VendorBenchmarkUser manual PDFOpen the app →

17 · The owner's handbook

Chapter 06 documents every settings page. This chapter is the same territory walked as work: what an organization owner actually does, in order, to take a workspace from empty to properly run. The core setup is one sitting of about an hour; the rest of the chapter is the decisions that deserve more thought and the cadence that keeps the workspace governed after the first week.

Everything here needs the owner role. If a settings page is managed by owners and you are not one, the page itself says who to ask, and any member can check who owns the workspace at the foot of the navigation rail.


Before you begin

Five minutes of gathering saves the sitting from stalling. Have ready:

  1. The teammate list: names, emails, and who gets which role. Roles are assigned per person at invite time and changed inline later.
  2. Your logo as an image file, if you want exported briefs and decks co-branded.
  3. Your plan facts: what the workspace is on and what that includes. Billing states the plan, allowances, and seats; Chapter 10 is the full matrix. Two gates worth knowing before you promise features to the team: single sign on, SCIM, and the API ship on the Enterprise plan, and analyst benchmarks outside a plan that includes them are added per proposal as benchmark credits.
  4. Your organization's answer to two policy questions, even provisionally: how long contracts should be retained after upload, and whether you contribute anonymized data to the community benchmarks and outcome network. Both live under Data controls and both default to the conservative choice until you decide.
  5. If SSO is on your path: whoever administers your identity provider.

The first hour

Work top to bottom. Every step is reversible except where marked, and the Settings home vitals will confirm your progress: anything reading Off or 0 is a gap this sitting closes.

Settings home, the workspace vitals
  1. Secure your own account first. Security: register your authenticator, turn on two-factor, store the backup codes. You are about to hold the keys to everyone's access; your account is the one that must not fall.
  2. Set the workspace identity. Branding: upload the logo so exported CFO briefs and boardroom decks carry it. Display currency: pick the currency your team enters amounts in. It relabels nothing retroactively and never converts a number; benchmarks stay in USD so market comparisons hold.
  3. Bring the people in. Members: invite one by one with a role each, or paste up to 50 addresses for a batch with one role. Invitations expire after 7 days and a resend restarts the clock. Decide domain capture while you are here: letting anyone on your email domain request to join replaces ad hoc invite requests with a queue you approve.
  4. Create the teams you will need for confidentiality. Teams: named the way the company organizes (Procurement, Finance, Legal). A team is an access unit: grant a restricted contract to the team once, and joining or leaving the team is the access change itself. Set these up before the first sensitive document arrives, not after.
  5. Decide whether deals need sign-off. Deal approvals is off by default. If your organization requires a documented approval step before signature, turn it on and name up to ten approvers. If it does not, leave it off; an empty ceremony helps nobody.
  6. Set the notification stance. Notifications: everything about renewals is strictly opt-in and starts silent, so the workspace never spams a team into filtering it. Turn on what you personally want (Turn on money-critical alerts switches on the renewal set in one click), then tell the team the same control exists for them; each person chooses their own. Owners additionally set the AI copilot rules and can post alerts into a Slack or Teams channel once one is connected.
  7. Load the sample portfolio, then plan its removal. From the dashboard, sample data gives every screen something to show while the team explores. Remove it before real data lands; Troubleshooting covers the cleanup if it lingers.

The hour is done when: the vitals on Settings home show two-factor On, people holding seats, and nothing urgent under Worth doing now.

Security defaults worth setting in week one

None of these blocks the first hour, and all of them are cheaper to set before habits form.

  1. Require two-factor for everyone. The organization policy lives on the same Security page as your personal setup. Turn it on once the team has had a day to register authenticators; from then on new members are held at setup until they comply.
  2. Set retention deliberately. Data controls: a retention period auto-deletes contracts a set number of months after upload, rows and files both, with a deletion certificate written for each sweep. Blank means keep until deleted, which is the right answer for most estates; set a number only if your records policy requires one.
  3. Answer the consent question. The community and outcome network toggle is also under Data controls. Contributing anonymized data sharpens the benchmarks everyone draws on; opting out is one switch and entirely respected.
  4. Know your audit surface before you need it. Audit log: who did what, including file views and downloads as separate events, exportable as CSV, streamable to a SIEM via webhook. Nothing to configure on day one beyond knowing it is there; security teams that want the stream set it up under Integrations.
  5. Network and session policy is available, and sharp. Under Security baseline, owners can pin the workspace to known networks (IP allowlist) and bound session lifetimes. The allowlist refuses to switch on unless your own address is covered, but an office IP change later still locks everyone out until the policy is fixed from an allowed network. Prefer ranges over single addresses, and skip this control entirely unless policy demands it.
Data controls: retention, certificates, consent

The single sign on decision

Single sign on is worth a considered yes or no rather than a default. The short version:

Single sign on and SCIM provisioning

Bringing the estate in

The owner's part of data-in is choosing the door and clearing the way; Chapter 15 covers the team's part, and Chapter 18 is the full guide: the four doors compared, spreadsheets and registers, coming from another tool, and the migration FAQs.

  1. A handful of documents: no ceremony. Upload a proposal for anything that needs benchmarking; Agreements for signed contracts with dates to watch.
  2. A folder, up to a few hundred files: Contracts. Anyone can run it; nothing about it is owner-gated.
  3. A whole estate, hundreds to thousands: Enterprise Uploader, which is owner-run precisely because it writes thousands of records. Everything stays in staging, invisible to alerts and agents, until you sign it off against a quality bar; the sign-off writes to your audit log with the scorecard attached. It is open to every organization, in the Contracts group on the rail under Phase 1 · Bring it in.
  4. Then connect the systems that keep it current. Integrations: contract intake rails, the SAM and ITAM sources that know entitlements and deployments, procurement, and the invoice forward-in address. Connect your data and close the gaps is the recipe, and Data health is the scoreboard that says when you are done.
The Enterprise Uploader: one door for the whole estate, and the run opens on the first drop

The governance cadence

A well-run workspace needs about an hour a month after setup, on three clocks.

Access reviews: snapshot, decide every line, store the attestation

When someone leaves

Offboarding is three moves, in this order, all on Members:

  1. If they are the only other owner, promote a replacement first. The platform refuses any change that would leave the workspace without an active owner.
  2. End access: remove them (or block, if the seat should stay reserved). Either signs them out everywhere immediately. For a lost laptop rather than a departure, Sign out alone ends every session without touching the seat.
  3. Let structure do the cleanup. Team memberships die with the member, and every confidential grant held through a team dies with the membership; nothing to sweep per document. The next quarterly access review confirms the surface is clean.

A member leaving of their own accord needs nothing from you: anyone can leave a workspace from the bottom of their own Profile.

The quarterly owner checklist

The standing review, one screen per line. Thirty minutes, four times a year.

Standing?The checkWhere
Access review completed and storedAccess reviews
Two-factor coverage is full, or the policy explains why notSecurity posture
No pending invitation is stale, no seat is unaccounted forMembers
Team rosters match how the company actually organizes todayTeams
Audit log skimmed: member changes and file downloads look rightAudit log
API keys are all known and in useAPI
Connected integrations synced recently, none silently failingIntegrations
Retention and consent settings still match policyData controls
Plan and allowances still fit how the team actually uses the platformBilling

Related: Set up your workspace · Settings & account · Your first 30 days

Next: Chapter 01 · Contracts & renewals

Was this page helpful?

Thank you. Your note goes straight to the team that writes this manual.

Updated 2026-08-18 · A VendorBenchmark product · Download the manual as PDF · Questions? Message our team in the app.