# Third-party management

A third party represents an external organization that provides a product or service, processes data, or otherwise contributes risk to your compliance program.

## What to record

Keep the vendor record focused on the relationship, not only the company name:

- business and security contacts;
- services used by your organization;
- data and operational dependencies;
- DPA, BAA, and compliance-report status;
- parent, child, and subprocessor relationships;
- risk assessments and their expiry dates.

The hierarchy distinguishes a direct vendor from downstream parties. This makes it possible to review concentration and subprocessor risk without flattening every provider into one list.

## Assessment lifecycle

An assessment belongs to a third party and records the review performed for that relationship. Probo can run asynchronous vendor vetting to gather supporting information, but the resulting material still requires human review. Publish a third-party list only after ownership and relationship data are accurate.

To disclose approved downstream providers to customers, see [Publish subprocessors in the Compliance Portal](/docs/product/compliance-portal/subprocessors).

## Access and automation

Third-party records are available through the web console and automation interfaces. Use [access reviews](/docs/product/access-review/overview) for identities imported from connected applications; use third-party management for the contractual, privacy, and operational relationship with the provider itself.

- [CLI thirdparty](/docs/developers/cli/commands/thirdparty) — Manage vendors and related records with prb thirdparty
- [MCP third parties](/docs/developers/api/mcp/tools/catalog/third-parties) — Operate third-party records from supported AI tools
- [n8n Third Party](/docs/developers/api/n8n/resources/third-party) — Automate vendor workflows in n8n
