> ## Documentation Index
> Fetch the complete documentation index at: https://docs.visotrust.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Troubleshooting & FAQ

> Troubleshooting steps and frequently asked questions about login, assessments, artifact uploads, notifications, and other common VISO TRUST issues.

## Getting Started

**I didn't receive my account setup email. What do I do?**
Check your spam folder first. If it's not there, contact your Customer Success Manager or email [support@visotrust.com](mailto:support@visotrust.com). If your organization uses SSO, confirm with your Org Admin that you've been assigned access in your identity provider.

**I can't log in with Google or Microsoft.**
If your organization has SSO configured, your first login must go through your SAML identity provider — navigate to [app.visotrust.com](https://app.visotrust.com), enter your email, and follow the redirect to your IdP. Social logins (Google, Microsoft) work for subsequent logins after your first successful SSO session.

**I can see the platform but can't take any actions.**
You likely have **Viewer** access. Viewers can view relationships, assessments, and risk data but cannot create or edit. Contact your Admin to request a role change if you need edit access.

***

## Relationships and Vendors

**How do I add a vendor that isn't in the VISO TRUST directory?**
When adding a relationship, search for the vendor name. If it doesn't appear, select **Create new third-party organization** at the bottom of the results. Enter the vendor's name and website URL — providing a URL is important for public research and instant assessment accuracy.

**Why is my vendor's risk score different from what I expected?**
Risk scores are driven by the combination of data types and business cases configured for the relationship. Check the relationship's Context settings to make sure the selections accurately reflect how you use this vendor. Also review what artifacts have been collected — a vendor with no analyzed documentation will have a higher residual risk than one with a validated SOC 2.

**What does "Pending Changes" mean on a relationship?**
It means new information exists that hasn't been incorporated into the current assessment summary yet — expired artifacts, a context update, newly discovered public artifacts, or new risk advisories. Run a public search or initiate an assessment update to resolve it.

**Can I have multiple relationships with the same vendor?**
Yes. Use the Products & Services scoping feature to create separate relationships for different products or services from the same vendor. Each relationship has its own assessment context and risk score.

***

## Assessments

**How do I start an assessment?**
There are three ways:

1. **Instant Assessment** — runs automatically when you create a relationship (if enabled)
2. **Upload artifacts** — go to the relationship, select **Add information**, and upload documents directly
3. **Collection request** — go to the relationship, select **Start assessment**, and send a request to the vendor

**The vendor says they didn't receive the collection request email. What should I do?**
Ask the vendor to check their spam folder — assessment emails sometimes get filtered. If it's not there, go to the relationship's Assessments tab, open the active assessment, and use **Send Reminder** to resend. You can also update the vendor contact and resend from the relationship settings.

**Can I upload documents on behalf of a vendor?**
Yes. Upload artifacts directly on the relationship — they'll be treated as **Collected from Client** rather than from the vendor. This is the right approach when you have documents on hand and don't need vendor involvement.

**An assessment has been in "Review Started" for a long time. Is that normal?**
The AI review typically completes within minutes. If AI Assessment + Auditor Review is configured, the auditor review may take longer (typically 1–2 business days). If it's been more than 48 hours without movement, contact [support@visotrust.com](mailto:support@visotrust.com).

**Can I cancel an active assessment?**
Yes — open the assessment and select **Close Request**. The assessment will be cancelled. Any artifacts already submitted or uploaded will be retained on the relationship.

**What happens when an assessment expires without a vendor response?**
Depending on your configuration, VISO TRUST either notifies the business owner and assessment creator, or automatically closes the collection request. You can configure this behavior in assessment defaults.

***

## Risk Scores

**Why did a vendor's risk score change without a new assessment?**
Several things can trigger score changes without a full assessment: artifacts expiring (reducing assurance on credited controls), context updates (adding or removing business cases or data types), or new risk advisories being detected. Check the relationship's Activity tab for a log of what changed.

**Can I override a vendor's risk score?**
Yes. When an assessment is in **Review Risk** status, select **Override Risk** to manually set a different inherent or residual value. Document your reasoning — overrides are recorded in the audit trail. Overrides remain in effect until the next assessment update.

**What's the difference between inherent and residual risk?**
Inherent risk is the starting point — potential exposure based on your relationship context, before accounting for vendor security controls. Residual risk is what remains after crediting the vendor's proven controls. Act on residual risk; use inherent risk to understand worst-case exposure.

***

## Artifacts and Documents

**Why was my artifact classified incorrectly?**
Classification is automatic but not perfect. If an artifact is misclassified, you can correct it from the Artifacts tab — select the artifact and update the Type field. Users assigned to the relationship and Org Admins can make this correction.

**Can I upload a password-protected document?**
Password-protected artifacts require manual handling. When you upload one, note in the comments that it's password-protected and provide the password through a secure channel to [support@visotrust.com](mailto:support@visotrust.com) so auditors can access it.

**Why does a vendor's SOC 2 only give partial credit?**
If VISO TRUST detected a SOC 2 badge on the vendor's website but hasn't reviewed the actual report, it grants partial credit (lower assurance). To get full credit, request the actual SOC 2 report through a collection request so it can be analyzed.

**Can I delete an artifact a vendor submitted?**
Delete permissions depend on your role — some roles can remove any artifact, while others can only remove artifacts their own team uploaded. Vendor-submitted artifacts are otherwise retained as part of the audit trail.

***

## Notifications and Access

**Business owners are getting too many emails. How do I reduce them?**
Go to **Settings → Org Profile → Notifications** and adjust the notification matrix — toggle off notification types that aren't useful. You can also **Override All Internal Email Recipients** to consolidate all internal notifications to a single inbox, or **Disable All Business Owner Notifications** entirely and route alerts through a central team.

**A user can't see a relationship they should have access to.**
Check the user's role. Contributors see all relationships in the organization by default, but some filtered views may hide relationships they're not subscribed to or don't own. If the relationship still isn't visible, check whether it's archived.

**I need to give a vendor access to submit documentation outside of a collection request.**
All vendor document submission happens through the collection portal, which is accessed via a collection request. There is no way to give a vendor ongoing platform access — each submission is through a specific, time-limited collection link.

***

## Getting Help

For issues not covered here:

* **Email:** [support@visotrust.com](mailto:support@visotrust.com)
* **In-platform:** Use the help button to contact support
* **Your Customer Success Manager:** For account-specific questions and configuration guidance
