VendorBenchmarkUser manual PDFOpen the app →

06 · Settings & account

Everything about you and your organization's setup lives here: your profile and how you sign in, what the AI has learned about you, your plan and billing, your teammates and their roles, the security and compliance controls that govern your data, and the connections to your other systems. Settings are grouped into four sections, You, Workspace, Security & compliance, and Connections. Some pages are visible only to organization owners; each section below says who can see it.

The settings window. Settings opens as a window of its own rather than as a page inside the workspace, the same Windows style window the Contract Reader and the Benchmark Library use. One frame holds the whole area, so moving from Billing to the audit log redraws only the page, never the window. The map runs down the left as a frosted rail holding all twenty three pages under their four groups, with your organization, your role, and your plan at the top of it, and the Trust center on a plate at the foot. Pages that carry a live fact show it on the entry: the number of people, the plan name, how many systems are connected. A dot marks a setting that needs attention, such as two factor still being off.

The Security & compliance section is deliberately short: one Security page carries account security, posture, single sign on, the baseline, data controls, and the audit log as nested sections, and one Trust center page carries the overview and the figures ledger as underline tabs. Each keeps its own section below, and old bookmarks to the former standalone pages redirect to the right place.


Settings home

Where: Settings · /settings
Who: everyone

The overview of your workspace: its current state first, then the map. Use it when you want to know where things stand; use the index rail when you already know the page you want.

Settings home screenshot

On the screen

How to use it

  1. Read the vitals. Anything reading Off or 0 is a gap worth closing.
  2. Work through Worth doing now; each row goes straight to the page that fixes it.
  3. Use the index rail on the left for everything else, or the filter if you are not sure which page owns the setting.

Related: Security · Billing · Trust center

Profile

Where: Settings › You › Profile · /settings/account
Who: everyone

Your personal details: your name, job title, timezone, photo, the vendors you follow, and your password. This is also where you connect your Microsoft account.

Profile screenshot

On the screen

How to use it

  1. Fill in your name, title, and timezone, then save.
  2. Add the vendors you care about so your alerts and weekly report are relevant.
  3. Use Change password to rotate your password whenever you need to; use Change next to your email when you move addresses.

Related: Security · Members · Notifications

Security

Where: Settings › Security & compliance › Security · /settings/security
Who: everyone

*In plain words: your account's locks: two-factor, sessions, and the org-wide policy.*

When to reach for this

The landing section (Account security) of the one Security page. Protect your account with two-factor authentication and see the devices where you are signed in; owners also set the organization-wide two-factor policy here. The other five sections, Posture, Single sign on, Baseline, Data controls, and Audit log, sit indented under Security in the index rail while you are inside it, and each is documented below.

Security screenshot

On the screen

How to use it

  1. Open your authenticator app (Google Authenticator, 1Password, Authy, and the like) and scan the code shown.
  2. Enter the six-digit code to confirm, then save your backup codes somewhere safe.
  3. Review active sessions and sign out any you do not recognize.

Tips

Related: Security posture · Two-factor authentication

AI personalization

Where: Settings › You › AI personalization · /settings/ai
Who: everyone

What the platform has learned about how you like output, in plain language and fully under your control. The more you use Vera AI, the more its answers match your preferences.

AI personalization screenshot

On the screen

How to use it

  1. Review the list to see what the AI has inferred.
  2. Remove anything that is wrong or that you would rather it not use.

Tips

Related: Memory · Vera AI

Memory

Where: Settings › You › Memory · /settings/memory
Who: everyone

What your organization learned in past negotiations and how it likes to negotiate. Briefs, mandates, and Ask all open with this record, so it is worth keeping current.

Memory screenshot

On the screen

How to use it

  1. Check the posture reflects how your organization actually negotiates.
  2. Prune or correct any remembered fact that is out of date.
  3. Corrections you make in the extraction review queue also teach the extractor directly: the next document from that vendor is read with your past corrections in hand.

Related: AI personalization


Billing

Where: Settings › Workspace › Billing · /settings/billing
Who: everyone (only owners can change the plan or pay)

See what plan your workspace is on, how much of your allowance you have used, your benchmark credits, and, if you own the organization, upgrade.

*In plain words: your plan, your meters, and the upgrade path.*

When to reach for this

Billing screenshot

On the screen

How to use it

  1. Check where you sit against your allowance for the period.
  2. If you own the organization and need more, pick a plan and message our team; upgrades are set up the same day and billed by invoice, net 30.
  3. Not an owner? Ask an owner to upgrade, or message the team.

Related: Members

Desktop app

Where: Settings › Workspace › Desktop app · /settings/desktop-app
Who: everyone

Install the platform as its own app on your laptop: its own window, taskbar icon, and Start menu entry, on the same account and data as the browser. The page offers two applications, VendorBenchmark Desk and Second Chair, each for Windows and, where noted, for macOS.

Desktop app screenshot

On the screen

How to use it

  1. Click Download the Desk and run the downloaded installer.
  2. If Windows warns about a new app, choose More info, then Run anyway.
  3. Sign in with the same email, password, and two-factor code you use in the browser.

Your contracts as folders on the machine. From version 0.19.0 the Desk can keep your estate on this computer as ordinary Windows folders, one per vendor. Open the Desk, go to Settings inside it, and under Your contracts as folders choose where they should live, then press Bring my contracts down. Every contract lands in its vendor’s folder, where it opens, moves and files like any other document. Drag a paper from one vendor folder to another in Explorer and it changes vendor everywhere, exactly as refiling it in the window does. Deleting a file there removes only your copy: the contract stays in the estate and comes back on the next pass, because removing a contract stays something you do in the app, where it asks twice. Stopping the mirror leaves the files alone, since they are your own copies of your own contracts.

The earlier Vera AI shell, a window around the browser workspace, is no longer offered here: the Desk replaces it and carries more. Copies already installed keep working and keep updating themselves.

Second Chair, the meeting app (early preview)

VendorBenchmark Desk, the platform as an app (early preview)

Mobile app

Where: the App Store and Google Play, on the same account and data as the browser
Who: everyone

Vera AI on your phone. Five native screens for the things a phone is better at, and a Rooms tab that opens the instruments themselves, signed in, running the same figures as the web app.

On the screen

How to use it

  1. Install the app, then sign in with the same email, password, and two-factor code you use in the browser.
  2. Turn on the fingerprint or Face ID lock in Settings if the phone is shared or travels with you.
  3. Choose your alert kinds in Settings; renewal alerts start off, exactly as they do on the web.

Tips

Related: Notifications, Desktop app

Members

Where: Settings › Workspace › Members · /settings/members
Who: org owners only

Invite teammates, set their role, and manage everyone in your organization. Owners also see pending invitations, seat usage against the plan, and any join requests waiting for them. A non-owner who opens the page sees a locked plate naming the workspace owners to ask, not a bare access line.

*In plain words: who is in, what they can do, and the clean way in and out.*

When to reach for this

Members screenshot

On the screen

How to use it

  1. Click Invite, enter the person's email, choose their role, and send. For a whole team, use Invite several people at once instead.
  2. Watch pending invitations for delivery problems and resend if needed; an expired invite just needs a resend.
  3. Adjust roles as responsibilities change; block anyone who should no longer have access.
  4. Before an owner leaves the company, promote their replacement to owner first; the platform refuses changes that would leave no active owner.

Tips

Related: Team activity · Deal approvals

Teams

Where: Settings › Workspace › Teams · /settings/teams
Who: org owners only

Named groups you can grant confidential contracts and agreements to as one unit. Membership in a granted team is the access itself: joining the team grants its documents at that moment, leaving revokes them, with nothing to clean up per document. A non-owner who opens the page sees a locked plate naming the workspace owners to ask.

*In plain words: grant a group once, and joining or leaving the group is the access change.*

When to reach for this

Teams screenshot

On the screen

How to use it

  1. Create a team and add the people who share an access need.
  2. Open a restricted contract and grant the team from its Access panel, next to individual grants.
  3. When someone changes roles, move them between teams; their document visibility follows automatically.

Tips

Related: Members

Team activity

Where: Settings › Workspace › Team activity · /settings/activity
Who: org owners only

What each member actually does on the platform, which features they use, and an on-demand report that turns the numbers into an adoption plan. A non-owner who opens the page sees a locked plate naming the workspace owners to ask.

Team activity screenshot

On the screen

How to use it

  1. Scan the verdict to gauge overall adoption.
  2. Use the per-member table to spot who has not started and which features go unused.
  3. Generate the usage report when you want a written adoption plan to act on.

Related: Members · Audit log

Deal approvals

Where: Settings › Workspace › Deal approvals · /settings/approvals
Who: org owners only

An optional sign-off chain: up to ten approvers who must clear a deal before it is signed. Off by default; turn it on when your organization needs a documented approval step. A non-owner who opens the page sees a locked plate naming the workspace owners to ask.

Deal approvals screenshot

On the screen

How to use it

  1. Turn on deal approvals and pick your approvers.
  2. Negotiators request sign-off from a deal's page under Major renewals; approvers vote from their queue.
  3. Track progress in the recent requests list.

Related: Approvals

Branding

Where: Settings › Workspace › Branding · /settings/branding
Who: org owners only

Put your organization's logo on the documents you export. Once a logo is set it co-brands the exported CFO executive brief and the boardroom deck and brief alongside the Vera AI brand. With no logo set, exports are unchanged.

Branding screenshot

On the screen

How to use it

  1. Upload a logo image.
  2. Export a CFO brief or a boardroom deck to see it applied, alongside the Vera AI brand.

Display currency

Where: Settings › Workspace › Display currency · /settings/currency
Who: org owners only

The default currency for amounts your team enters. Benchmarks stay in USD so every market comparison holds.

Display currency screenshot

On the screen

How to use it

  1. Pick your currency and press Save.
  2. Leave rows that already carry their own currency alone; they keep it, whatever this is set to.

Tips

Related: Billing · Branding

Date format

Where: Settings › Workspace › Date format · /settings/date-format
Who: org owners only

How numeric dates in uploaded contracts are read. A date written 03/04/2026 is March 4 under the US convention and 3 April under the European one; only you know which convention your contracts follow, so the platform asks once instead of guessing. Every extraction pass, the instant pre-fill in the upload wizard, the background enrichment after a file is attached, and the bulk import, reads numeric dates in the order set here.

Date format screenshot

On the screen

How to use it

  1. Pick the convention your contracts are written in and press Save.
  2. Upload as usual; the wizard pre-fills term dates in the chosen order.

Tips

Related: Display currency · Upload a proposal

Notifications

Where: Settings › Workspace › Notifications · /settings/notifications
Who: everyone (owners get the extra alert and webhook controls)

*In plain words: what may interrupt you, on which channel; everything renewal-shaped starts silent until you ask.*

When to reach for this

The page opens with What reaches you now: a summary computed from your saved switches listing every email, briefing, and chat DM that will currently reach you, each naming its trigger, with renewal notices showing your organization's lead days. When nothing is on it says so plainly: everything is opt in until you turn it on.

Tune which alerts reach you, on which channel, and when. One preference model governs every channel: a setting made here (or a mute made from the inbox bell) applies to the in-app inbox, push, and email together, so nothing silences you on one surface while interrupting you on another. Renewal alerts are opt in: nothing about a renewal reaches you, on any channel, until you switch it on. Owners can also post alerts to Slack or Teams and set the AI copilot's alert rules.

Notifications screenshot

On the screen

How to use it

  1. Pick your weekly briefings: price lists, licensing news, knowledge, any mix. Off is always one toggle (or one email click) away.
  2. Set quiet hours if you carry the mobile app: nights stay silent and nothing important is lost, it waits for morning.
  3. Turn on the renewal alerts you want. They start off, so a workspace stays silent about renewal dates until someone here asks for them, and the standard renewal checklist tasks are not filed either; Turn on money-critical alerts switches the whole set on at once. Renewal notice alerts also switch on the Monday renewal radar, one roll-up email covering everything entering or inside its notice window over the next 60 days, and the daily leverage note described above.
  4. Turn off any alert kind you do not want, move it to a single channel, or send it to the weekly digest. Every renewal alert email also carries a one-click Turn it off link that works without signing in.
  5. Want your renewals in Slack or Teams? DM the Vera bot once in your company workspace, then flip the Chat DM toggle on the alert types you care about.
  6. Review the Muted chips: anything you muted from the bell in passing is listed here, so no alert type stays silenced invisibly.
  7. Choose which Monday brief sections you receive; the others still land in the app.
  8. Owners: set the copilot alert rules and connect a chat channel if the team wants alerts there.

Security posture

Where: Settings › Security & compliance › Security › Posture · /settings/security/posture
Who: everyone (owners see and manage every control; members see the policies that apply to them and their own devices)

The Posture section of the Security page (formerly the standalone Security Center, whose old address redirects here). Your organization's live security posture on one view: two-factor coverage, single sign-on, retention, API credentials, the audit stream, recent security events, and your sign-in devices. Live state, not marketing.

Security Center screenshot

On the screen

How to use it

  1. Read the posture tiles for a one-glance health check.
  2. Owners: work down the controls list and tighten anything that reads as merely "Available" rather than "In force."
  3. Check your devices and sign out anything unfamiliar from the Account security section.

Related: Security · Trust center · Audit log

Clause positions

Where: Settings › Security & compliance › Clause positions · /settings/clause-library
Who: everyone

The summary of your negotiation playbook: the positions, pre-approved language, and walk-away lines that every AI review holds your contracts to. There used to be two editors for the same library, one here and one on the desk. There is now one. Editing lives in the Clause library desk, next to the comparison and redline tools that read the positions; this page is the summary.

Clause positions screenshot

On the screen

How to use it

  1. Read the three figures to see where the library stands.
  2. With nothing on file yet, press Restore starter library to begin with the 22 starter positions. It takes effect immediately, with no confirmation step, and reports how many it added.
  3. Press Open the Clause library desk to add, edit, or delete positions and to set the must-have flags.

Tips

Related: Clause library · Security baseline

Security baseline

Where: Settings › Security & compliance › Security › Baseline · /settings/security/baseline
Who: everyone

The Baseline section of the Security page. The data-protection and security requirements every vendor contract should meet. These are the rules the DPA check enforces when it reviews a contract.

Security baseline screenshot

On the screen

How to use it

  1. Edit the baseline to match what your organization requires of vendors.
  2. Turn on any rulepacks that apply.
  3. The DPA check then measures each contract against this baseline.
  4. Owners setting a network policy: the card shows your current IP with one click to add it, and the allowlist refuses to switch on unless your own address is covered, so you cannot lock yourself out at enable time. Every denial lands in your audit log, and a policy change takes up to a minute to reach every server.

Note: if your office IP later changes, everyone including owners is blocked until the policy is updated from an allowed network; prefer ranges over single addresses if your egress IP rotates.

Related: Clause positions

Single sign on

Where: Settings › Security & compliance › Security › Single sign on · /settings/security/sso
Who: org owners only

The Single sign on section of the Security page. SAML single sign-on and SCIM provisioning for your organization, for teams that manage access through an identity provider.

Single sign on screenshot

On the screen

How to use it

  1. Enter your identity provider's SAML details.
  2. Decide whether to enforce single sign-on for everyone on your email domain.
  3. Issue a SCIM token if you want automatic user provisioning.
  4. If your identity provider supports group push, push the groups that should map to teams; members must be provisioned as users first.
  5. Optionally map groups to roles: members of a mapped group get that role on every push (approver, analyst, member, or viewer; ownership is never assigned this way), and leaving the group takes the role with it.

Related: Security posture

Data controls

Where: Settings › Security & compliance › Security › Data controls · /settings/security/data
Who: org owners only

The Data controls section of the Security page. Retention, export, and deletion for your organization's data, the document retention switch for the analysis tools, plus your consent choices for the community and outcome network. Every hard deletion writes a deletion certificate you can hand to an auditor.

*In plain words: how long data lives, where it lives, how it leaves, and the certificates that prove deletion.*

When to reach for this

Data controls screenshot

On the screen

How to use it

  1. Set a retention period if your policy requires one; blank keeps contracts until you delete them.
  2. Choose whether to contribute to the community and outcome network.
  3. Request an export or deletion when you need it; our team processes deletion requests and confirms by email.
  4. After any deletion, open its certificate from the Deletion certificates list to verify what was removed.
  5. To clear the workspace and start again, press Count what would go under Reset the estate, read the numbers, type your organization's name, and confirm. Export first if you might want the data back: this one cannot be undone.

Related: Trust center · Audit log

Audit log

Where: Settings › Security & compliance › Security › Audit log · /settings/security/audit
Who: org owners only

The Audit log section of the Security page. Who did what in your organization, including views and downloads of contract files. A transparency and compliance record you can filter, search, and export. Old links and saved views under the former standalone address redirect here with their filters intact.

Audit log screenshot

On the screen

How to use it

  1. Pick a filter or search for an actor or activity.
  2. Save a view if you audit the same slice regularly.
  3. Export to CSV, or set up an audit webhook under Integrations for continuous streaming.

Related: Security posture · Integrations

Access reviews

Where: Settings › Security & compliance › Access reviews · /settings/access-reviews
Who: org owners only

*In plain words: a quarterly, exportable proof that someone looked at who can reach what.*

When to reach for this

A quarterly attestation of who can reach what. Starting a review snapshots your organization's entire access surface at that moment: every member with their role, every team membership, and every restricted document grant. You then confirm or revoke each line, and the completed review is stored as a durable record you can hand to an auditor.

Access reviews screenshot

On the screen

How to use it

  1. Open Settings › Access reviews and choose Start a review.
  2. Work through each line. Confirm access that is still right; revoke a team membership or document grant that is not. Revocation takes effect immediately.
  3. A member who should leave the organization is flagged rather than removed here. Finish the removal on the Members page, which protects the last owner and revokes their sessions.
  4. When nothing is pending, choose Complete review. Every decision is written to the audit log.
  5. Export any completed review as CSV for an auditor or a security questionnaire.

Related: Members · Teams · Audit log

Trust center

Where: Settings › Security & compliance › Trust center · /trust
Who: everyone

How your data is protected, told in three commitments: kept apart (tenant isolation), kept sealed (encryption and access), and kept yours (audit, deletion, and eyes-off AI). The masthead proves the isolation claim with live numbers. Two underline tabs make this one page: Overview (this view) and the Figures ledger.

Trust center screenshot

On the screen

How to use it

  1. Read the three chapters to understand the controls applied to your data.
  2. Share this page with security reviewers who ask how the platform protects information.
  3. When a reviewer wants a document rather than a link, press Print or save as PDF and send the brief.

Related: Security posture · Data controls · Figures ledger

Figures ledger

Where: Settings › Security & compliance › Trust center › Figures ledger · /trust/figures
Who: everyone

Every number the platform has cited for you, in one place. The ledger lists each figure across your reports and briefs, linked to the source fact it traces to and the day that fact was current, so any number you forward can be stood behind.

Figures ledger screenshot

On the screen

How to use it

  1. Look up any number a report or brief shows to see the fact it came from and when it was current.
  2. Search for the vendor or figure a reviewer is questioning and hand them the source in one step.

Related: Trust center · Audit log


Integrations

Where: Settings › Connections › Integrations · /settings/integrations
Who: org owners only

Connect the systems your team already uses: contract intake, tickets and calendars, spend and identity data, your warehouse, and the SAM and ITAM tools that know what you own and use.

*In plain words: the plumbing between this platform and everything else you run.*

When to reach for this

Integrations screenshot

On the screen

How to use it

  1. Pick a system, enter its credentials or copy the intake address it needs, and connect.
  2. Let the first sync run, then review the license and procurement intelligence tables.
  3. Add an audit webhook if you want to stream events to your SIEM.

Related: Audit log · API · The integration catalog

API

Where: Settings › Connections › API · /settings/api
Who: org owners only

API keys, webhooks, and the MCP connector, so you can connect Claude, ChatGPT, or any other tool to your benchmark data.

API screenshot

On the screen

How to use it

  1. Create an API key and store it securely; you see the full value only once.
  2. Point your tool or the MCP connector at the connection details shown.
  3. Revoke any key you no longer use.

Related: Integrations


That covers the settings. When you are not sure where a screen belongs, start from the manual index and follow the chapter that matches the rail group you are looking at.

Next: Chapter 07 · Common workflows

Was this page helpful?

Thank you. Your note goes straight to the team that writes this manual.

Updated 2026-08-31 · A VendorBenchmark product · Download the manual as PDF · Questions? Message our team in the app.