Organization Contacts
Before configuring notification routing, designate your organization’s primary contacts: Support Contact — the primary contact vendors see during interactive assessments. This person’s name and email appear in assessment communications sent to vendors. Setting a clear support contact improves vendor trust and streamlines communication. Incident Response Contact (optional) — a designated recipient for all risk advisory notifications across your entire vendor portfolio. Ideal for a centralized security operations or compliance team that needs to triage every advisory regardless of which business owner owns the relationship.Notification Routing
Disable Business Owner Notifications
By default, Business Owners receive notifications about the relationships they own — assessment updates, risk advisory alerts, lifecycle reminders, and more. You can disable all Business Owner notifications globally. Use this when another team is centrally managing all communication, or when you’re triaging notifications through a shared inbox before routing them.Override Internal Email Recipients
Consolidate all internal notifications into a single email address — useful for ticketing systems, shared inboxes, or security operations centers that triage alerts before routing them to the appropriate person.The override applies only to internal notifications. Vendor-facing emails (collection requests, reminders, submission confirmations) are never redirected by this setting.
Notification Types
The notification settings matrix groups notifications into categories. Each notification can be toggled on or off per recipient. Depending on the category, recipients include the Business owner, Assessment lead, Subscribers, the creator of the item, and the vendor’s third party contact. Some notifications — particularly those sent directly to vendors — cannot be disabled.Assessments
- Assessment started
- Assessment submitted
- Assessment completed
- Assessment cancelled
- Assessment forwarded
- Assessment expired
- Assessment expiration extended
- Assessment reminder
- Invalid assessment recipient email
Remediation
- Remediation requested
- Remediation reminder
- Remediation artifacts provided
- Remediation declined
- Remediation forwarded
- Remediation target date missed
Monitoring & Risk Alerts
- Risk advisory
Lifecycle & Recertification
- Relationship onboarded
- Upcoming recertification
Relationship Management
- Relationships imported
Mentions
Users tagged in comments on a relationship or assessment receive a notification — regardless of their role or subscription status on that relationship.Previewing Notification Content
To see exactly what a notification looks like before it goes out, select any notification type in the Settings matrix. A preview shows the email subject and body, including how placeholder data (vendor name, relationship name, etc.) is populated. Use this to validate that your support contact name appears correctly and that the communication tone matches your organization’s expectations.Per-Relationship Notification Settings
In addition to org-wide settings, individual relationships have their own notification configuration. Open the relationship’s Relationship configuration dialog (gear icon) and use the Contacts section to:- Enable or disable notifications for the Business Owner on that specific relationship
- Add or remove Subscribers who receive updates for that relationship