# Request and Review Vendors

This article explains how vendor intake requests are raised and reviewed in Sprinto.\
It covers:

* How employees request new vendors
* How reviewers (Vendor Admins) are notified
* How reviewers evaluate an intake vendor
* How to update the vendor’s lifecycle stage (Intake, Active, Archived)
* What happens after a vendor is approved or archived

Vendor requests support organisations that evaluate tools before onboarding them. Intake requests help GRC, Security, Legal, and Finance teams assess vendors before marking them as Active.

***

## **Roles**

#### **Employee / Business Owner**

* Can request a vendor from the Employee Portal
* Can view and edit intake requests (until decisioned)
* Receives notifications when the request is submitted and when a reviewer acts on it

#### **Vendor Admin / Reviewer**

* Reviews all vendors in the **Intake** stage
* Can update vendor details, scoring, due diligence, and documents
* Decides whether the vendor should become **Active** or move to **Archived**
* Receives notifications when a vendor is added to Intake

***

## **Part 1: Request a Vendor (Employee Portal)**

### **Step 1: Navigate to Vendors**

1. Log in to the Sprinto Employee Portal.
2. Navigate to **Vendors**.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FqhcoBGeeu1rRBkrpY5Ob%2FEmployee%20-%20Intake%20requests%20(1).png?alt=media&#x26;token=8463fa68-1b92-4cb8-ae62-8155612e019a" alt="" width="563"><figcaption></figcaption></figure>

### **Step 2: Enter vendor details**

1. Select **Request vendor** to open the Add vendor drawer.
2. Employees can enter:
   * Vendor name (required)
   * Description
   * Category (required)
   * Company logo
   * Intake request reason (required)
   * Internal business contact
   * Vendor contact (name and email)
   * Any custom fields defined by your organisation

{% hint style="info" %}
**Important:** Employees cannot choose a Stage.\
All employee-created vendors are added to the **Intake** stage.
{% endhint %}

3. Select **Save**.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FuQai8FPQaH3uLJIbR9Dx%2FAdd%20vendor%20(2).png?alt=media&#x26;token=7ca601c1-6d2f-4c38-a9e1-3c9af3d1d3a2" alt="" width="563"><figcaption></figcaption></figure>

### **Step 3: View your vendor requests**

After saving:

* The vendor appears in the employee’s **Intake requests** list.
* Employees can:
  * View details
  * Edit the request while it is still in Intake
  * Track whether the reviewer has decisioned it

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FWZcwwPjRmma3vfaCCuw2%2FException%20detail%20(2).png?alt=media&#x26;token=2e5a43fb-ae18-42ea-b6ed-3c2d954de7e0" alt="" width="563"><figcaption></figcaption></figure>

### **Notifications**

After a vendor request is submitted, Sprinto notifies:

* The requestor (employee)
* The Internal Business Owner (if defined)
* The Vendor Admin (default is the InfoSec Officer, unless configured otherwise)

Each notification includes a link to the vendor details page.

***

## **Part 2: Review Vendor Requests (Admin Portal)**

### **Step 1: Reviewer receives a notification**

1. When a vendor is added to Intake, the Vendor Admin is notified.
2. The notification links directly to **Data Library → Vendors → All vendors (Stage = Intake).**
3. This list shows all vendors pending review.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FLTo7KNzICKutWF9YqQAQ%2FAll%20vendors%20-%20added%20(1).png?alt=media&#x26;token=caa976b8-f128-4bd9-a7f6-faa1fe1c800a" alt="" width="563"><figcaption></figcaption></figure>

### **Step 2: Open the intake vendor**

1. In the Admin Portal, go to **Data Library** > **Vendors**.
2. Use the **View** dropdown to select **Intake**.
3. Select a vendor to open its vendor details drawer.

You will see:

* **Details**
* **Risk score**
* **Due diligence**
* **Documents**
* **Findings**
* **Tasks**

These tabs function similarly to those for Active vendors.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FVnSasuTQJAHXJWSd3TcU%2FAll%20vendors%20-%20added%20(1).png?alt=media&#x26;token=4e876f78-e826-42d3-9768-8365c5691620" alt="" width="563"><figcaption></figcaption></figure>

### **Step 3: Review intake-specific monitor**

Intake vendors display a single task-based monitor:

**Vendor intake request should be decisioned**

* Assigned to the Vendor Admin
* Default SLA: 30 days
* Status: Failing or Pending until decisioned

Select **Fix issue** to begin the decision process.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FiZ6AKxmlTFeI2kXwQu49%2FTemplate.png?alt=media&#x26;token=aeb14c04-184d-4096-ae0a-c0cf404fe96a" alt="" width="563"><figcaption></figcaption></figure>

***

## **Part 3: Update the Vendor Stage**

Selecting **Fix issue** opens the **Update stage** modal.

The modal displays:

* **Intake**
* **Active**
* **Archived**

The current stage is marked with a **Current** badge.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2Fq8UmTUcVLstC9QPdlc09%2FUpdate%20stage.png?alt=media&#x26;token=4524a402-9c05-4bdf-a75a-77486277b085" alt="" width="525"><figcaption></figcaption></figure>

### **Option 1: Approve the vendor (move to Active)**

1. Select **Active**.
2. Select **Save**.

#### **What happens next**

* The intake monitor switches to **Passing**.
* Two new monitors are added:
  * **Vendor risk should be scored**
  * **Periodic review of access-critical systems**
* Any risk scoring or due diligence begun during Intake is retained.
* The requestor, Internal Business Owner, and Vendor Admin receive notifications.
* The vendor becomes read-only for the employee; the “request reason” field is hidden.

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FYfglmC0OpE85z85D2If7%2FTemplate%20(1).png?alt=media&#x26;token=ed552f58-aae6-4bc0-b0ba-25e52d78e671" alt="" width="563"><figcaption></figcaption></figure>

### **Option 2: Archive the vendor (move to Inactive)**

1. Select **Archived**.
2. Enter a reason (if prompted).
3. Select **Save**.

#### **What happens next**

* The vendor moves to the **Inactive** stage.
* Employees can no longer edit the request.
* Reviewers can later restore the vendor to:
  * Intake
  * Active

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2FZ98OFlnSZUiy83WRRVSL%2FTemplate%20(2).png?alt=media&#x26;token=c1115cc2-5bc1-486f-b8cc-13adb6f09e2e" alt="" width="563"><figcaption></figcaption></figure>

### **Option 3: Keep the vendor in Intake**

If the reviewer needs more information, they can:

* Edit vendor fields under **Details**
* Request documents
* Add findings or tasks
* Begin due diligence or risk scoring
* Leave the vendor in Intake until ready to decide

<figure><img src="https://3220032727-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FEsyn5VMU6e0OyGjRtKgx%2Fuploads%2F3j5PQR6dirvdaqH2DByC%2FTemplate%20(3).png?alt=media&#x26;token=5b4d1328-47ad-41c9-bb5d-22db1b15b747" alt="" width="563"><figcaption></figcaption></figure>

***

## **Part 4: Change Stage Manually (Any Time)**

Reviewers do not need to use the monitor to change stages. They can:

1. Open a vendor.
2. Select **Update stage** (top-right).
3. Choose **Intake**, **Active**, or **Archived**.

This allows:

* Re-evaluating Active vendors (Active → Intake)
* Restoring Archived vendors
* Archiving Active vendors when offboarded

***

## **Notifications After Decision**

Sprinto sends notifications whenever:

* A vendor request is approved (moved to Active)
* A vendor request is rejected or archived
* A reviewer updates the vendor’s stage

Notifications go to:

* Requestor (employee)
* Internal Business Owner
* Vendor Admin

***

## **FAQs**

#### **Can employees edit a vendor after requesting it?**

Yes. Employees can edit vendor details **only while the vendor is in Intake**.

#### **Can reviewers perform risk scoring and due diligence in Intake?**

Yes. All scoring, tasks, findings, and due diligence actions are available during Intake.

#### **Does due diligence automatically trigger in Intake?**

No. Intake does not run automated monitors for due diligence. These monitors run only after the vendor becomes Active.

#### **What happens to documents uploaded during Intake?**

Documents remain linked to the vendor and become visible in the global documents list only after the vendor moves to Active.
