Skip to main content
For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It’s for the person who wants to start using a new tool or vendor, not for the risk team reviewing the request. If you’re on the reviewing side, see the Analyst and reviewer guide.
You found a tool your team needs. Before anyone signs anything, your organization needs to know who the vendor is, what data they’ll touch, and whether you already pay for something that does the same job. That’s what a vendor intake request is, and it should take you a few minutes rather than an afternoon. Coverbase does most of the typing. You confirm, correct, and decide.

Read this part first

Submitting a request is not approval. It does not authorize you to buy, sign, expense, or deploy anything.
When you finish, your request goes to your security or due diligence team, and they decide it. A vendor record may appear in Coverbase with your request attached, but it sits in Created status. It is not an approved vendor until someone reviews and accepts it. This trips people up, so it’s worth being blunt: a completed intake form means “asked”, not “allowed”. Wait for the decision before you commit spend or send data.

Two ways to file one

The portal

A three-step form: Select Vendor, Additional Information, Review Questionnaires. Use the link your admin gave you.

Chat

Ask an AI assistant connected to Coverbase. Same request, same queue, no form.
They produce the same thing. Pick whichever you’re already in front of. To file in chat, just say what you want in ordinary language. You don’t need to know the word “intake”:
I want to start using PostHog for product analytics.
My team needs a load testing tool and we’re looking at k6. Can we buy it?
Is Snowflake approved for us to use?
That last one checks first and offers to file a request only if there isn’t already an approved record.

What you’ll be asked

1

Which vendor, exactly

Coverbase researches the company and shows you what it found: what they do, their website, their headquarters, their trust center. Check it. Two companies called Acme is the normal case, and a request filed against the wrong one gets sent back to you a week later. If it’s wrong, say so and correct it.
2

Whether you already have something that does this

You’ll be shown existing vendors in your portfolio that cover the same job, and any prior relationship with this vendor. Depending on how your admin configured things, you may also see alternatives found on the web.This isn’t an obstacle. If an approved vendor already does what you need, using it means no review, no procurement cycle, and no new contract. Take the shortcut when it’s there.
3

What you'll use it for

You get a short list of concrete use cases this vendor is actually bought for, not a blank box. Pick one, or type your own if none fit.
4

Which services are in scope

Same shape: a list of candidate services, and you can add one that isn’t listed.
5

The inherent risk questionnaire

The big one, and the one Coverbase does most of for you. It answers what it can from public sources and whatever context you provided, then shows you each answer with the reasoning behind it.Your job is to check them. Answers Coverbase was confident about are marked as such; the ones it wasn’t are flagged for you to look at first. Anything about your intended use, the data you’ll send, or your internal owner is yours to answer, because no amount of public research can find it.
Behind the scenes, Coverbase also screens the vendor’s financial stability, security posture, and sanctions status, and checks whether the request duplicates something you already have. You don’t have to ask for any of that. It happens as part of the flow, and you’ll see the results.
Which of these steps you see depends on how your organization configured its intake portal. Some orgs turn off web alternatives, or pre-qualification, or prior assessment history. If a step described here doesn’t appear for you, that’s a deliberate choice by your admin, not a bug.

Getting through it faster

Give context up front

Anything you already know: the use case, the data types involved, a link to their security page, the team that’ll own it. Coverbase feeds that into the drafting, so more context up front means fewer questions for you later.
Drafted answers come with a confidence signal. The low-confidence ones usually name exactly what was missing, and they’re where your knowledge actually adds something. The high-confidence ones mostly need a glance.
A partially answered request isn’t in anyone’s queue. It sits open until you come back to it. If you do have to stop, you can pick it up later, in the portal or by asking the assistant where your request got to.
Questions about what customer data flows to the vendor drive the whole depth of the review. An optimistic answer here means a review scoped too shallow, which is the failure mode that actually hurts. If you don’t know, say you don’t know.

After you submit

Your request lands in the risk team’s review queue with everything attached: your answers, the enrichment, the screening results, and the duplicate check. From there one of three things happens:
  • Approved. Onboarding starts and an assessment is created against the right control set, sized to the risk your answers indicated.
  • Sent back. A reviewer needs something clarified. You’ll get a specific question rather than a rejection.
  • Rejected. Usually because an approved vendor already covers the need, or the screening surfaced something disqualifying.
Note that you can’t edit your answers after submitting. A reviewer can correct them on the way through, and can send the request back to you if something needs your input.

Vendor intake in chat

The full conversational flow, step by step, including what your assistant will and won’t do on its own.

Analyst and reviewer guide

What happens to your request on the other side, and what reviewers are looking for.