Skip to content

Role-Based End-to-End Scenarios

Scenario A — Onboarding a new vendor and receiving their first SBOM

  • Organization: invites the vendor from the Vendors page, optionally assigning a product at the same time.
  • Vendor: receives the invitation email, activates their account, and completes the three-step onboarding wizard, uploading their first SBOM for the assigned product.
  • Organization: sees the SBOM appear on the Vendor detail page and the Product detail page; any critical vulnerabilities appear in the Vulnerability Queue automatically.

Scenario B — A critical CVE is discovered in a customer-deployed product

  • Organization: reviews the CVE in the Vulnerability Queue, checks CVSS/EPSS/KEV signals, and confirms which customer deployments are affected on the CVE detail page.
  • Organization: sends a notification through the three-step wizard, selecting the affected product and reviewing the affected-customer preview before sending.
  • Customer: receives the advisory in their Security Inbox, marks it Investigating, and later confirms Mark as Patched once the fix is applied.
  • Organization: tracks the alert workflow on the Notification detail page until resolution.

Scenario C — A customer's scanner flags a CVE the organization hasn't disclosed

  • Customer: submits a VEX Request from My Deployments or the New VEX Request form, describing the CVE and deployment context.
  • Organization: reviews the request in the VEX Request Inbox, investigates using the checklist and any existing VEX statements, and submits an official VEX response.
  • Customer: receives the VEX document by email and in the portal, viewable on the VEX request's detail page, and can load it directly into their own scanner.