VendorBenchmarkUser manual PDFOpen the app →

12 · Integrations, clients & deployment

The technical chapter, written for the IT, security, and procurement-ops people who wire Vera AI into an estate. It answers three questions: how data gets in and out (the integration catalog), what runs on your machines (thin and thick clients), and where the platform itself can run (the four deployment models). Nothing here is required to use the platform; everything here makes it stronger.


How the platform is delivered

Where: the standard service · app.vendorbenchmark.com

Vera AI is delivered as a managed cloud platform (SaaS). The application, database, storage, and backups are operated by us; your team signs in from a browser and maintains nothing. The technical posture, in the terms a security review asks about:

The Trust center tells this story with live numbers, and the Security posture shows your own workspace's posture against it.

Clients: what runs on your machines

The platform is thin-client first: the browser is the primary interface and nothing needs to be installed. Around it sit a thick-client desktop app and several headless surfaces.

The browser (thin client)

Who: everyone

Any modern browser is a full client. All processing happens server side, with one deliberate exception: the browser-local calculators. Several tools (Cloud cost optimizer, VCF licensing, M365 optimization) parse your usage export as a file in the page itself, so raw usage data never leaves your machine unless a step explicitly sends approved figures for analysis; each tool states which side of that line it works on. Files sent to the AI tools are read in memory and never stored.

The Windows desktop app (thick client)

Who: everyone · install is per user, no admin rights

A native shell around the same account and data, for teams that live in the platform daily: its own window and taskbar identity, drag a contract from Explorer straight onto it, native Windows notifications for deliveries and notice windows, Vera summonable over any app, Windows Hello lock, and automatic updates. Install it from Settings › Desktop app. It is a client, not a data store: uninstalling it touches nothing in your workspace. A macOS build is planned; until then Mac users get the identical workspace in the browser.

Chat clients: Vera in Slack and Microsoft Teams

Who: connected by an org owner

Vera answers inside your own Slack workspace or Teams tenant: ask about a price, a clause, or a renewal without leaving chat, with every figure tagged to its source exactly as in the app. Connected under Integrations.

Email as an interface

Who: addresses are provisioned by an org owner

Five inbound rails give every teammate an integration that needs zero training, because it is just email:

The API, MCP, and agent-to-agent

Who: org owners only (keys)

Vera OS, the autonomous procurement companion

Vera OS companion page

Where: the Vera OS page · /vera-os · reachable from the Renewals & deals rail group and the launcher home
Who: everyone; Vera OS is in beta and included with your plan, nothing to request

Vera OS is a separate product: an autonomous procurement operating system that runs as its own workspace with its own sign-in. Agents there work renewals and deals end to end under mandates you sign once, evaluated in deterministic code on every step that touches money: a renewal watchtower that opens a deal room for every term ending inside 180 days with the benchmark preloaded, cited decision briefs you approve with one tap against a 24 hour SLA, co-pilot drafting where a human always sends, and an autopilot lane that closes tail spend inside two deterministic gates with a human veto window before anything settles. Every deal is readable as a case file with a replayable trace.

How it relates to this platform. Vera OS consumes your VendorBenchmark benchmarks, playbooks, and Terms Watch through the platform API, and contributes closed-deal datapoints back anonymized, released only once at least five exist for a vendor. It replaces nothing here: every view in Vera AI stays exactly where it is.

Using the page. Vera OS is open to every workspace with no access request. The navy stage leads with Launch the Control Tower, which opens immediately.

The Control Tower preview. · /vera-os/tower

Vera OS Control Tower

The Control Tower reads your own estate the way Vera OS reads it, live and read-only: a metric strip (deal rooms to open inside 180 days, the exposure in that window, auto-renews, the estate run rate, vendors with a delivered benchmark) over a deal-rooms table of every agreement with an expiry, soonest first. The suggested lane column is a stated deal-size rule, command at $250,000 and above, co-pilot at $25,000 and above, autopilot below, never a model's judgment, and a row opens that agreement's renewal war room. Nothing is written back. Once your full workspace link is online, an Open the full workspace button appears on both pages and opens Vera OS in its own tab.

The Vera OS menu. The dark menu down the left of the Control Tower is the frame around the whole workspace, not part of one page: it stays with you as you move between screens, stays put under the top bar while a long table scrolls, and marks the screen you are on. On a narrow screen it becomes one scrolling row of the same map above the page. It holds three groups.

Deal rooms. · /vera-os/deals

Vera OS deal rooms

Every term Vera OS would open a room for, soonest first, with the lane its size puts it in, the notice date that actually binds, the exposure, and whether a delivered benchmark grounds it. The lane chips and the Show every term link filter the table and are written into the address, so a filtered view can be sent to a colleague. Rows open the renewal war room in Vera AI. When nothing ends inside 180 days the table falls back to the whole term book and says so.

Agreements. · /vera-os/agreements

Vera OS agreements

The whole estate, largest first, with the annual value, the term end, the notice date, whether it auto-renews, and the benchmark behind it. Agreements carrying no term date are marked in red and counted under the table: no room can ever open for them, so an auto-renewal on one would pass unseen.

Vendors. · /vera-os/vendors

Vera OS vendors

The estate rolled up to the party you negotiate with. Legal-entity and country spellings of one company (for example Salesforce, Salesforce UK Limited, and SFDC Ireland Limited) fold into a single row with the spellings listed beneath it, and the lane follows the total held with that party rather than the smallest line.

Benchmarks. · /vera-os/benchmarks

Vera OS grounding

The grounding, and the gap. A lane may only quote a number a delivered benchmark supports, so this screen leads with the vendors that have none, ranked by what they are worth and flagged when their term ends inside the window, then lists the grounded vendors with the report behind each one.

Delivered reports. · /vera-os/reports

Vera OS delivered reports

Every published benchmark report in the workspace, newest first, with the spend each one covers and its overall score. Drafts never appear here.

The Vera Wire. · /vera-os/wire

The Vera Wire in Vera OS

The market feed filtered to vendors you actually hold a term with, each item with its verdict, Vera's read, and the date, and the rest of the market kept short beneath it. The full feed with its lenses stays at The Vera Wire in Vera AI.

The integration catalog

Where: Settings › Connections › Integrations · /settings/integrations
Who: org owners only

Integrations screenshot

The page is one calm scroll, arranged the way this section is: contract intake first, then renewal workflow, spend and usage data, data out, and automation, with the two deep estates, procurement (P2P) and license discovery (SAM / ITAM), at the foot. Every connector ships with the same operating rules: credentials are stored encrypted and used only server side, read-only scopes are requested wherever the source system offers them, every sync is logged under Recent activity, and connector-reported entitlement figures are held for human confirmation before they can drive an alert (you will see them marked "confirm" on Billing watch). Disconnecting a source stops its syncs immediately.

Contract intake

Get the paper in without anyone uploading by hand. Half of these connectors are just private email addresses, provisioned in one click and shared with your whole team.

Contract intake connectors
ConnectorWhat it does
Email-inA private intake address; forwarded proposals become tracked contracts
Deal email-inForward a live vendor thread onto the deal record; the ghost writer can draft the reply
Invoice email-inForwarded invoices reconcile billed against contracted on Invoices
Purchase request email-inTeammates raise Requests by mail, straight into triage
Ask an agent by emailSend a question plus a document; the answer returns to your inbox
DocuSignCompleted envelopes flow in as signed agreements
IroncladExecuted contracts sync from your CLM
Google Drive folder watchDrop files in a folder, they arrive here
SharePoint folder watchSame, for Microsoft estates
Box folder importBulk import from a Box folder

Renewal and deal workflow

Push the work to where your team already lives.

Renewal workflow connectors
ConnectorWhat it does
JiraRenewal tasks and findings as issues in your project
ServiceNow (tickets)The same, as ServiceNow tickets
Calendar invitesNotice windows and renewal deadlines as calendar events
Calendar feed (meeting packs)A read-only ICS feed; vendor meetings get a pre-call pack
SlackAlerts to a channel, plus Vera in your workspace
Microsoft TeamsAlerts to a channel, plus Vera in your tenant

Spend and usage data

The money and the activity behind it: what you pay, and who actually uses what you pay for.

Spend and usage connectors
ConnectorWhat it does
CoupaSpend actuals by API
Okta usageWho actually signs in to which app
Microsoft Entra ID usageThe same, for Microsoft estates
Spend actuals importA CSV from Coupa, SAP Ariba, Zip, or a NetSuite GL export, or any generic spend CSV
Seat usage importA CSV of per-app seat activity
Smart importOne-off bulk loads: the AI reads whatever columns your export has and maps them for you

Data out and automation

Your data is yours to take with you, continuously.

Data out and automation
ChannelWhat it carries
Warehouse exportContracts, renewals, savings, and spend tables to Snowflake or BigQuery
Event webhooksSigned JSON events (deliveries, status changes, findings) to any endpoint, including Zapier or Make; verify the signature before trusting a payload
Audit webhookThe audit log streamed to your SIEM
File exportsEvery report as PDF, Word, or PowerPoint; ledgers and tables as CSV or Excel

The integrations page also carries the Agent Negotiation Protocol card: an org owner opts your workspace into structured agent-to-agent negotiation there, and the public spec lives at app.vendorbenchmark.com/agent-protocol (see The API, MCP, and agent-to-agent).

Procurement and ERP (P2P)

Purchase orders, requisitions, and supplier records, so spend that never touched a contract still shows up, with maverick spend flagged. Beneath the connector cards, the Procurement intelligence table turns the synced records into a supplier-by-supplier read.

Procurement and ERP connectors
ConnectorSource
CoupaAPI connection
SAP AribaAPI connection (US, EU, APAC endpoints)
NetSuiteToken-based API connection
Oracle Fusion Cloud ProcurementAPI connection
SAP S/4HANAAPI connection
File exportsCoupa, NetSuite GL, Ariba, Zip, or CSV when an API connection is not approved

License and deployment discovery (SAM / ITAM)

Connect the systems that know what you own and what is deployed; the License intelligence table beneath the cards then shows entitled against deployed against active per vendor, with estimated shelfware. This is the data that powers Data health, Billing watch, and audit exposure. Each connector card opens on a click to show its credential form and carries a mode badge: API connection, file import, or both.

SAM and ITAM connectors, one card open
ConnectorSource
ServiceNow SAM ProEntitlements and license positions
Flexera OneEntitlements and deployments (US, EU, APAC endpoints)
Snow License Manager / Snow AtlasEntitlements and usage
USU / Aspera SmartTrackEntitlements
Microsoft 365Seat assignments and last-activity via Microsoft Graph
Microsoft IntuneDevice and app inventory
Jamf ProApple estate inventory
ServiceNow CMDBDeployed software inventory
Oracle LMS / ULA positionYour measured Oracle deployment position
SaaS management platformsZylo, Zluri, Torii, or Productiv, via their CSV exports
Cloud billingAWS Cost & Usage Report, Azure cost export, or Google Cloud billing export, feeding Spend and the Cloud cost optimizer

How to use it

  1. Start with identity: SSO and SCIM first, so access is governed from day one.
  2. Open the cheapest intake rails: email-in addresses and a folder watch cost minutes and remove the manual-upload habit.
  3. Connect one SAM or usage source and one spend source, then follow Data health, which ranks every remaining gap by the feature it unlocks.
  4. Turn on data out last: the warehouse export and the audit webhook make the platform a citizen of your data estate rather than an island.

Related: Integrations (settings reference) · API · Connect your data and close the gaps

Deployment models

Who: Cloud is the standard service; the other three are Enterprise conversations

Most teams run the standard Cloud service and are live the same day. For organizations whose policies require more, three further models exist; they are scoped with your security team rather than sold as checkboxes. Bring your requirements to the Advisory desk or the team Chat, and the full comparison lives at vendorbenchmark.com/deployment.

01 · Cloud (available today)

The managed multi-tenant platform described at the top of this chapter. Live the same day, always current, full benchmark network access, Enterprise controls (SSO, SCIM, MFA, audit) on by default, and the lowest cost of the four. The trade-offs are the ones inherent to shared infrastructure: isolation is enforced in the database rather than by separate hardware, the hosting region is ours, and contract files are processed outside your network perimeter, encrypted and access-logged.

02 · Dedicated cloud (Enterprise agreements)

A single-tenant deployment provisioned and operated exclusively for you: dedicated database, dedicated file storage, dedicated encryption keys, your own subdomain or custom domain, hosted in the region your policy requires. It answers the two requirements shared multi-tenancy cannot: data residency mandates, and security policies that rule out a shared database regardless of how it is isolated. Still zero operations work for your team; updates arrive on an agreed maintenance cadence rather than continuously, and it is priced as a dedicated environment above the standard plans. Time to first benchmark: days.

03 · Hybrid connector (Enterprise early access)

For a hard "documents cannot leave the network" policy. A lightweight connector (one container) runs inside your environment and reads contracts locally: it extracts the commercial terms, shows your team exactly what it found, and sends only the figures you approve to the cloud for benchmarking. The documents themselves never cross your boundary, and you still get the full market comparison, negotiation targets, and renewal calendar. Document-centric features (clause-level review, full-text document search) run reduced or stay local, and your team operates and updates the one connector. Time to first benchmark: weeks, including your security review.

04 · Self-hosted (by arrangement)

The full platform inside your own boundary, for defense, government, and the strictest financial mandates. We deliver versioned releases your team deploys into your own cloud account or data center, with our runbooks and support; your team owns upgrades, backups, scaling, and restores, audit events stream straight into your SIEM, and market data arrives as periodic snapshots rather than a live network connection. It is the most control and the most work of the four, which is why it is scoped as a joint engagement. Time to first benchmark: months.

The four at a glance

CloudDedicated cloudHybrid connectorSelf-hosted
Best forMost teamsResidency mandates, no shared databaseDocuments cannot leave the networkAir-gapped and sovereign environments
Who operates itUsUs, on your dedicated infrastructureYou run one connector, we run the restYour team, with our support
Contract files liveOur encrypted cloud storageYour dedicated storage, your keys, your regionInside your network, never uploadedYour infrastructure, entirely
UpdatesContinuousAgreed cadenceCloud continuous, connector by youVersioned releases you apply
Benchmark networkFullFullFull, for approved figuresPeriodic snapshots
Time to first benchmarkSame dayDaysWeeksMonths

Related: Trust center · Plans, allowances & limits


This is the last chapter. Back to the manual index.

Was this page helpful?

Thank you. Your note goes straight to the team that writes this manual.

Updated 2026-07-26 · A VendorBenchmark product · Download the manual as PDF · Questions? Message our team in the app.