Enterprise readiness
Contractor Hub security and procurement overview
A concise starting point for commercial, IT, security and procurement teams reviewing a VariationDesk Contractor Hub deployment. Project-specific questionnaires and identity-provider setup are handled as part of enterprise onboarding.
Tenant isolation
Subcontractor and main-contractor organisations remain separate workspaces. Cross-company access is created only through explicit project relationships and per-variation submission.
Project-scoped access
Contractor Admins can give commercial users whole-portfolio access or limit them to selected Contractor Hub projects.
Role-aware decisions
Contractor Admin, Commercial Manager, Project Commercial and Viewer roles keep team management, supplier management and commercial decisions separated.
Two-step verification
Main-contractor workspaces require VariationDesk two-step verification. Enterprise SSO can be configured for qualifying Contractor Hub deployments.
Immutable submissions
Each external variation submission is stored as a numbered immutable revision with an integrity hash; later corrections create another revision rather than silently replacing what was sent.
Controlled supplier sharing
Subcontractors decide which authorised variation is sent and can further reduce evidence, commercial-value and quotation visibility for that submission.
Audit and exports
Contractor Hub provides commercial-register CSV, immutable-event audit CSV and pilot/outcome PDF exports, subject to the user's project permissions.
Lifecycle retention
Closing or archiving a contractor project stops active workflow while retaining appropriate historical submission and decision records.
Enterprise review pack
For a live procurement or security review, VariationDesk can provide the current Data Processing Addendum, sub-processor information, security information, deployment scope and customer-specific SSO setup details. SAML identity-provider metadata must be exchanged and configured before SSO enforcement is switched on.