Vendor Management

Every vendor relationship, tracked from first look to offboarding

Deciding whether a new technology vendor is worth onboarding, and keeping the ones you already work with on track, are two different jobs — Granur treats them that way. A weighted evaluation and mandatory gates keep a first-timer honest; health scorecards, obligations, certifications, and a portfolio view by spend and risk keep the rest of your vendor base accounted for — every vendor in one searchable directory, not a spreadsheet someone updates when they remember to.

Vendor directory

Every vendor you work with, in one list

Not a folder of contracts — the vendor itself, as its own record. Every relationship your org has is searchable and filterable by capability, segment, and health, with every contract tied to that vendor rolled up underneath it.

Click into any vendor and see its full history in one place — every contract, every health check, every certification — instead of piecing it together from separate records.

Vendor directory
Northwind Analytics
Data warehousing
Healthy
Solstice Cloud
Tech & Cloud
Watch
Ledgerline HR
HR
Healthy
Vantage Media
Adtech & Adserving
At risk
New-vendor evaluation

A scorecard before you commit to a first-timer

A brand-new vendor and a routine renewal are not the same risk. Granur treats them differently by design — a first-time vendor gets a weighted evaluation across eight dimensions (strategic fit, capability, architecture, data, security, performance, commercial, and vendor model), plus mandatory pass/fail gates and a strategic-risk read on ecosystem fit and exit cost, the moment it's flagged "new" at intake; a renewal doesn't, because that relationship has already been vetted.

New vendor path

Evaluation scorecard, Vendor Risk Assessment, and privacy / AI diligence all apply — the relationship is unproven, so the gates run in full.

Existing vendor (renewal) path

No evaluation scorecard and no re-run of diligence already on file. The focus shifts to negotiation — terms, pricing, and renewal timing.

Vendor evaluation
Recommend with Conditions

Weighted rubric for onboarding a new vendor — separate from the VRA / compliance gates.

Mandatory gates — 4/4 required passed
84/100
Strategic Fit (15%)4/5 — evidence: PoC validated
Security & Compliance (15%)4/5 — evidence: PoC validated
Commercial & TCO (10%)3/5 — evidence: PoC validated
References checked, strong capability match. Pricing is slightly above comparable vendors — condition approval on a 6-month rate lock.
Vendor segmentation

A portfolio view, not one vendor at a time

Every vendor placed by spend against risk on a single map — so the ones worth prioritizing surface on their own, instead of waiting to be found in a one-vendor-at-a-time lookup. Spend uses the same normalization as the Spend page; risk reuses each vendor's highest per-contract risk score from the risk badge.

Vendors land in one of four quadrants — strategic, bottleneck, leverage, or routine — so a portfolio review starts with "who needs attention" instead of a spreadsheet of every vendor in alphabetical order.

Spend vs. risk
Spend →Risk →
Vendor health & lifecycle

The relationship doesn't end at signature

A segmentation map tells you where to look. These are what you're actually looking at once you get there.

Health scorecards

A weighted KPI rubric — quality, delivery, cost, service, innovation, communication — run periodically per vendor, with an auto-suggested health rating and an action-item list, so "how's this vendor doing" has an actual record behind it.

Obligations, not just renewals

The actual deliverables a vendor relationship promises — a report due quarterly, a right to audit, a volume commitment — tracked against an owner and a due date, separately from when any one contract with that vendor expires.

Certifications & insurance

COI, SOC 2, ISO 27001, W-9, and anything else a vendor needs on file — tracked with expiry dates and an automatic amber-then-red warning as a certification approaches or passes expiration.

Offboarding, checked off

A five-step checklist — access revoked, data returned, final invoice, knowledge transfer, contracts closed — so winding down a vendor relationship is a record, not a memory.

Vendor management is half the picture. See the dashboard where every contract is tracked, stage by stage

Security & data

Your vendor data, isolated and accounted for

Granur is early — we're straightforward about what's built today rather than borrowing badges we haven't earned.

Org-scoped multi-tenancy

Every contract, user, and event is scoped to your organization — no cross-tenant access.

Hashed credentials, session auth

Passwords are hashed, never stored in plain text; sessions are signed and short-lived.

Full, exportable audit trail

Every stage move, approval, and settings change is logged automatically — visible on the Timeline, and exportable as a CSV or PDF for a security reviewer.

You control the data

Your vendor data lives in your own database — Granur doesn't share it across organizations.

See your own vendors on the pipeline

Pick a plan, upload a handful of agreements, and watch the evaluation scorecard and health tracking fill in.