For AI agents: a documentation index is available at https://docs.coverbase.com/llms.txt. This page is also available in markdown by appending .md to the URL.
This guide is part of the User Guides collection. It is for the person who wants to start using a new tool or vendor, not for the risk team reviewing the request. If you are on the reviewing side, see the Analyst and reviewer guide.
Read this part first
When you finish, your request goes to your security or due diligence team, and they decide it. A vendor record may appear in Coverbase with your request attached, but it sits in Created status. It is not an approved vendor until someone reviews and accepts it. A completed intake form means “asked”, not “allowed”. Wait for the decision before you commit spend or send data.Two ways to file one
The portal
A three-step form: Select Vendor, Additional Information, Review Questionnaires. Use the link your admin gave you.
Chat
Ask an AI assistant connected to Coverbase. Same request, same queue, no form.
I want to start using Northwind Analytics for product analytics.
My team needs a load testing tool and we’re looking at Loadspin. Can we buy it?
Is Acme approved for us to use?That last one checks first and offers to file a request only if there is not already an approved record.
What you’ll be asked
1
Which vendor, exactly
Coverbase researches the company and shows you what it found: what they do, their website, their headquarters, their trust center. Check it. Two companies called Acme is common, and a request filed against the wrong one is sent back to you. If it is wrong, say so and correct it.
2
Whether you already have something that does this
You are shown existing vendors in your portfolio that cover the same job, and any prior relationship with this vendor. Depending on how your admin configured things, you may also see alternatives found on the web.If an approved vendor already does what you need, using it means no review, no procurement cycle, and no new contract.
3
What you'll use it for
You get a short list of use cases this vendor is commonly bought for, rather than a blank box. Pick one, or type your own if none fit.
4
Which services are in scope
A list of candidate services. You can add one that is not listed.
5
The inherent risk questionnaire
Coverbase does most of this one for you. It answers what it can from public sources and whatever context you provided, then shows you each answer with the reasoning behind it.Check them. Answers Coverbase was confident about are marked as such; the ones it was not are flagged for you to look at first. Anything about your intended use, the data you will send, or your internal owner is yours to answer, because public research cannot find it.
Which of these steps you see depends on how your organization configured its intake portal. Some orgs turn off web alternatives, or pre-qualification, or prior assessment history. If a step described here does not appear for you, your admin turned it off.
Getting through it faster
Give context up front
Give context up front
Anything you already know: the use case, the data types involved, a link to their security page, the team that will own it. Coverbase feeds that into the drafting, so more context up front means fewer questions for you later.
Work the flagged answers first
Work the flagged answers first
Drafted answers come with a confidence signal. The low-confidence ones usually name what was missing, and they are where your knowledge adds the most. The high-confidence ones mostly need a glance.
Finish it in one sitting if you can
Finish it in one sitting if you can
A partially answered request is not in anyone’s queue. It sits open until you come back to it. If you do have to stop, you can pick it up later, in the portal or by asking the assistant where your request got to.
Do not guess on data questions
Do not guess on data questions
Questions about what customer data flows to the vendor drive the whole depth of the review. An optimistic answer here means a review scoped too shallow. If you do not know, say so.
After you submit
Your request lands in the risk team’s review queue with everything attached: your answers, the enrichment, the screening results, and the duplicate check. From there one of three things happens:- Approved. Onboarding starts and an assessment is created against the right control set, sized to the risk your answers indicated.
- Sent back. A reviewer needs something clarified. You get a specific question rather than a rejection.
- Rejected. Usually because an approved vendor already covers the need, or the screening surfaced something disqualifying.
Related
Vendor intake in chat
The full conversational flow, step by step, including what your assistant will and will not do on its own.
Analyst and reviewer guide
What happens to your request on the other side, and what reviewers are looking for.