> ## Documentation Index
> Fetch the complete documentation index at: https://docs.assetinfinity.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# The vendor portal

> What a login for another company's people can see — their own jobs and orders, and nothing more.

A way to give a contractor or supplier a login of their own, narrowed to their own work, rather than
relaying everything through email and phone.

## Marking a role external

A **role**, not a person, is what's marked external — under [roles](/setup/roles). Anybody holding
that role gets the narrowed portal instead of the ordinary navigation, which is what lets one tenant
run both its own staff and a handful of contractor logins without a special case for each person.

<Warning>
  A role held by your own people cannot be marked external — the system refuses it and names who
  holds it. Ticking it would put your own staff outside the company as far as permissions are
  concerned: a narrowed navigation, no internal notes, and only their own supplier's work visible.
</Warning>

## What the portal shows

Three destinations, and nothing else:

| Screen | What's on it |
| - | - |
| **Work orders** | Jobs assigned to their company — their own, not the site's |
| **Purchase orders** | Orders sent to their company, read-only |
| **Messages** | Conversations they've been brought into — they reply in a thread, they don't start one |

From a job assigned to them, a vendor contact submits a **quote** before the work and an **invoice**
after it — see [vendor invoices](/commercial/vendor-invoices) for how those are reviewed and accepted
on your side. Nothing they submit touches your stock or your cost ledger until somebody on your side
accepts it.

## What it doesn't show

Everything else in the product is simply absent rather than present and refusing — no internal notes
on a job, no other company's work, no settings, no reports. In particular, a supplier never sees:

* The **cost** you're charged internally, or what a repair is costing you beyond their own invoice.
* **Warranty or entitlement** decisions — whether a repair is covered, and by which agreement.
* **Replacement or disposal dates**, or anything else from the asset record beyond what their job
  needs.

That boundary is what makes a contractor login worth issuing in the first place: what "our" data they
can see is decided once, by the role, rather than trusted to whoever remembers to hide a field.

<Card title="Vendors" icon="handshake" href="/commercial/vendors">
  Approving a vendor before any of this applies to them.
</Card>

<Card title="Roles" icon="users" href="/setup/roles">
  Marking a role external, and what that changes.
</Card>
