Vendor Management

Nicolas Audet
Nicolas Audet
  • Updated

Vendor Management allows you to give external vendors secure access to gaiia so they can manage and complete field work on your behalf — without exposing internal operations or other vendors’ data.

Overview

Vendor Management ensures that external subcontractors can operate independently in gaiia while remaining fully scoped to their own data.

Vendor users can:

  • View and manage their assigned work orders
  • Access their own technicians
  • Dispatch and schedule work

Vendor users cannot access:

  • Internal ISP work orders
  • Internal ISP technicians
  • Other vendors’ work orders or technicians
  • Cross-vendor operational data

This separation is enforced using Roles, Policies, and Vendor Tags.

 

Understanding roles and policies

Roles: What a user can do

Roles define which areas of gaiia a user can access. They are groups of permissions configured by your admin.

Examples of role permissions:

  • Workforce > Work Orders > View
  • Workforce > Work Orders > Edit
  • Workforce > Technician > View
  • Schedules > View + Edit

A vendor dispatcher role may allow viewing work orders, viewing technicians, and scheduling.

Policies: What a user can see

Policies apply a secure data filter on top of role permissions.

Even if a role allows access to Work Orders and Technicians, the policy ensures the user only sees records associated with their vendor.

Roles grant access. Policies restrict scope.

It is critical to assign a Policy when creating a vendor user. Without a policy, the user will see all data permitted by their role.

Vendor tags

Vendor Tags are applied to Work Orders and Technicians to define visibility.

When a Work Order or Technician is tagged with a vendor:

  • The vendor can see it
  • The ISP can see it
  • Other vendors cannot see it

Internal ISP technicians and internally completed Work Orders remain untagged and are not visible to vendors. Only Work Orders and Technicians are assigned vendor tags, if permissions are provided for other areas of gaiia (ex. Tickets), the vendor will be able to see ALL company data. 

Work orders and vendor tags

How vendor tags are applied

Vendor tags can be applied:

  • Automatically during auto-assignment flows
  • Manually by ISP users

Automatic tagging

If auto-assignment is enabled (Checkout, Client Portal, or Technician modal), vendor tags are automatically applied when appropriate.

The system ensures that:

  • Vendor dispatchers can only assign from their vendor’s technician list
  • ISP dispatchers can assign across vendors and internal teams

Manual tagging

ISP users can manually apply or update Vendor Tags on Work Orders.

This is commonly used for:

  • Manually created Work Orders
  • Jobs assigned to a specific vendor

Vendor tag modification rules

Vendor tags can only be modified if no technician is assigned.

Allowed:

  • Work Order is unassigned
  • Vendor tag can be added or changed

Not allowed:

  • Work Order has an assigned technician
  • Vendor tag change is attempted

If a tag change is required:

  1. Unassign the technician.
  2. Update the Vendor Tag.
  3. Reassign the correct technician.

The system blocks vendor tag changes when a technician is assigned.

 

Schedule visibility

Vendor users see a scoped Schedule view:

  • Only vendor-tagged technicians appear
  • Only vendor-tagged Work Orders appear
  • The schedule condenses automatically (no empty lanes)

Internal ISP users retain full visibility across vendors and internal teams.

 

Accessing restricted records (404 behavior)

If a vendor attempts to access a record outside their scope:

  • A 404 page is displayed

This may occur via:

  • Direct URL access
  • Links
  • Search results

This behavior confirms that policy scoping is functioning correctly.

 

Creating vendor users

To create a vendor user:

  1. Navigate to Settings > Users.
  2. Click New User.
  3. Assign the appropriate Role.
  4. Assign the appropriate Policy (Vendor name).

If a new Policy is required or changes are needed, contact support@gaiia.com.

Creating a vendor technician

A vendor technician requires both:

  • A gaiia User profile
  • A Technician profile

Required flow:

  1. Create the User (with Role + Policy).
  2. Navigate to Workforce and click New Technician.
  3. Select the existing User.
  4. Complete required fields and click Create.

Make sure to create the User profile before the Technician profile. A technician’s Vendor Tag cannot be edited after creation. External vendor users require both the User layer to have an applied policy and the technician layer. 

If an incorrect tag is assigned:

  • Delete the technician profile and recreate it with the correct Vendor Tag, or
  • Contact support@gaiia.com if record continuity is required.

Vendor users can:

  • View their vendor’s technician list (pre-filtered)
  • Access their technicians’ profile pages

Internal ISP technicians remain invisible to vendors.

Do not use the “External” technician flow. It does not provide mobile app access.

 

Security best practices

Do not provide vendors with your API Key. Sharing your API Key can expose sensitive business data.

Always:

  • Assign a Policy to every vendor user
  • Avoid granting Admin-level permissions to external users
  • Avoid granting access to Analytics, or Reporting modules

Was this article helpful?

Have more questions? Submit a request