Vendor Intake gives you one self-service form that anyone, from a vendor to someone on your own team, can fill out to bring a new vendor into Titan Assess. Instead of manually adding a vendor’s details and chasing a security questionnaire over email, you publish a single form once, and every submission lands in one place for you to review. Requests can come in three ways: a vendor or teammate submits the public form, a request comes in automatically through an integration, or you add a request yourself directly in the application.
Use Vendor Intake when you want a repeatable way to collect vendor information and risk-relevant answers up front, before adding a vendor to your directory. It’s useful when a business team wants to bring on a new vendor and needs your team’s sign-off, or when you’d rather have vendors register themselves through a public link than create each one by hand.
Not sure this is what you need? Vendor Intake is a questionnaire-based process that requires review and approval before a vendor is added. If you already trust the vendor and just want to add them to your directory without a form or approval step, use Adding a vendor directly instead.
Setting up your intake form
Each organization has one intake form. You build it once under My Network > Vendor Intake, on the Form builder tab.
- Add the questions you want vendors to answer. Common examples include what type of data will be shared with the vendor, their impact on your business, contact information, and whether they encrypt data. Choose a response type for each question: multiple choice, single choice, paragraph, attachment, date, email, number, or switch.
- Mark which questions are required.
- Optionally flag a question as affecting risk, and set its scoring.
- Optionally map a question to a standard vendor field: external vendor contact email, coworker contact email, data types shared, business impact, risk level, contract end date, contract value, access types, vendor ID, or last assessed date. Mapped answers carry over automatically when you approve a submission.
A What company do you want to add? question is always included and can’t be edited or removed; it’s how every intake identifies the vendor. Because this question always handles company identity, it isn’t a field you map yourself.
Once a form is published, editing its questions won’t change any request that’s already been submitted; each submission is evaluated against the version of the form that was live when it came in. Edits take effect for new submissions going forward.
You can also set up rules that automatically assign a risk level to each vendor based on their intake answers. See Set risk level rules for vendor intake for how to build and test these rules.
Adding a request yourself
If you already know a vendor’s details, you can log the request yourself instead of waiting for them to fill out the public form.
- From the Requests tab, select Add request.
- Optionally paste notes or upload supporting files; Titan Assess will suggest answers to your intake questions based on what you provide. Suggested answers are a starting point, not a guarantee: review them before saving, since some questions may come back unanswered if the notes or files don’t cover them.
- Search for and select the vendor’s company.
- Answer the remaining questions.
- Select Add request to save it.
This creates the request with a status of Submitted, the same as if the vendor had filled it out themselves.
Sharing the public intake link
Once your form is published, copy its link from the Vendor Intake header and share it with vendors, or with anyone at your company who works with vendors directly. Anyone with the link can submit a request, as long as their email matches your access allowlist.
What vendors see when they open the link
- They enter their email address and select Send email. If their email or domain isn’t on your allowlist, they can’t continue.
- They’re asked to check their inbox for a confirmation email, which they can request again if it doesn’t arrive.
- Selecting the link in that email opens the intake form. This link can only be used once and signs them in for 24 hours.
- They search for and confirm their company, then answer the questions, including uploading any files an attachment question asks for.
- Submitting shows them a simple confirmation screen. They won’t see whether or when you approve or reject their submission.
Reviewing, approving, and rejecting submissions
Every submission, whether it arrived through the form, an integration, or you added it yourself, appears under the Requests tab with a status of Submitted. Select a request to open it and review its answers, including the risk level generated by your risk level rules.
From there, you can:
- Select Edit answers to correct or update any response before deciding.
- Select Complete Intake to approve it. This shows the vendor properties pulled from mapped answers, such as contact info and risk level, which you can adjust before confirming, along with a toggle to put the vendor under continuous monitoring (this uses a vendor slot). You can also add an optional note about the completion before confirming.
- Select Reject if the vendor shouldn’t move forward. You’ll need to add a note explaining why before you can submit the rejection. This marks the request as Rejected and does not add or update anything in your vendor directory.
Approving adds the vendor to your directory (or, if that company already exists there, updates its existing record) and marks the request as Approved.