Answers to the questions we hear most often about Vendor Pulse, Zeron's third-party risk management (TPRM) product.
What is Vendor Pulse? Zeron's TPRM product. You keep a vendor register, send questionnaire assessments and risk evaluations to those vendors, review what comes back, and track the risks that result.
What sections does it have? The sidebar carries Dashboard, Vendors, Master Data, ZIN Advisor, Documents, Reports, and Admin (with Management and Settings under it).
What permissions do I need? Access is controlled by permission scopes rather than fixed job titles. Each section checks its own scope — for example vendor:view for Vendors and master:view for Master Data — and shows an "Unauthorized" screen if you lack it. See *Vendor Pulse: Roles & Permissions Reference* for the full list.
How do I add a vendor quickly? Go to Vendors and click Single Add. Start typing the company name — after 3 characters Vendor Pulse searches an external company profile database and fills in the details when you pick a match. Company Name and Company Domain are both required to continue.
On on-premise deployments there are no suggestions; you type the name and domain yourself.
Can I load many vendors at once? Yes. Vendors → Bulk Upload, then Download Template, fill in the Vendors sheet and upload it. .xlsx and .xls, up to 15 MB.
How do I classify vendors? With a Category and Subcategory on the vendor form. You define these under Master Data → Product & Service Categories. Both fields are optional.
Why does a vendor's profile say "Not provided"? That is what empty enrichment fields show — revenue, employee count, location and risk manager — instead of a blank or a zero.
What is Master Data? Your library of reusable questionnaire Templates, plus your Product & Service Categories. You build a template once and use it for many vendors.
What are the assessment states? Three, shown by the status filter on a vendor's Assessment Process tab:
| State | Meaning |
|---|---|
| Upcoming assessment | Scheduled for a future date and not yet sent. The vendor cannot see it |
| Ongoing assessment | Sent to the vendor and not yet closed out |
| Completed assessment | Finished and scored |
What do the columns on an assessment row mean? An ongoing assessment shows Assessment Name, Completion Progress, Pending Questions, Scheduled Date, Days Left, Sent By, Review Progress and Compliance Percentage. Once a due date has passed, Days Left shows a red Overdue chip with the number of days.
Can vendors respond directly? Yes, through the vendor assessment portal. They sign in with a one-time code sent to their email — there is no password. Vendors have their own roles in that portal: Admin, Collaborator and Viewer.
Can I change an assessment after it has been sent? Only its Assessment Due Date. The template, scheduled date, scheduling interval and submission deadline are fixed when the assessment is created.
How does re-assessment scheduling work? When you create an assessment you can set an Assessment Scheduling Interval. Once that assessment is sent, the next one in the sequence is scheduled automatically for the same interval later. Leave the interval at never for a one-off assessment.
Can I send a reminder? Yes — the row's ⋮ menu has Send Reminder under the Ongoing assessment and Completed assessment filters. It is refused once the due date has passed.
What is a risk evaluation? A way to send specific identified risks — rather than a questionnaire — to a vendor and ask them to describe how they will handle each one and attach evidence. You start it on a vendor's Manage Risk tab: mark risks with Mark Evaluation, then use Risk Evaluation Actions → Send Evaluation.
Where do risks come from? Each risk carries a Risk Source: DRM, Assessment or Manual.
What lifecycle does a risk follow? Four stages: Risk Initiation, Risk Scoring & Prioritisation, Risk Management and Risk Closure.
Can I edit a comment I posted? Yes. Hover your own comment and use Edit. It becomes a text box with Cancel and Save, and afterwards carries an italic *(edited)* marker whose tooltip shows the edit date.
Are there limits? Two. You can only edit your own comments — org users and vendor-portal members can never edit each other's — and only within 15 minutes of posting. After that, reply instead.
If I mention someone twice in one comment, do they get two notifications? No, one.
What is the AI Questionnaire Assistant? It suggests answers drawn from your ZIN Knowledge Base so you are not retyping the same answers. There is also a Chrome extension — offered as Add to Chrome from the Knowledge Base tab — for filling in questionnaires hosted in other companies' portals.
What is Vendor Analysis? An AI-generated view of a vendor, on the vendor's Vendor Analysis tab. It covers Financial Stability, Business Continuity, Incident History, Key Strengths, Key Risks, Market Position, Security Posture and Recommendations. The page carries its own note asking you to verify the content independently before acting on it. It is not available on on-premise deployments.
What is the ZIN Advisor section? The section holding your AI content: three tabs, Checklist, Knowledge Base and Questionnaire.
Why can I not see the ZIN Advisor chat or the AI search bar? They appear only when the ZIN AI service is reachable from your deployment. When it is not, the entry is hidden and the chat page returns you to the dashboard. This is not a permission setting.
What is the Digital Risk tab? A view of a vendor's external, internet-facing risk.
Why is it Unauthorized? Three conditions must all hold: you have vendor:digital:view, the vendor has a primary domain recorded, and you are not on an on-premise deployment.
Why do I see "Unauthorized" on a page? Your group is missing that page's scope. An administrator can adjust it under Admin → Management. The *Roles & Permissions Reference* lists which scope each area needs.
Why does a button appear but the action fail? Some controls are shown on one scope while the save is checked against another — Product & Service Categories are the main example, where the buttons follow master:* but saving follows vendor:*. Ask your administrator to grant both.
Symptom: No suggestions appear when typing a vendor name → Type at least 3 characters. On on-premise deployments there are no suggestions at all.
Symptom: A section shows "Unauthorized" → You are missing that section's scope. See the Roles & Permissions Reference and ask your administrator.
Symptom: The vendor did not get the assessment → Check the SPOC email on the vendor's profile, then resend with Send Reminder and ask them to check spam.
Symptom: A vendor contact can read but not answer → They hold the Viewer role in the vendor portal. Their portal Admin can promote them.
Symptom: The Edit action on my comment has gone → The 15-minute edit window has passed. Add a reply instead.
Need more help? Contact support@zeron.one