How can we help?

Browse topics to learn how Docubark works, or search for what you need.

Account & Access

Creating your account

Sign up for Docubark with your email in about a minute.

You can create a Docubark account with your work email and a password, or with your Google or Microsoft account. This walks through email sign-up.

Sign up with email

  1. Go to the sign-up page.
  2. Enter your work email, full name, and a password of at least 8 characters, then confirm the password.
  3. Click "Create account".
  4. Docubark emails you a 6-digit code β€” enter it on the verification screen to activate your account (see Verifying your email).

Prefer single sign-on?

You can skip the password entirely and sign up with Google or Microsoft instead β€” see Signing in with Google or Microsoft.

Verifying your email

Confirm your email address with the 6-digit code.

After you sign up with email, Docubark sends a 6-digit confirmation code to make sure the address is really yours.

Enter your code

  1. Open the email from Docubark and copy the 6-digit code.
  2. On the "Verify account" screen, enter your email and the code.
  3. Click "Verify". Once verified, you'll be taken to sign in β€” or straight into the app if you're already signed in.
Tip: Didn't get the email? Check your spam or junk folder β€” corporate Microsoft/Outlook filters sometimes delay it a few minutes. If it still hasn't arrived, contact support.

Signing in

Log in to Docubark once your account is set up.

Once your account is active, sign in from the Docubark login page to reach your dashboard.

Sign in with email and password

  1. Go to the sign-in page, or click "Log in" from docubark.com.
  2. Enter your email and password and submit.
  3. If prompted, enter the one-time code Docubark emails you to complete sign-in.
  4. You'll land on your Vendors dashboard.
Tip: Forgot your password? See Resetting your password. Prefer not to use a password at all? See Signing in with Google or Microsoft.

Signing in with Google or Microsoft

Use single sign-on instead of a password.

Prefer not to manage another password? You can sign up and sign in with your Google or Microsoft account. It works from both the sign-up and sign-in pages.

Use single sign-on

  1. On the sign-up or sign-in page, click "Google" or "Microsoft".
  2. Choose your account and approve the permission prompt.
  3. You'll be signed straight into Docubark β€” no separate password or email verification step needed.
Tip: If your company already uses Google Workspace or Microsoft 365, this is usually the fastest and most secure way in.

Resetting your password

Recover access if you forget your password.

Forgot your password? You can reset it yourself from the login page β€” no need to contact support.

Reset your password

  1. On the sign-in page, click "Forgot password".
  2. Enter your email and submit. Docubark emails you a 6-digit reset code.
  3. On the reset screen, enter the code, a new password of at least 8 characters, and confirm it.
  4. You'll be signed in automatically with your new password.
Tip: If you originally signed up with Google or Microsoft, use that provider's "Sign in" button instead (see Signing in with Google or Microsoft) β€” there's no Docubark password to reset.

Creating Assessments / Questionnaires

Creating controls

Add the controls and questions your assessments are built from β€” manually or by import.

Controls are the building blocks of an assessment β€” each one holds the questions you evaluate a vendor against. You can add them one at a time or import them in bulk from a spreadsheet.

Add a control manually

  1. Go to Controls under Assessments.
  2. Click "Add Control", enter a control name, and confirm to create it.
  3. Open the new control and add your questions, answer options, and scores.

Import controls from a spreadsheet

  1. On the Controls page, click "Import".
  2. Download the template and fill in your controls and questions.
  3. Drag in your Excel file β€” .xlsx, .xls, or .xlsm, up to 10MB β€” and upload.
Tip: Importing is the fastest way to bring in an existing control set. Keep the columns in the template's format so Docubark can read the file β€” see Importing controls from the template.

Importing controls from the template

How to fill out the downloadable Excel template β€” with examples.

You can bulk-create controls by filling out Docubark's Excel template. Here's exactly how it works, with examples.

Get the template

  1. Go to Controls under Assessments and click "Import".
  2. Click "Download Template" to get the Excel file, then fill it in.

How the template is laid out

The template is turned on its side: the field labels run down column A, and each control goes in its own column β€” B, C, D, and so on. So one column = one control. Fill column B for your first control, column C for the next, and so on.

Row (in column A)What to put in the control's column
Control NameRequired. The control's name. A column with no name is skipped.
Rubric Title / Max Points / Rubric ContentFill these only for rubric scoring (see below). Leave blank for point-per-question scoring.
Min / Max Effective ValueScore range for the Effective (green) band. Optional β€” defaults to 75–100.
Min / Max Needs Improvement ValueThe Needs improvement (yellow) band. Optional β€” defaults to 40–74.
Min / Max Ineffective ValueThe Ineffective (red) band. Optional β€” defaults to 0–39.
Question 1 … Question 30Four rows per question (content, type, options, points), repeating down the column.
Tip: Each control uses either a rubric or point-per-question scoring β€” never both. If a control has rubric text and questions with point scores, the import is rejected.

Example β€” a rubric-scored control

Fill the rubric rows and leave the question rows blank. The reviewer scores the whole control against your rubric. See Rubric scoring.

Row (column A)Column B (this control)
Control NameAccess Control
Rubric TitleAccess control maturity
Max Points10
Rubric ContentScore 8–10 if MFA is enforced everywhere and access is reviewed quarterly; 5–7 if partially; 0–4 if not.
Min / Max Effective Value8 and 10
Min / Max Needs Improvement Value5 and 7
Min / Max Ineffective Value0 and 4

Example β€” a point-per-question control

Leave the rubric rows blank and fill the question rows instead. Each question takes four rows. See Point-per-question scoring.

Row (column A)Column B (this control)
Control NameEncryption
Question 1Is data encrypted at rest?
Question 1 Typeselect
Question 1 Options*Yes|No
Question 1 Points10|0

The Options and Points shorthand

  • Type is text, select, or multiselect. "text" is a free-text answer β€” leave its Options and Points blank.
  • Separate options with a pipe: "Option A|Option B|Option C".
  • Put an asterisk before the good answers: "*Yes|No" means Yes is acceptable and No is a bad answer (bad answers show in red).
  • Points apply to select questions only β€” one integer per option, in the same order, separated by pipes.
FieldExampleReads as
Options*Full encryption|*Partial|NoneFull and Partial are acceptable; None is a bad answer
Points10|5|0Full = 10, Partial = 5, None = 0
Tip: For multiselect questions, list options the same way but leave Points blank (points apply to select only). Ranges are optional β€” leave the six value rows blank to use the defaults.

Upload it

  1. Save the file as .xlsx.
  2. Back on the Controls page, click "Import", drag your file in, and upload.
  3. Docubark confirms how many controls and questions it imported.

Creating builder tags

Group controls into subcategories that map to vendor types.

The assessment builder organizes controls into categories and tags. Tags let you assemble the right set of controls for a given vendor type.

Create a builder tag

  1. Go to Builder under Assessments.
  2. Click "Add New Category" to create a category (if you don't already have one).
  3. Click the plus (+) sign on the category to create a tag.
  4. Enter a tag name and description, pick an icon, and optionally assign an SME group.
  5. Save, then attach the controls that belong to this tag.

Creating SME groups

Set up groups of subject matter experts to review assessment areas.

An SME group is a set of subject matter experts responsible for a specific area of an assessment. Attach a group to a builder tag so the right people are looped in automatically.

Create an SME group

  1. Go to SME Groups under Assessments.
  2. Create a new group and give it a name and description.
  3. Add members by name and email, or pick existing teammates.
Tip: Link an SME group to a builder tag so questions in that area route to the right experts.

Rubric scoring

Score a control against an overall rubric instead of individual questions.

Rubric scoring lets a reviewer score an entire control against a written rubric, rather than tallying individual questions. It suits judgment-based areas where an overall assessment is more meaningful than a checklist.

How it works

  • Each rubric control has a rubric title, the rubric guidance text, and a maximum number of points.
  • The reviewer reads the evidence and assigns a score up to the max points.
  • That score maps to an effectiveness band β€” Effective (green), Needs improvement (yellow), or Ineffective (red) β€” based on the ranges you set.
Tip: Use rubric scoring for holistic controls; use point-per-question scoring when each question should carry its own weight.

Point-per-question scoring

Score a control from the answer options on each question.

With point-per-question scoring, each question's answer options carry their own point values, and the control's score is the points earned versus the points available.

How it works

  • Every answer option has a point value; you pick the option that matches the vendor's answer.
  • Options can be flagged as a "bad answer" (shown in red) to mark a weak choice.
  • Informational or N/A options can be excluded from the denominator so they don't count toward the maximum.
  • The control score is points earned Γ· points available, shown as a percentage.
Tip: See how assessment scoring rolls up for how question and category scores combine into an overall result.

How assessment scoring rolls up

How question and category scores combine into one assessment score.

An assessment's overall score is a straightforward roll-up of the points earned across all of its scored categories β€” whether those categories use rubric or point-per-question scoring.

From questions to categories

Within a category, each scored question contributes its earned points and its available points. N/A answers and excluded (informational) options are skipped so they don't distort the result. The category score is earned Γ· available β€” shown as a percentage and mapped to an effectiveness band.

From categories to the assessment

The overall score sums earned and available points across every scored category, then divides. There's no separate per-category weighting β€” each category contributes in proportion to its points, so a larger category naturally counts for more. When a ticket has several assessments, the same roll-up combines them into one percentage.

Tip: N/A answers are excluded entirely, so marking a question that doesn't apply won't count against the vendor.

Vendors & Tickets

Creating a vendor

Add a vendor so you can track and assess it.

Adding a vendor creates the record you'll open tickets and run assessments against.

Add a vendor

  1. Go to Vendors and click "Add Vendor".
  2. Enter the vendor name (required). Optionally add the product, URL, vendor type, and a short description of the use case.
  3. Click "Save" β€” the vendor appears in your list, ready for tickets and assessments.
Tip: Bringing over a lot of vendors? Use Import β†’ "Import Vendors" to add them from a spreadsheet.

Creating a ticket from a vendor profile

Open a ticket directly on a vendor to start a piece of work.

A ticket tracks a unit of work on a vendor β€” like a review or a reassessment. The quickest way to start one is from the vendor's profile.

Create a ticket

  1. Open the vendor and go to its Tickets tab.
  2. Click "Create Ticket".
  3. Choose a ticket type (required) and, optionally, a department, then click "Create".
  4. Docubark opens the new ticket so you can run an assessment and track progress.

Creating a ticket from the intake form

Collect vendor requests and convert them into tickets.

The intake form lets people request a vendor for review. Submissions arrive as intake tickets that you convert into a vendor and ticket.

Share the intake form

  1. Go to Intake β†’ Form and copy your intake form URL.
  2. Share the link with anyone who requests new vendors.

Convert a submission to a ticket

  1. Go to Intake β†’ Tickets to see submitted intakes (status "Intake Review").
  2. Open a submission to review its answers.
  3. Click "Convert" and choose "Create New Vendor" or select an existing vendor.
  4. Confirm β€” Docubark creates the vendor and ticket from the intake.

Running an assessment in a ticket

Manually choose a builder tag and run its assessment.

Inside a ticket you can run an assessment against any builder tag you choose β€” useful when you want to pick the assessment yourself rather than rely on intake mapping.

Run an assessment

  1. Open the ticket (or vendor) and go to the Assessments tab.
  2. Click "Start Assessment" to open the Run an Assessment wizard.
  3. Choose the builder tag: pick from "Your Team's Assessments", or toggle "Show Standard Assessments" for the standard ones, then click Continue.
  4. Pick an Answer Mode β€” "AI Assistant" (then select the vendor files to analyze) or "Manual Entry" β€” and click Continue.
  5. Click "Run Now".
Tip: AI Assistant drafts answers from the files you select; Manual Entry lets you fill them in yourself.

Sending a questionnaire to a vendor

Create an assessment in a ticket and send it to the vendor to complete.

You can send an assessment to a vendor contact so they answer the questions themselves, then track their progress from Docubark.

Send the questionnaire

  1. Open the ticket and create the assessment you want the vendor to complete (see Running an assessment in a ticket).
  2. On the ticket page, open the assessment's dropdown menu and select "Send to Vendor".
  3. In the "Send Assessments to Vendor" dialog, choose the vendor contact and confirm the assessments to send.
  4. The contact receives an email with a link to answer the questions β€” no Docubark account required.
Tip: The vendor needs a contact email on file. If it doesn't have one, add a vendor contact first, then send.

Completing your questionnaire with vendor documents

Let Docubark draft the answers from the vendor's documents.

Instead of chasing the vendor, you can have Docubark draft the answers from documents they've already provided β€” SOC 2 reports, policies, prior questionnaires.

Answer from documents

  1. Open the vendor and upload the documents on its Files tab.
  2. Go to the Assessments tab and click "Start Assessment".
  3. Choose the builder tag and click Continue.
  4. For Answer Mode, pick "AI Assistant", select the documents to analyze, and click Continue.
  5. Click "Run Now" β€” Docubark reads the documents and drafts the answers for you to review.
Tip: This is the same wizard covered in Running an assessment in a ticket β€” here the focus is on answering from uploaded documents.

Using the vendor list (filter, sort, export)

Find, organize, and export your vendors.

The vendor list is your master view of every vendor, with columns for status, risk, and review dates. You can filter, sort, choose columns, and export it.

Filter

  • Search by name, product, or URL.
  • Filter by vendor type, status, inherent risk, residual risk, review frequency, and next review (upcoming, overdue, or today). Risk filters appear when the matching risk modules are enabled.

Sort and columns

  • Click any column header to sort; click again to reverse. Turn on "Keep Sort Permanent" to remember it.
  • Use the "Columns" menu to show or hide columns such as Inherent Risk, Residual Risk, Annual Loss, Control Effectiveness, and review dates.

Export

Click "Export (csv)" to download the list as a CSV. The export respects your current filters, so you get exactly the vendors and columns you're looking at.

Tip: You can also group vendors by parent company to see a parent and its subsidiaries together.

Importing your vendor list

Bulk-add vendors from a spreadsheet.

Instead of adding vendors one at a time, import them from an Excel file β€” handy when migrating from a spreadsheet or another tool.

Import vendors

  1. On the Vendors page, click "Import" β†’ "Import Vendors".
  2. Download the template and fill it in. The first row must be the headers.
  3. Required columns are Vendor Name, Vendor Product, Vendor URL, and Vendor Status (Department is optional).
  4. Pick the vendor type to apply, drag in your .xlsx or .xls file (up to 10MB), and upload.

Ludicrous Mode

Turn on "Ludicrous Mode" to have AI enrich each vendor from a web search before import β€” then you only need the Vendor Name (up to 200 vendors per upload). You can also set one ticket type to apply to all of them.

Tip: The same Import menu also has "Import Contacts" and "Update Departments" for bulk contact and department updates.

Risk Settings

Data Volume

Group vendors by how much data they process, and score each level.

Data Volume classifies a vendor by how much data it processes β€” the more records a vendor handles, the greater the potential impact if something goes wrong. Each volume level carries a risk score that feeds your inherent risk calculation.

How it works

You define volume levels (for example Low, Medium, and High) as record-count ranges. During vendor intake, the vendor is matched to a level based on how much data they handle.

  • Category name β€” e.g. "Small scale" or "Enterprise"
  • Record range β€” a minimum and an optional maximum (leave the max blank for open-ended, e.g. 100,000+ records)
  • Risk score (0–100) β€” how much this volume level contributes to inherent risk
  • A color, and optionally builder tags that auto-apply when this level is selected
Tip: Rule of thumb β€” Low: limited data processing, minimal exposure. Medium: moderate volumes, standard controls. High: large-scale processing, enhanced security measures.

Why it matters

A breach at a vendor holding millions of records is far more damaging than one holding a handful. Scoring volume lets Docubark weight high-volume vendors appropriately. Configure it under Risk Settings β†’ Data Volume.

Data Classification

Define the types of data a vendor handles and how sensitive each is.

Data Classification defines the types of data a vendor handles β€” and how sensitive each type is. Sensitivity is usually the single biggest driver of vendor risk, so this feeds directly into the "data sensitivity" part of your inherent risk score.

How it works

You create a ranked list of classifications (for example Public, Internal, Confidential, PII), ordered from least to most sensitive. During intake a vendor may handle several types β€” Docubark uses the highest-scoring classification selected as the data sensitivity score, so handling even one highly sensitive type raises the risk regardless of what else is present.

  • Classification name and description
  • Risk level β€” low, medium, or high (color-coded)
  • Risk score (0–100)
  • Order (least to most sensitive), an optional PII flag, and optional builder tags
Tip: Because the highest score wins, give your most sensitive categories (PII, financial, health) the highest scores so they anchor the result.

Why it matters

Sensitive data β€” PII, financial, health, source code β€” carries regulatory and reputational weight (GDPR, HIPAA, and the like). Classifying it lets Docubark apply the right scrutiny and controls to the vendors that touch it. Configure it under Risk Settings β†’ Data Classification.

Unavailability Impact

Rate the business impact if a vendor's service goes down.

Unavailability Impact rates what happens to your business if a vendor's service becomes unavailable. It captures how critical a vendor is to your operations and feeds the "business impact" part of your inherent risk score.

How it works

You define impact levels (for example Low, Medium, High, or Critical). During intake the vendor is assigned a level based on how much you depend on them.

  • Impact level name and description
  • Risk level β€” low, medium, or high
  • Risk score (0–100)
  • Order, plus optional builder tags
Tip: In the ticket's inherent-risk breakdown this appears as "Business Impact." Think in recovery-time terms β€” a payment processor going down is Critical; a rarely-used tool might be Low.

Why it matters

A vendor's availability can matter as much as the data it holds. Rating unavailability impact ensures business-critical vendors get the oversight and review cadence they deserve. Configure it under Risk Settings β†’ Unavailability Impact.

Inherent Risk

The baseline risk of a vendor before controls β€” and how it's scored.

Inherent risk is a vendor's baseline risk before any controls are considered β€” how much damage they could do based on the data and access they have. It's the anchor the rest of Docubark's risk model is built on.

How the score is calculated

Docubark combines three weighted factors into a single 0–100 score:

Each factor is multiplied by a weight you set, and the weights must add up to 100%: (data sensitivity Γ— its weight) + (data volume Γ— its weight) + (business impact Γ— its weight).

Configuring it

  1. Under Risk Settings β†’ Inherent Risk, set the weight for each factor so they total 100%.
  2. Define your risk-level tiers (e.g. Low / Medium / High) with score ranges, a color, a risk factor (a multiplier used downstream), and a review frequency.
  3. Optionally attach builder tags to a tier so they auto-apply during intake.

What it drives

  • Review cadence β€” each tier sets how often the vendor is reassessed (e.g. annually, every 3 years, or upon incident)
  • Assessment scope β€” a tier's builder tags decide which assessments and questions apply
  • It's the starting point for residual risk and FAIR modeling
Tip: Prioritize by inherent risk β€” the vendors that can hurt you most deserve your time and scrutiny first.

Residual Risk

The risk that remains after a vendor's controls are taken into account.

Residual risk is what's left after a vendor's controls reduce their inherent risk. Where inherent risk asks "how bad could this be," residual risk asks "how bad is it likely to be, given how well this vendor actually protects itself."

How it works

Docubark takes inherent risk as the baseline, then applies the vendor's control effectiveness β€” a 0–100% score derived from their assessment answers (and any manual adjustments). Controls reduce how often a loss is likely to occur, producing a residual risk level and an Annual Loss Expectancy (ALE) β€” roughly, what this vendor could cost you in a typical year. The flow is: Inherent Risk β†’ Controls β†’ Residual Risk.

Configuring it

  • Expected incident cost β€” the baseline dollar cost of a typical security incident for your organization
  • Vulnerability modifier β€” a flat factor (default 0.05, i.e. 5%) that scales raw vulnerability so the implied breach probability matches published industry data
  • Risk-level tiers β€” dollar (ALE) ranges with colors and score ranges
Tip: Changed your settings? Use "Rescore Vendors" to apply them across existing tickets.

Why it matters

Two vendors with the same inherent risk can carry very different residual risk depending on their controls. Expressed in dollars via FAIR modeling, residual risk is what lets you compare vendors on a common, business-friendly scale. Configure it under Risk Settings β†’ Residual Risk.

FAIR Modeling

How Docubark turns risk scores into a dollar figure using the FAIR model.

FAIR (Factor Analysis of Information Risk) is the quantitative model Docubark uses to translate assessment scores into a dollar figure. It's how a vendor's residual risk becomes an Annual Loss Expectancy you can put in front of a CFO or board.

The core equation

Risk = Loss Event Frequency Γ— Loss Magnitude. In plain terms: how often a loss is likely to happen, multiplied by how much it would cost β€” giving an annualized dollar figure (the ALE).

Loss Event Frequency β€” how often

  • Threat Event Frequency (TEF) β€” the baseline rate of credible attacks per year, driven by the vendor's inherent risk
  • Vulnerability β€” the percentage of those attacks that would actually succeed: (100% βˆ’ control effectiveness) Γ— the vulnerability modifier. Better controls mean lower vulnerability
  • Loss Event Frequency (LEF) = TEF Γ— Vulnerability. Controls reduce how often losses happen, not how much they cost

Loss Magnitude β€” how much

  • Primary loss β€” your configured expected incident cost (the base impact)
  • Risk factor β€” a multiplier from the vendor's inherent-risk tier; higher inherent risk amplifies the cost of a single loss
  • Total Loss Magnitude = primary loss Γ— risk factor

Putting it together

Annual Loss Expectancy (ALE) = LEF Γ— Loss Magnitude. That single dollar figure is what Docubark plots and reports, so you can prioritize by real financial exposure rather than color-coded guesses.

Tip: The key intuition: controls change frequency (how often), inherent risk changes magnitude (how much) β€” and both feed the same annualized number.

Monitoring & Oversight

Subprocessors on a vendor profile

See a vendor's subprocessors, auto-gathered from public data.

The Subprocessors tab on a vendor profile lists the fourth parties that vendor relies on β€” its own subprocessors. Docubark gathers this automatically from publicly available data, so you can see a vendor's supply chain without chasing it down.

How it's generated

  • Docubark pulls the subprocessor list from public sources and caches it; it refreshes on first load and can be re-run.
  • Each entry shows the subprocessor's name and its country of processing, plus when the list was last refreshed.
  • If nothing can be found publicly, you'll see a note that a list couldn't be gathered.

Cross-check against a document

You can also upload one of the vendor's documents and have AI check it against the tracked list β€” it flags which listed subprocessors it found (with the page and a supporting quote), plus any new ones in the document that aren't tracked yet.

Tip: For the org-wide view across all vendors, see the Subprocessors page.

The Subprocessors page

A cross-vendor view of your fourth-party exposure.

The Subprocessors page rolls up subprocessors across all of your vendors into one place β€” a fourth-party map of who your vendors depend on.

What it shows

It aggregates the subprocessor lists gathered on each vendor profile, so you can spot concentration risk β€” for example, many of your vendors relying on the same underlying provider β€” at a glance.

Tip: Subprocessor data originates on each vendor's profile; see Subprocessors on a vendor profile for how it's generated.

Monitoring Alerts

Continuous breach and fraud news tied to your vendors.

Monitoring Alerts surface recent breach and fraud news about your vendors, so a problem at a third party reaches you without you going looking for it.

How they're generated

  • A daily run scans the news for breach and fraud coverage published in the last 24 hours and matches it to your vendors.
  • Each alert is tagged Breach (red) or Fraud (yellow), with a title, summary, the article date, when it was detected, and a link to the source.

Managing alerts

Alerts appear both under Monitoring Alerts (team-wide) and on the vendor's own Alerts tab. Dismiss one you've handled or that isn't relevant, optionally noting why β€” for example duplicate coverage or a false positive.

Tip: Turn on continuous monitoring β€” and optional daily email digests β€” in Team Settings, where you can also enable it for all vendors at once.

Exceptions

Document an accepted risk on an assessment and track it to closure.

An exception is a documented decision to accept a gap or risk rather than remediate it right now. You raise it on a specific assessment answer, and Docubark tracks it until it's closed.

Raising an exception

  1. In an assessment, open the exception control on the question you want to flag.
  2. Choose a risk level β€” Low, Medium, High, or Critical β€” and add an optional comment.
  3. Save. The exception records an allowed window (default 90 days) and a target close date.

Where exceptions live

  • On the vendor's Exceptions tab β€” with days open, allowed days, target close, risk level, status, and the related assessment, control, and question. You can edit the allowed days, risk level, and Open/Closed status inline.
  • On the Exceptions page β€” every exception across all vendors, with filters for days open, allowed days, risk level, and status.
Tip: Exceptions turn "we accepted this risk" into an auditable record with an owner and a clock, instead of a forgotten email.

Document expirations

Track when vendor documents expire and see what's coming due.

Vendor documents β€” SOC 2 reports, certificates, insurance β€” expire. Docubark lets you set an expiration date on any uploaded document and rolls them all up so nothing lapses unnoticed.

Set an expiration on a document

  1. Open the vendor and go to the Files (Documents) tab.
  2. In the "Expires at" column, click the date field for the document and pick its expiration date.
  3. It saves right away.

The Expirations page

The Expirations page lists every document with an expiration across all vendors. A "Days Left" column shifts from gray to yellow to orange to red (and "overdue") as the date nears. Filter by an expiry window β€” 30, 60, or 90 days, or already expired β€” or search by vendor or file name.

Tip: Only documents with an expiration date set appear on the Expirations page, so add dates as you upload.

Administration

Team members & roles

The user roles and what each one can access.

You manage who's on your team and what they can do under Team settings. Docubark has four roles, each with a different level of access.

The roles

  • Admin β€” full access: manage vendors, assessments, settings, and team members. The team owner is the top-level admin (shown as "Admin (Owner)").
  • Member β€” day-to-day TPRM work: vendors, assessments, intake, and reports.
  • Business Owner β€” a limited requester view: submit new vendor requests, track their own requests, and browse approved vendors. See the Business Owner view.
  • SME β€” subject matter experts who answer the assessment areas assigned to their SME group.

Inviting people

  1. Under Team settings, enter the person's email, pick a role, and send the invite.
  2. Invites show as Pending until accepted.
  3. An admin can change a member's role, or remove them, at any time.
Tip: Roles decide what each person sees β€” a Business Owner, for instance, never sees the full vendor list or settings.

The Business Owner view

What a business owner sees β€” request, track, and browse approved vendors.

Business Owners are the people requesting new vendors, not running the TPRM program, so their view is intentionally simple β€” three things.

What a Business Owner can do

  • New Request β€” open the intake form to request a new vendor for review.
  • My Requests β€” track the status of requests they've submitted, including whether approval is needed, approved, or rejected.
  • Approved Vendors β€” browse the vendors the company has already approved, so they can reuse an approved tool instead of requesting a duplicate.
Tip: Give someone this view by assigning them the Business Owner role.

Ticket configuration

Set up ticket types, departments, SLAs, and labels.

Ticket configuration (under Ticket Settings) controls how assessment tickets are classified and paced β€” where you tailor the workflow to your program.

What you can configure

  • Ticket types β€” the categories of work (for example New vendor or Reassessment), each with a name and optional description.
  • Departments β€” the business units you can assign tickets to.
  • SLAs β€” target turnaround in days for the whole ticket, for SMEs, and for vendors.
  • Section labels β€” rename the "Notes & Comments" section to match your team's language.
Tip: The same settings area holds your Business Intake Form link β€” see the intake form.

The intake form

Build the form requesters use to submit vendors β€” including the inherent-risk inputs.

The intake form is the questionnaire a requester fills out to submit a vendor. It collects the basics, any custom questions you add, and the inputs that drive inherent risk. You share it as a link, and each submission becomes an intake ticket.

What the form collects

  • Basic info β€” vendor name, URL, product, vendor type, use case, ticket type, and department, plus the submitter's and vendor contact's details.
  • Custom questions β€” add your own (text, URL, select, multi-select, or long answer), mark them required, allow document attachments, or let AI help answer them.

Inherent risk inputs

The form also gathers the three inputs behind a vendor's inherent risk score:

  • Data classification β€” which types of data the vendor will handle (select all that apply); the most sensitive selection drives the score. See Data Classification.
  • Data volume β€” how many records, chosen on a Low-to-High slider. See Data Volume.
  • Unavailability impact β€” the business impact if the vendor goes down. See Unavailability Impact.

Each answer feeds the weighted inherent-risk calculation, and selections can auto-apply builder tags to the resulting ticket.

Tip: Configure the weights and risk tiers under Risk Settings β†’ Inherent Risk.

Didn’t find what you needed? Contact support or book a demo.