How to Collaborate on Assessments

How to Collaborate on Assessments

Overview

An assessment involves two groups of people: your own reviewers inside Vendor Pulse, and the vendor's own staff working in the vendor portal. This guide explains how each side collaborates, where comments live, and how to see who on the vendor side has access.

The two collaboration surfaces are different, so it is worth being clear about them up front:

WhereWho uses itWhat they can do
Team tab on a vendorYour organisationView the vendor's own portal members (read-only list)
Assessment Process tab → assessment reviewYour organisationComment on individual answers, tagging colleagues
Vendor portalThe vendor's staffAnswer questions, upload evidence, comment, invite their own colleagues

Prerequisites

  • A vendor record with at least one assessment
  • Permission to view vendors (vendor:view)
  • Permission to view and review assessments (vendor:assessment:view, vendor:assessment:review) to work inside the review screen

Seeing Who Is Working on the Vendor's Side

Navigation: Sidebar → Vendors → [select a vendor] → Team

The Team tab is a read-only view of the people the vendor has added to their own portal. You cannot add or remove members from here — that is done by the vendor's own admin inside the vendor portal.

The table shows:

ColumnMeaning
NameThe member's name, or their email if no name was given
EmailThe address their one-time password is sent to
RoleAdmin, Collaborator or Viewer
StatusInvited, Active or Deactivated
JoinedWhen they first signed in
Last ActiveWhen they were last seen in the portal

Use the search box above the table to find a member by name or email.

What the vendor-side roles mean

  • Admin — can answer questions, invite and remove collaborators, change their roles, and submit the assessment.
  • Collaborator — can contribute answers, evidence and comments, but cannot manage team access.
  • Viewer — read-only access to the assessment.

The vendor's main contact (SPOC) is the first Admin. Their role cannot be changed, and the vendor cannot demote their last remaining Admin.

Submitting is Admin-only, and the button is hidden from everyone else. A Collaborator or Viewer does not see a disabled Submit Answers button or an explanatory message — the control simply is not there. Because every invited colleague is a Collaborator unless the Admin says otherwise, a vendor can answer an entire questionnaire and still have no way to submit it. Expect this to come up as "our vendor has no submit option".


Commenting on Assessment Answers

Navigation: Sidebar → Vendors → [select a vendor] → Assessment Process → open an assessment for review

Comments in Vendor Pulse are attached to specific things — an individual assessment answer, or a risk — rather than to the vendor as a whole. There is no separate "Comments" tab on the vendor page.

When you open a question in the assessment review screen, you will see:

  • The Previous Comment — the most recent comment on that answer
  • A Read All link, which opens a Comments panel from the right-hand side of the screen
  • An Add Comment box at the bottom of the question

Adding a comment

  1. Type your comment in the Add Comment box. Basic formatting is supported.
  2. Choose the comment's visibility from the dropdown next to the button:
  • External — the vendor is notified about the comment.
  • Internal — kept between your own team; no vendor notification is sent.
  1. Click Add Comment.

A comment can be up to 500 words. The running word count is shown under the box.

Mentioning a colleague

Type @ in the comment box to open the tagging list, then pick a User from your organisation. The person you tag is notified. If you name the same person more than once in a single comment, they receive only one notification.

Editing your own comment

  1. Hover over a comment you wrote.
  2. Click the Edit (pencil) icon that appears in the top-right corner of the comment.
  3. The comment turns into a text box. Change the text and click Save, or Close to abandon the change.

Editing is restricted:

  • You can only edit comments you wrote. You cannot edit anyone else's, and vendor-side members cannot edit your comments.
  • You can only edit within a short window after posting (15 minutes by default). After that the Edit icon disappears and the change is rejected — post a follow-up comment instead.

An edited comment carries an italic (edited) marker. Hovering that marker shows Edited on with the date.

Deleting your own comment

Hover a comment you wrote and click the Delete (bin) icon. A confirmation appears before the comment is removed. The Delete icon only appears on your own comments.

Searching comments

The Comments panel has a search box at the top. It searches the text of the comments on that item.


Commenting on Risks

Navigation: Sidebar → Vendors → [select a vendor] → Manage Risk → open a risk

Risks have their own comment thread, which behaves exactly the same as comments on assessment answers — same Internal/External choice, same 500-word limit, same @mention behaviour, same author-only edit rule.


How the Vendor Collaborates on Their Side

When you send an assessment, the vendor's SPOC receives an emailed link to the vendor portal. Inside the portal they see a Team Access card at the top of the questionnaire, which tells them what their own role allows.

A vendor Admin can:

  1. Click Add Collaborator in the portal header.
  2. Enter the colleague's Name and Email, and choose a Collaborator role (Admin, Collaborator or Viewer).
  3. Click Send Invitation.

The invited person receives their own emailed link and signs in with their own one-time password. The portal warns the Admin that anyone they add will be able to answer questions, upload evidence and add comments on the assessment.

A vendor Admin can also click the avatars in the Team Access card to open the Team Members dialog, where they can change a member's role, Remove a member, or Send Invite again to someone previously removed.

Collaborators only ever see the assessment they were invited to. They have no access to anything else in your Vendor Pulse tenant.


Where Documents Live

Navigation: Sidebar → Documents, or Vendors → [select a vendor] → Documents

Evidence uploaded by the vendor against assessment questions, and private documents your own reviewers attach, are collected on the vendor's Documents tab. The table shows:

ColumnMeaning
DocumentsThe file name
Document TypeVendor Document or Private Document
Assessment NameThe assessment, template, category and question it came from
Approval StatusWhether your reviewer has approved or rejected the evidence
Risk TitleThe risk it is attached to, where applicable
Uploaded DateWhen it arrived

Use the row menu → View to preview a file, or the Export button to export documents in bulk. Documents are not uploaded from this tab — vendor evidence arrives through the vendor portal, and your own reviewers attach private documents from within the assessment review screen.

Private Documents are internal only. As the upload dialog states, they are stored against the question or risk for your reference and are never shared with or visible to the vendor.

The Documents entry in the sidebar gives you the same kind of view across every vendor.


Troubleshooting

A colleague cannot see the vendor at all → Vendor Pulse access is controlled by your organisation's roles and permissions, not by the vendor's Team tab. Ask your administrator to grant them the vendor view permission (vendor:view).

I want to add someone to the Team tab but there is no button → The Team tab is a read-only view of the vendor's own portal members. Only a vendor Admin can invite people, and they do it from Add Collaborator inside the vendor portal.

The Edit icon has disappeared from my comment → You can only edit your own comment within the edit window after posting (15 minutes by default). Once it has passed, post a follow-up comment instead of editing. There is no reply-to-comment action; comments form a single flat thread.

I cannot edit a colleague's comment → This is intentional. Only the author may edit a comment.

The vendor says they never received the assessment link → Check the SPOC email on the vendor's profile is correct and ask them to check spam. You can resend from the assessment row's Send Reminder action.

The vendor says they cannot see a Submit option → They are signed in as a Collaborator or Viewer, not as the Admin. Only the vendor's SPOC can submit. Ask the SPOC to sign in and submit, ask the vendor's Admin to promote that person in the Team Members dialog, or change the SPOC email on the vendor profile to their address. The assessment stays Ongoing until someone with the Admin role submits it.

My comment was rejected as too long → Comments are limited to 500 words. The word counter under the box shows where you are.

The vendor did not get notified about my comment → Check the visibility dropdown. Internal comments deliberately produce no vendor notification; use External if you want the vendor to know.


Need more help? Contact support@zeron.one

    • Related Articles

    • How to Send Risk Assessments to Vendors

      Overview Separately from questionnaire assessments, Vendor Pulse lets you send specific identified risks to a vendor and ask them to respond. The vendor logs in to a portal, describes how they will handle each risk, uploads supporting evidence, and ...
    • Understanding the Vendor Dashboard

      Overview The Vendor Pulse dashboard is your portfolio-level view: how many vendors you have, how their assessments are progressing, where your risk is concentrated, and which vendors need attention first. It is made up of four summary cards across ...
    • How to Review Vendor Risk Scores

      Overview Vendor Pulse shows vendor risk in three places, each answering a different question: Where Question it answers Profile tab on a vendor How risky is this vendor overall? Manage Risk tab on a vendor What specific risks are open, and who is ...
    • Troubleshooting Common Issues in Vendor Pulse

      Overview Most "I can't see this" or "this won't save" problems in Vendor Pulse come down to one of three things: a missing permission scope, a field that has not been filled in on the vendor, or a file that does not match its template. This guide ...
    • How to Generate Vendor Risk Reports

      Overview Vendor Pulse produces two kinds of report, and both are generated per vendor: Report Format How it is produced Executive PDF You add a remark and optional recipients, then generate Detailed Excel workbook Generated immediately, no extra ...