AI Vendor Onboarding Policy
Every vendor your agents can pay needs an onboarding step. This policy makes it explicit.
The policy
1. Request — engineer submits vendor with category and expected spend.
2. Review — procurement checks reputation, pricing, and contract.
3. Approve — vendor added to the allowlist with limits.
4. Monitor — audit log reviewed quarterly; limits adjusted.
5. Remove — offboarding when unused or risky.
What to record
Vendor, category, limits, owner, approval date, review date.
Enforcement
New vendor purchases = FLAGGED until the vendor is allowlisted.
Allowlisted vendor spend = enforced caps per category.
The policy runs itself.
FAQ
Who approves vendors?
Procurement or the budget owner — whoever owns vendor relationships.
What happens to unapproved vendor spend?
BLOCKED if hard-allowlist, FLAGGED if you use approval thresholds.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check