For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It’s for the person who wants to start using a new tool or vendor, not for the risk team reviewing the request. If you’re on the reviewing side, see the Analyst and reviewer guide.
Read this part first
When you finish, your request goes to your security or due diligence team, and they decide it. A vendor record may appear in Coverbase with your request attached, but it sits in Created status. It is not an approved vendor until someone reviews and accepts it. This trips people up, so it’s worth being blunt: a completed intake form means “asked”, not “allowed”. Wait for the decision before you commit spend or send data.Two ways to file one
The portal
A three-step form: Select Vendor, Additional Information, Review Questionnaires. Use the link your admin gave you.
Chat
Ask an AI assistant connected to Coverbase. Same request, same queue, no form.
I want to start using PostHog for product analytics.
My team needs a load testing tool and we’re looking at k6. Can we buy it?
Is Snowflake approved for us to use?That last one checks first and offers to file a request only if there isn’t already an approved record.
What you’ll be asked
1
Which vendor, exactly
Coverbase researches the company and shows you what it found: what they do, their website, their headquarters, their trust center. Check it. Two companies called Acme is the normal case, and a request filed against the wrong one gets sent back to you a week later. If it’s wrong, say so and correct it.
2
Whether you already have something that does this
You’ll be shown existing vendors in your portfolio that cover the same job, and any prior relationship with this vendor. Depending on how your admin configured things, you may also see alternatives found on the web.This isn’t an obstacle. If an approved vendor already does what you need, using it means no review, no procurement cycle, and no new contract. Take the shortcut when it’s there.
3
What you'll use it for
You get a short list of concrete use cases this vendor is actually bought for, not a blank box. Pick one, or type your own if none fit.
4
Which services are in scope
Same shape: a list of candidate services, and you can add one that isn’t listed.
5
The inherent risk questionnaire
The big one, and the one Coverbase does most of for you. It answers what it can from public sources and whatever context you provided, then shows you each answer with the reasoning behind it.Your job is to check them. Answers Coverbase was confident about are marked as such; the ones it wasn’t are flagged for you to look at first. Anything about your intended use, the data you’ll send, or your internal owner is yours to answer, because no amount of public research can find it.
Which of these steps you see depends on how your organization configured its intake portal. Some orgs turn off web alternatives, or pre-qualification, or prior assessment history. If a step described here doesn’t appear for you, that’s a deliberate choice by your admin, not a bug.
Getting through it faster
Give context up front
Give context up front
Anything you already know: the use case, the data types involved, a link to their security page, the team that’ll own it. Coverbase feeds that into the drafting, so more context up front means fewer questions for you later.
Work the flagged answers first
Work the flagged answers first
Drafted answers come with a confidence signal. The low-confidence ones usually name exactly what was missing, and they’re where your knowledge actually adds something. The high-confidence ones mostly need a glance.
Finish it in one sitting if you can
Finish it in one sitting if you can
A partially answered request isn’t in anyone’s queue. It sits open until you come back to it. If you do have to stop, you can pick it up later, in the portal or by asking the assistant where your request got to.
Don't guess on data questions
Don't guess on data questions
Questions about what customer data flows to the vendor drive the whole depth of the review. An optimistic answer here means a review scoped too shallow, which is the failure mode that actually hurts. If you don’t know, say you don’t know.
After you submit
Your request lands in the risk team’s review queue with everything attached: your answers, the enrichment, the screening results, and the duplicate check. From there one of three things happens:- Approved. Onboarding starts and an assessment is created against the right control set, sized to the risk your answers indicated.
- Sent back. A reviewer needs something clarified. You’ll get a specific question rather than a rejection.
- Rejected. Usually because an approved vendor already covers the need, or the screening surfaced something disqualifying.
Related
Vendor intake in chat
The full conversational flow, step by step, including what your assistant will and won’t do on its own.
Analyst and reviewer guide
What happens to your request on the other side, and what reviewers are looking for.