CLM & Contract Tracking

Every contract, tracked stage by stage, tied to the vendor it belongs to

Once a vendor relationship is underway, this is where the actual contract moves — six stages, five parallel review tracks, and three compliance gates, all visible on one dashboard and tied back to that vendor's record. Negotiation, signatures, and renewals are tracked on the contract itself, not scattered across email threads and spreadsheets.

The dashboard

Every contract, one centralized view

A Kanban board or a sortable table — the Contract Log — your choice, showing every contract at whatever stage it's actually in, right now. Not a status someone updates when they remember to; the real, current state of the whole pipeline, in one place.

Every stat tile on the dashboard is a live filter, not a static number. Click Critical tier, New vendors, or a specific contract type, and the view narrows to exactly that slice — no separate report, no exporting to a spreadsheet to answer a simple question.

Live filters
142
Total
9
Critical tier
14
Due in 30 days
6
High risk
3
Stuck 14+ days
11
New vendors

Click any tile to filter the board to exactly that slice.

Routing pipeline

Six stages that move it forward

Every vendor relationship carries a stage, and every stage change is timestamped — so “where is this?” is always a one-second answer. Eight of them are forward motion — a contract actively moving through review, approval, and on into active management and renewal. “With Vendor” and “Hold” are wait states, not part of that flow — a contract can sit in either from any point and come back. This is the default — an account owner can add, reorder, rename, or remove stages from the workflow builder, no code change required — guided by industry best practices for securing contracts and vendor relationships, not locked in as one-size-fits-all.

A first-time tech platform or data vendor sees Evaluation and Security & Compliance move to the front of this order, ahead of Business & Finance Approval and Legal Review — a renewal keeps the order shown below.

Intake
Evaluation
Security & Compliance
Legal Review
Business & Finance Approval
Signature
Active
Renewal / Close
With Vendor
On Hold
Stage 1
Intake

Capture the business need, use case, scope, vendor, owner, and initial requirements.

Stage 2
Evaluation

Assess solution fit, capabilities, architecture, commercial model, and alternatives.

Stage 3
Security & Compliance

Review security, privacy, data handling, regulatory requirements, and third-party risk.

Stage 4
Legal Review

Review and negotiate contract terms, liability, IP, termination rights, and legal requirements.

Stage 5
Business & Finance Approval

Confirm business sponsorship, budget, financial commitments, and required leadership approvals.

Stage 6
Signature

Route the finalized agreement to authorized signatories and complete execution.

Stage 7
Active

Manage the contract, vendor relationship, usage, spend, performance, and obligations.

Stage 8
Renewal / Close

Review continued need and performance, then renew, renegotiate, replace, or terminate.

Parallel review tracks

Five tracks, tracked independently

A vendor relationship's overall stage tells you where it sits in the pipeline. But Engineering, the Business Owner, Finance, Legal, and Security each move at their own pace — so Granur tracks each one separately, with its own reviewer and status, instead of flattening everything into a single “in review” flag.

Legal gets a deeper status vocabulary than the other tracks — including Send to OC, With OC for Review, and Review OC Feedback — to reflect outside-counsel handoffs without inventing a separate workflow for it.

Engineering
Technology / Engineering, Enterprise Architecture, Partnerships, and Procurement weigh in on solution fit, capabilities, architecture, and vendor commercials.
Business Owner
Business Owner, Technology Leadership, and the Executive Approver sign off on the final business case, scope, and investment.
Finance
Finance / FP&A, Procurement, and the Budget Owner confirm budget availability, TCO, pricing, and payment terms.
Legal
Legal, Procurement, and Partnerships review contract terms, IP, liability, and termination — with a dedicated outside-counsel handoff path.
Security
Information Security, Privacy, Data Governance, and Risk / Compliance review data handling, privacy, and third-party risk — DPA, SOC 2 report, sub-processors, and data residency.
Compliance & diligence

Three gates, before anything moves

New-vendor and uses-AI flags trigger the gates automatically — nothing relies on someone remembering to ask.

Every contract also carries its own automatic risk score — new vendor, missing diligence, high value, urgent — visible at a glance on the dashboard, not something you have to go looking for.

Vendor Risk Assessment

Every new tech platform or data vendor is screened before a contract can move through review.

Privacy / AI diligence

Flagged automatically for any agreement involving personal data or AI usage.

Vendor Request Form

The formal intake record required before procurement and finance engage.

AI-assisted intake

Upload a PDF, not a blank form

Drop in a contract and Claude reads it — pulling out the terms that matter and pre-filling the intake form for you to review and correct, not blindly trust. Nothing saves until you confirm it.

Extracted automatically
Renewal date
Auto-renewal clause
Termination / notice period
Payment terms
Usage commitments
Price escalators
Compliance requirements
AI, used narrowly

Reading contracts is the tedious part — let AI do that part

Intake extraction is one job. Two more run the same way — scoped narrowly, reviewed by a person, never auto-applied without a look.

Risk-clause review, on demand

Run an AI pass over the actual contract text and get back specific, severity-tagged flags — an uncapped liability clause, a silent auto-renewal, one-sided indemnification — each with the exact excerpt it came from, not a generic warning.

Ask your contracts a question

“Which vendors renew in Q1 with an auto-renewal clause?” Ask it directly and get an answer with the specific contracts it's based on — instead of opening ten agreements to check.

Negotiation

Where the deal stands, not just where the document is

“In Legal review” tells you the redline is being worked. It doesn't tell you whether you're close on price, still fighting over liability caps, or waiting on the vendor to counter. Best-practice CLM keeps those as separate questions — so Granur tracks negotiation as its own record on every contract: status, how many rounds it's taken, where the current position sits, what outcome you're targeting, and the next concrete step.

It updates independently of the Legal track, so a deal can be “Final Terms” on negotiation while the redline is still in a review round — an accurate picture instead of one flattened status.

Negotiation
Final Terms
Rounds so far3
Current position
Vendor accepted 12-month term at proposed rate; still negotiating auto-renewal notice window.
Target outcome
60-day notice window, flat pricing through renewal.
Send counter on notice window
Timeline
Renewal due in 12 days
Upcoming
Moved to Legal
History · 4 days ago
Finance status → Approved
History · 9 days ago
Timeline & audit trail

Every date, every change, one chronological view

Key dates — submission, start, end, deadlines, redlines-to-vendor, effective, and renewal — sit alongside a live log of stage moves and review-status changes, split into what's upcoming and what already happened.

Collaboration

Context stays on the record, not in someone's inbox

Why a deal stalled, who flagged a risk, what was decided and why — that's exactly the kind of thing that gets lost in an email thread six months later.

An activity feed, not a status meeting

System events and team posts in one reverse-chronological feed — what changed, who posted about it, and who liked or replied — instead of a recurring sync to cover the same ground out loud.

Comment and @mention, right on the record

Ask a question or loop someone in directly on a contract or a vendor thread — they're notified, and the exchange stays attached to the thing it's actually about.

Notifications ranked by what matters

Renewals, deadlines, mentions, and stuck-in-stage contracts — ranked by severity in one bell icon, instead of an inbox where an urgent flag looks the same as a newsletter.

Beyond the signature

An executed contract still has a job to do

Signing a contract isn't the finish line — the deadline it creates and the spend it represents still need tracking afterward.

Reminders that find you

A personal email or push reminder ahead of any renewal or deadline, on your own lead time, plus a private calendar feed of every deadline and open obligation you can subscribe to from any calendar app.

Spend, sliced every way

Portfolio value, average deal size, and spend broken down by vendor, type, and stage — plus which renewals in the next 90 days carry the most risk, without exporting anything to a spreadsheet first.

Why this pipeline

Built around established CLM best practices

Every stage of contract lifecycle management has a well-established best practice. Here's what's already real in Granur today — and what's next.

Creation & intake

A single intake point with pre-approved templates and clause libraries speeds up drafting and cuts down on human error.

In Granur today

Every contract starts at one intake point — upload a PDF and AI-assisted extraction pre-fills the form for you to review, instead of a blank drafting start. Saved templates carry default fields for a given deal type, and a shared clause library drops standard language straight into a template, so drafting starts from your organization's own precedent, not a blank page.

Negotiation & review

Strict version control plus parallel, AI-assisted review keeps redlining collaborative instead of one slow, sequential handoff — and the commercial negotiation itself gets tracked separately from document review, so a deal's position isn't buried in someone's inbox.

In Granur today

Review tracks — Engineering, Business Owner, Finance, Legal, Security by default — run in parallel, not one after another, and the routing checklist adds a tracked round every time a redline goes back to the vendor. A dedicated Negotiation panel records round count, current position, target outcome, and next step — separate from the Legal track, because where a deal stands commercially isn't the same question as whether the redline is clean.

Approval & execution

Automated approval routing by authority threshold, finished off with a secure e-signature.

In Granur today

The pipeline enforces stage-by-stage routing with an XLT Approval flag for deals that need it, and built-in e-signature closes it out — request a signature from an org member or an outside vendor contact, they sign via a secure link with a typed legal name, the contract auto-advances from Signature to Active the moment every signer is done, and a signer who goes quiet gets an automatic reminder (or a one-click nudge from you).

Storage & management

One secure, searchable, access-controlled repository — not five different folders and inboxes — with the portfolio sliceable by contract type, vendor relationship, and deadline instead of one flat list.

In Granur today

Every agreement lives in a single dashboard, isolated per organization. Every key metric on the dashboard is a live filter — click Critical tier, New vendors, or a specific contract type and the table narrows to exactly those agreements, no separate report needed. Four roles — Owner, Admin, Member, Viewer — control who can change settings, manage the team, or just look; a Viewer is enforced as read-only everywhere, not just hidden in the interface. Every document version is kept, too, with a word-level diff between any two, so there's no guessing which redline is current.

Post-execution & analysis

Automated renewal and milestone alerts, plus cycle-time tracking, to drive continuous improvement.

In Granur today

The Timeline and Contract Log surface every upcoming renewal automatically, and cycle time — days spent in each stage — is tracked on every contract, so slow stages are visible, not anecdotal.

Runs itself

The pipeline moves things forward without being asked

A tracker only helps if someone remembers to check it. Granur also pushes.

Automation rules

When a contract enters a stage, or a checklist finishes, a rule can notify Slack or move the contract forward on its own — no one has to remember to trigger it.

Slack, Teams & webhooks

A daily digest or an on-demand push to Slack or Teams, and outbound webhooks for your own systems — a contract created, a stage changed, a signature completed — signed and delivered automatically.

A read API of your own

A dedicated API key gives another internal tool read access to your contract data — no export, no copy-paste, no waiting on someone to pull a report.

Every contract here is tied to a vendor relationship. See the vendor directory, evaluation scorecards, and health tracking

Security & data

Your contract data, isolated and accounted for

Granur is early — we're straightforward about what's built today rather than borrowing badges we haven't earned.

Org-scoped multi-tenancy

Every contract, user, and event is scoped to your organization — no cross-tenant access.

Hashed credentials, session auth

Passwords are hashed, never stored in plain text; sessions are signed and short-lived.

Full, exportable audit trail

Every stage move, approval, and settings change is logged automatically — visible on the Timeline, and exportable as a CSV or PDF for a security reviewer.

You control the data

Your contract data lives in your own database — Granur doesn't share it across organizations.

See your own contracts on the pipeline

Pick a plan, upload a handful of agreements, and watch the routing map fill in.