Vanta keeps track of compliance and security controls, for example ISO 27001 and SOC 2. Tenders ask about exactly this. With the Vanta connector the AI agent can pull the answers from Vanta instead of you having to find them yourself.
The connector is available on paid plans. You connect with your own Vanta account, and the agent only gets access to what you can already see and do. You use the connector through the agent, so you need the administrator or member role. Contributors don't have access to the agent. Read more about roles and permissions.
What the agent can do
Look up controls, policies and risks.
See the status of your compliance work.
Use that content when the agent answers security questions in a tender.
Vanta decides which tools are available, and your own permissions decide what the agent gets to see. You can see the list on the integration card once you have connected.
First: an administrator picks the region
Vanta runs in several regions, and we can't see which one you belong to. So an administrator has to pick the region before anyone can connect. It's a one-time job.
Go to "Settings" → "Integrations", find Vanta and click "Configure".
Choose "EU" or "US" under "Region". If you're unsure, look at the address you sign in to in Vanta, or ask Vanta.
Click "Save setup".
If you pick the wrong region, nobody can connect. If the administrator changes the region later, everyone in the workspace has to connect to Vanta again.
How to connect
Go to "Settings" → "Integrations".
Find Vanta under "Personal" and click "Connect".
Sign in to Vanta and approve access.
When you return to Cobrief, you can see which account is connected.
Connecting from the settings turns the connector on for new conversations. Conversations you have already started keep their current setting. You can also connect from the "Connectors" menu inside a conversation. That turns the connector on for that conversation.
Use Vanta in a conversation
Open the "Connectors" menu in the agent and turn Vanta on for the conversation. For example, you can ask the agent to:
"What's the status of our ISO 27001 controls?"
"Find our access control policy and summarise it."
"Answer the security questions in this tender based on Vanta."
Choose what the agent may do
The tools from Vanta fall into two groups: those that only read, and those that can change or delete something. By default the agent may read freely, while anything that changes something needs your approval in the conversation. The agent shows you what it wants to do, and you choose "Approve" or "Reject".
Administrators can change this for the whole workspace under "Settings" → "Integrations" → Vanta. Each group and each individual tool can be set to "Always allow", "Needs approval" or "Blocked". Other users can see the settings but cannot change them.
Disconnect or reconnect
Go to "Settings" → "Integrations", find Vanta and click "Disconnect". The agent then loses access to your Vanta account. You can connect again whenever you like.
If access expires or is revoked, Cobrief shows "Requires new sign-in". Click "Reconnect" to continue.
Administrators can also click "Remove setup" on the Vanta card. Everyone in the workspace then loses their connection, and the connector disappears until the setup is added again.
Security
The agent uses your own sign-in with Vanta and never reaches further than you do yourself. Content is fetched while the agent works, and we don't keep a copy of your Vanta data. Answers and documents the agent produces are stored in Cobrief as usual.
Read more about how we work with security and privacy in our Trust Center.
Can't connect?
If you don't see Vanta under "Integrations", the region hasn't been picked yet. Ask an administrator to do it.
If everyone's sign-in fails, the wrong region is probably selected. An administrator can change it under "Configure".
Always check what the agent pulls from Vanta before you submit it in a bid. You are responsible for what the response says.

