Scenario A — Onboarding a new vendor and receiving their first SBOM¶
Organization: invites the vendor from the Vendors page, optionally assigning a product at the same time.
Vendor: receives the invitation email, activates their account, and completes the three-step onboarding wizard, uploading their first SBOM for the assigned product.
Organization: sees the SBOM appear on the Vendor detail page and the Product detail page; any critical vulnerabilities appear in the Vulnerability Queue automatically.
Scenario B — A critical CVE is discovered in a customer-deployed product¶
Organization: reviews the CVE in the Vulnerability Queue, checks CVSS/EPSS/KEV signals, and confirms which customer deployments are affected on the CVE detail page.
Organization: sends a notification through the three-step wizard, selecting the affected product and reviewing the affected-customer preview before sending.
Customer: receives the advisory in their Security Inbox, marks it Investigating, and later confirms Mark as Patched once the fix is applied.
Organization: tracks the alert workflow on the Notification detail page until resolution.
Scenario C — A customer's scanner flags a CVE the organization hasn't disclosed¶
Customer: submits a VEX Request from My Deployments or the New VEX Request form, describing the CVE and deployment context.
Organization: reviews the request in the VEX Request Inbox, investigates using the checklist and any existing VEX statements, and submits an official VEX response.
Customer: receives the VEX document by email and in the portal, viewable on the VEX request's detail page, and can load it directly into their own scanner.