Fruxon logo
Fruxon
Back Office

Onboarding a vendor is twelve documents and four sign-offs.

Document completeness, KYC and sanctions checks, policy attestations, annual renewals. An agent assembles the file, checks what can be checked, and puts a human signature where the rule says a human signs.

Why the file is always almost complete

A control that only works when somebody remembers isn't a control.

The insurance certificate expired in April, the attestation was never countersigned, the beneficial-owner form is in an email thread rather than the file. None of it was negligence; it was twelve documents across four people with no single owner and no deadline that anybody feels. The gap is invisible right up until the moment an auditor asks for the file.

A vendor file, end to end

What happens between “we're using them” and “they're approved”.

It opens the file where your process keeps it

A request in your workflow tool, a folder in Drive or SharePoint, a row in the vendor master. It reads the policy that applies to this category of vendor rather than a generic checklist.

It chases what's missing, from whoever owes it

The vendor, or the internal sponsor who has been meaning to send it. On the channel that person reads, on a cadence you set, checking what comes back against what the policy actually required.

It checks what can be checked

Registry lookups, sanctions and watchlist screening through the sources you subscribe to, expiry dates on certificates, whether the countersignature is actually there. Findings are recorded with the source and the date, not summarised away.

A person signs the things that need signing

The compliance owner gets the assembled file, the findings and what's outstanding, and approves — or doesn't. The approval, the approver and the evidence stay attached to the record as an immutable revision.

What that needs underneath

Evidence that survives the question “how do you know?”.

Every finding cites its source

A screening result records what was queried, against which source, on what date, and what came back. A summary without a source is an opinion, and an opinion doesn't close a finding.

Renewals are runs, not reminders

Expiry dates become scheduled runs per vendor. The file is re-checked on the same schedule whether or not the relationship manager is still at the company.

Immutable revisions, exportable trail

Every save is a revision, every run is traced end to end, and the record of who approved what and when exports for the audit rather than being reconstructed for it.

Where a human signs

The agent assembles the case. It doesn't approve the vendor.

That separation is deliberate and it isn't a limitation — an approval is a person accepting responsibility, and there is no version of this where that gets delegated to software. What the agent removes is the four weeks of chasing and cross-checking that happen before somebody is in a position to decide, and the uncertainty about whether the file was actually complete when they did.

Human signature required on approval, with the approver named on an immutable record

Two-stage approval where your policy calls for it, with a fallback ladder and timeouts

Findings escalate to the owner of that risk area rather than to a compliance inbox

Sandbox Mode until you're satisfied, including read-through against live sources

Systems

Your document store, your vendor master, your screening sources.

Connect a system once for the whole organization and every agent can use it from then on — with credentials held at the org and referenced by name, never pasted into a prompt.

Slack

GitHub

Jira

Google Drive

Salesforce

MongoDB

Notion

Linear

Grafana

Discord

Google Chat

Confluence

PostgreSQL

HubSpot

Airtable

Shopify

Stripe

Datadog

Sentry

GCP

BigQuery

Slack

GitHub

Jira

Google Drive

Salesforce

MongoDB

Notion

Linear

Grafana

Discord

Google Chat

Confluence

PostgreSQL

HubSpot

Airtable

Shopify

Stripe

Datadog

Sentry

GCP

BigQuery

Google Calendar

Gmail

Mixpanel

Monday

MySQL

SAP

Zendesk

Zoho CRM

Google Maps

Google Ads

Coralogix

Telegram

Apollo

Mailchimp

Calendly

Redis

Supabase

GCP Logging

gVisor

Loops

Typeform

Google Calendar

Gmail

Mixpanel

Monday

MySQL

SAP

Zendesk

Zoho CRM

Google Maps

Google Ads

Coralogix

Telegram

Apollo

Mailchimp

Calendly

Redis

Supabase

GCP Logging

gVisor

Loops

Typeform

Don't see yours? Import tools from any MCP server or request an integration.

Compliance questions, answered plainly

Assume your auditor is reading this section over your shoulder.

No, and it shouldn't. It assembles and checks; a named person approves through a gate, and that person is the approver on the record. Where your policy requires two signatures, the ladder supports two.

The sources you already subscribe to, connected as tools. The agent doesn't have private knowledge of sanctions lists — it queries yours and records the query, the source and the date alongside the result.

Findings carry their source, so a summary is checkable against the document it came from rather than trusted on its own. Changes to the agent can be gated behind evaluations run against your own historical files before they deploy.

That's the strongest case for it. Expiry dates become scheduled runs per vendor, so the re-review happens on time for every vendor rather than for the ones somebody remembered.

Build the agent. We'll run the rest.