> ## Documentation Index
> Fetch the complete documentation index at: https://docs.coverbase.com/llms.txt
> Use this file to discover all available pages before exploring further.

# User Guides

> Step-by-step guides for getting started with Coverbase, from a blank environment to running vendor risk end to end.

<Info>
  Welcome. This is a shareable home for Coverbase's getting-started guides. It doesn't show up in the main documentation navigation, so anyone you send the link to can read it, and you can bookmark it for your team. We'll add more here over time (Radar and the rest).
</Info>

Coverbase is your AI-powered platform for third-party risk and procurement. These guides take you from an empty environment to a running program: importing vendors, telling the platform what "good" looks like, and then doing the daily work of assessing vendors and acting on what you find.

You don't need any prior Coverbase experience. Each guide reads start to finish, with real screenshots of the platform along the way.

## Two ways in, depending on your role

The work splits cleanly into two jobs. Pick the guide that matches what you're here to do, or read both if you wear both hats.

<CardGroup cols={2}>
  <Card title="Admin and setup guide" icon="sliders" href="/user-guides/admin-setup">
    For the program owner or administrator standing up the environment. You'll import your vendors, build your tag structure and intake questionnaire, tune scales and control sets, and set up templates, monitoring, and integrations. This is where the AI gets its instructions.
  </Card>

  <Card title="Analyst and reviewer guide" icon="user-check" href="/user-guides/analyst-reviewer">
    For the analysts and reviewers doing the daily work. You'll triage new vendor requests, launch assessments, review what the AI found, correct it where it's wrong, engage vendors, and close the loop with findings, reports, and monitoring.
  </Card>
</CardGroup>

## Asking for a new vendor

Most people who touch Coverbase touch it exactly once: to request a tool their team wants. That guide is deliberately short and assumes nothing.

<Card title="Requesting a new vendor" icon="cart-shopping" href="/user-guides/requesting-a-vendor">
  For the business requester, not the risk team. What you'll be asked, how to file in the portal or in chat, how to get through it faster, and the thing people most often get wrong: submitting a request is not approval.
</Card>

## Running an assessment

The assessment is the centre of the platform, so it gets two pages of its own: a full walkthrough and a cheat sheet.

<CardGroup cols={2}>
  <Card title="How to run an assessment" icon="list-check" href="/user-guides/running-an-assessment">
    The complete lifecycle, screen by screen: getting the vendor in through intake or the New Vendor wizard, creating the assessment from a plan, collecting evidence five different ways, working the issues, running follow-up cycles, domain reviews, and the final export.
  </Card>

  <Card title="Assessment quick reference" icon="bolt" href="/user-guides/assessment-quick-reference">
    A one-page cheat sheet: the five steps, quick tips, common scenarios, and a troubleshooting table. Keep it open in a tab while you work.
  </Card>
</CardGroup>

## Controlling the quality of evidence

Assessments lean on the public web when documents run out. This guide is the one to send anyone who asks how that evidence is vetted.

<Card title="Evidence quality and source credibility" icon="shield-check" href="/user-guides/evidence-quality">
  How every web page is graded for publisher accountability before it can be cited, where you set the minimum bar (per control set or per control), how credibility, relevance, and freshness are kept separate, what shows up on evidence cards and in the Excel export, and exactly which parts of the platform this covers.
</Card>

## Financial health and security intelligence

Two cards in every vendor's Vendor Intelligence section carry a score rather than a description. Both are assembled without contacting the vendor, and both are designed to be checked rather than trusted. The product pages behind them are [Financial Health Score](/products/financial-health-score) and [Security Intelligence](/products/security-intelligence).

<Card title="Financial health and security intelligence guide" icon="gauge-high" href="/user-guides/vendor-fact-sheet">
  How to read the Financial Health Score and Security Posture cards: why the confidence tier matters more than the number, how to open the rationale behind any score, what "unmeasured" means and why it isn't a failing grade, and how to turn a finding into a question a vendor can actually answer.
</Card>

## Contracts

Contract intelligence has two halves, and they're set up separately. Read both if you own the contracts module.

<CardGroup cols={2}>
  <Card title="Contract Guardian guide" icon="file-contract" href="/user-guides/contract-guardian">
    Language-level. Build a clause set from the packaged library or from your own template contract, write the risk-tier variants that define acceptable, negotiable, and unacceptable language, then run reviews and triage the deviations.
  </Card>

  <Card title="Document Insights guide" icon="file-magnifying-glass" href="/user-guides/document-insights">
    Field-level. Define the values Coverbase pulls out of every document (dates, caps, notice periods, governing law), with a starter library to copy and a straight answer on when to use Extract vs Synthesize.
  </Card>

  <Card title="Baseline contract extraction" icon="wand-magic-sparkles" href="/user-guides/baseline-contract-extraction">
    Turn your own template MSA or DPA into a clause set. What extraction gives you, and the tiering you still have to write.
  </Card>

  <Card title="Clause set spreadsheet import and export" icon="file-import" href="/user-guides/clause-set-spreadsheet-import">
    Already have your clause playbook in a spreadsheet? The workbook format, every column explained, what happens when you re-upload a file, and how to export a set back out to branch it.
  </Card>

  <Card title="Contract dates and reminders" icon="calendar-days" href="/user-guides/contract-dates-and-reminders">
    The contract timeline: what each date means, which ones Coverbase calculates and why they can't be cleared, who gets the reminder emails, and how to turn a reminder off for a single contract.
  </Card>
</CardGroup>

## Building your report template

Both guides touch report templates: the admin builds one, the analyst exports against it. The authoring detail lives in its own reference, which sits in the main documentation rather than here.

<CardGroup cols={2}>
  <Card title="Custom Word report templates" icon="file-word" href="/reporting/assessment-report-templates">
    Author the branded `.docx`: placeholder syntax, AI-written sections, repeating findings tables, and signature anchors.
  </Card>

  <Card title="Placeholder reference" icon="brackets-curly" href="/reporting/template-placeholders">
    Every vendor, assessment, service, review, and finding placeholder, with its resolved value and formatting.
  </Card>
</CardGroup>

## The order things happen

Starting from a blank environment, the two guides run in sequence. An admin configures the platform once. After that, analysts run assessments against that configuration every day.

<Steps>
  <Step title="Set up the environment (admin)">
    Import vendors, create tags, build and weight the intake questionnaire, configure scales and control sets, and set your templates, monitoring, and integrations. Follow the [Admin and setup guide](/user-guides/admin-setup).
  </Step>

  <Step title="Run the work (analyst and reviewer)">
    Triage requests, launch assessments, review and correct AI findings, follow up with vendors, and disposition results. Follow the [Analyst and reviewer guide](/user-guides/analyst-reviewer), or [How to run an assessment](/user-guides/running-an-assessment) for the screen-by-screen version of a single assessment.
  </Step>

  <Step title="Keep improving">
    Every correction a reviewer makes teaches the platform, so the issue count falls with each cycle. Monitoring keeps working in the background. The program gets sharper over time.
  </Step>
</Steps>

## How Coverbase thinks

A little context makes everything else click.

<AccordionGroup>
  <Accordion title="Document-first, not questionnaire-first" icon="file-magnifying-glass" defaultOpen>
    Traditional TPRM sends vendors long questionnaires and trusts their self-reported answers. Coverbase works the other way around. It collects the vendor's actual documents (SOC 2, pen test, ISO certificates, policies, contracts), parses the whole set, and measures that evidence against your controls. Most of what you configure exists to guide that measurement, and questionnaires become a targeted backup for the gaps rather than the starting point.
  </Accordion>

  <Accordion title="Tags are the routing engine" icon="tags">
    When someone requests a vendor, their answers to the intake questionnaire apply tags automatically. Tags then decide which control frameworks apply, which documents are required, which team reviews, and how the vendor is scored. A financial-services vendor handling PHI in the EU gets a very different track than a US-only SaaS tool with read-only access, and it happens without manual triage.
  </Accordion>

  <Accordion title="The AI drafts, humans judge" icon="scale-balanced">
    A typical assessment measures a hundred-plus controls and surfaces a handful of material issues. In one real case, 111 controls produced 5. The AI does the reading and you do the judging. Every result carries citations to the source language, so when the AI is wrong it's easy to see, and when you correct it, that correction is permanent and applies to every future assessment.
  </Accordion>

  <Accordion title="Configuration changes aren't retroactive" icon="clock-rotate-left">
    By design, for auditability, edits to questionnaires and control sets apply going forward. Completed submissions and assessments keep the version they ran on, and a control-set edit creates a new version rather than overwriting the old one. If a new standard has to apply to existing vendors, you run a bulk reassessment. Nothing you've already signed off on changes underneath you.
  </Accordion>
</AccordionGroup>

## What you'll be able to do

<CardGroup cols={2}>
  <Card title="Automated vendor intake" icon="inbox-in">
    Route requests to the right teams automatically, with most intake questions already answered by the platform's research agent.
  </Card>

  <Card title="AI-powered assessments" icon="robot">
    Cut review time sharply. The AI reads the evidence and surfaces only the gaps that need a human.
  </Card>

  <Card title="Continuous monitoring" icon="satellite-dish">
    Get alerted within hours of a material risk event across your third and fourth parties, instead of waiting for the next annual review.
  </Card>

  <Card title="Branded vendor portals" icon="palette">
    Vendors interact with a portal that carries your logo and your voice, not ours.
  </Card>
</CardGroup>

## Need a hand?

<CardGroup cols={2}>
  <Card title="Product support" icon="envelope" href="mailto:support@coverbase.ai">
    Email [support@coverbase.ai](mailto:support@coverbase.ai) for technical questions.
  </Card>

  <Card title="Live working sessions" icon="chalkboard-user">
    Your Coverbase team runs hands-on sessions and walks through each step on screen with you.
  </Card>
</CardGroup>

<Note>
  The screenshots throughout these guides come from a demo environment with sample vendors and data. Your environment will show your own vendors, branding, and configuration.
</Note>
