor list. Also covers why archived suppliers are hidden by default.
Contracts
Start with the workspace guide to learn the screens. Then it splits four ways: getting a contract in (intake and the repository), what a contract is (components and dates), what its language says (Contract Guardian and negotiation rounds), and what values to pull out of it (Document Insights, under Documents below).Contracts workspace
The screens you work in every day. The attention cards, the table and renewal runway views of the list, and the cards on a contract record.
Contract intake and approval
Raise a contract request from a vendor, confirm what the AI read off the draft, route it through your approval chain, and send the approved agreement to DocuSign.
The contracts repository
Forward an agreement to your organization’s paralegal inbox, and let Coverbase name, deduplicate, version and file it. The inbox log, the folder schemes and the settings behind the address.
Contract components
The catalog. Every component Coverbase reads a contract into, what it interprets each one as, which contract fields it may answer, and what happens when two documents claim the same one.
Contract dates and reminders
The contract timeline. What each date means, which ones Coverbase calculates and why they cannot be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.
Negotiation rounds
Upload the marked-up contract a vendor sends back, see what they changed, which of your asks they accepted, and what they edited without being asked, without starting the clause review over.
Clause review with Contract Guardian
Contract Guardian guide
Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable and unacceptable language, then run reviews and triage the deviations.
The clause set library
The 12 packaged clause standards Coverbase ships, from Enterprise SaaS to HIPAA to Payments. What each one covers, which clauses would block a signature, and how to choose a starting point.
Generate a clause set from your own contract
Upload your template MSA or DPA and let Coverbase extract a clause set from it. What extraction gives you, why it drops language it cannot quote, and the tiering you still have to write yourself.
Import and export clause sets as spreadsheets
Already have your clause playbook in Excel? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.
Getting it signed
Coverbase signs agreements in the same place it stores them, so the executed copy and the evidence that it happened land on the contract and the vendor without anyone filing them.E-signature overview
Start here. The four moving parts, the shape of a signing, the envelope statuses, and the organization-wide settings worth doing once before your first send.
Signature templates
Build an NDA or order form once: the source document, the signing parties as roles rather than people, and the fields each role fills. Plus what freezes a template, and why it is the first send rather than publishing.
Sending for signature
The four-step send wizard, routing order and access codes, tracking what is out, correcting or voiding an envelope, and the hash-chained audit trail.
The signing experience
The counterparty’s side: consent, filling, adopting one signature that covers every block, and the executed copy they keep. Plus how to brand the portal as yours.
Documents
Three guides about the documents on a vendor: the values Coverbase pulls out of every one, asking them a question in chat, and the reminders that fire before one lapses.Document Insights guide
Field-level extraction. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract versus Synthesize.
Asking your documents a question
Ask a plain-English question in chat and get back the passage from a vendor’s documents that answers it: the verbatim quote, its page, a cropped image of the passage, and a link that opens the document with it marked.
Document expiry reminders
How Coverbase reminds you before a vendor document lapses: which dates it fires from, who receives the email, and where to see everything that is expiring.
Workflows and automation
Automations that react when a record changes: the ready-made templates, and building your own from a trigger, conditions and an action.Workflow templates
The nineteen ready-to-run automations Coverbase ships: what each one does, which modules it needs, what you have to change before turning it on, and how to make one your own.
Building a workflow
Pick a trigger, narrow it with conditions, configure the action, use placeholders, test it, switch it on, then read the runs and the work queue items it produces.
Dashboards and reporting
What the program looks like from above, drawn live from your own records, and the documents you hand to someone else.Dashboards and the chart library
The 15 dashboards and 110 charts Coverbase ships ready to use: a board overview, a cycle-time and SLA view, contract spend and renewals, savings, intake demand, control assurance, tag coverage, findings and Radar triage. Every one is a copy you own and can edit.
Reporting overview
The two kinds of assessment deliverable: standard exports, and custom Word report templates filled from live assessment data. Which one to use, and how a custom report is generated.
Custom Word report templates
Author the branded
.docx: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.Placeholder reference
Every vendor, assessment, service, review and finding placeholder, with its resolved value and formatting.
Evidence packaging and the due-diligence file
Produce the complete file for one third party, and assemble an examination package.
Sourcing and RFPs
Vendor selection with risk and compliance evaluation built into it rather than bolted on afterwards. The product page behind this is RFP Platform.How to run an RFP
One sourcing event end to end. Draft the RFP with the AI wizard, compare the field without contacting anyone, score responses against your rubric with evidence attached, read the pricing side by side, and record the decision in a memo somebody can read a year later.
Internal controls
Coverbase against your own applications, with the same findings, workflows and reporting as third-party risk.Internal controls monitoring with Inspect
Connect your applications through Okta, Entra or Google, run an inspection against an internal control set, read the result, watch for drift between runs, keep probes and schedules running, and turn what it finds into findings.
The complete directory
Every guide in this section, in one table.Reference pages that live outside these guides
Pages every guide points at sooner or later. They sit elsewhere in the documentation because they are reference rather than walkthrough.Control Set library
Both halves of the packaged library and what each set measures: the vendor frameworks to assess a third party against, and the internal sets Inspect evaluates against your own applications.
Field reference
Every filterable field, its path, and where it comes from. The same paths drive saved views, workflow conditions and the query API.
What each product does
A page per capability, from Autonomous Intake to internal controls monitoring, for when you want the what and why before the how.
How Coverbase thinks
A little context makes everything else click.Document-first, not questionnaire-first
Document-first, not questionnaire-first
Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor’s documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
The AI drafts, humans judge
The AI drafts, humans judge
A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it is easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
Configuration changes are not retroactive
Configuration changes are not retroactive
For auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you have already signed off on changes underneath you.
Looking something up
The questions people arrive with, and the place each one is answered.Need a hand
Product support
Email support@coverbase.ai for technical questions.
Live working sessions
Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding and configuration.