Vendor management recipe
Vendor intake register with owner notification and requester receipt
“Verified” means checked against Google’s official Workspace Studio documentation — not that CertPilot has run this flow in a live Workspace.
Overview
What this recipe does
Each vendor request creates one intake record, one internal review notification, and one requester receipt; no approval or vendor-system action occurs.
Starter: When a form response comes in (your vendor intake Google Form)
Build
Steps
- Add the vendor to the intake SheetSheetsUse Sheets 'Add a row' to record the vendor, business purpose, requester, data type, proposed owner, renewal date, and review status from the Form response.
- Post the review handoff to ChatChatUse Chat 'Post in a space' to notify an existing vendor-review space with the minimum details needed to assign a human reviewer.
- Acknowledge the requesterGmailUse Gmail 'Send an email' to confirm that the intake was logged and explain that a human reviewer will make the decision outside the flow.
Data
Variables
- Vendor — Vendor or service name from the intake Form. (e.g. Acme Support)
- Business purpose — Why the service is requested. (e.g. Customer support knowledge base)
- Requester — Person submitting the intake. (e.g. owner@example.com)
- Data type — High-level data classification supplied by the requester. (e.g. Internal operational data)
Google Gemini
Describe it with AI
Paste this draft into Google Workspace Studio's Describe it with AI box, then review and adjust the flow it builds. This is Google's Gemini feature — CertPilot does not run any AI.
Before you start
Prerequisites
- An eligible Google Workspace edition with Workspace Studio and Gemini enabled by your admin.
- Access to Sheets, Chat, and Gmail (subject to your admin's Studio step controls).
- A vendor intake Google Form, a Vendor Intake Sheet, and an existing vendor-review Chat space.
Boundaries
Security & limitations
Security notes
- Do not collect passwords, API keys, contract files, payment-card data, or other secrets in the intake Form.
- Restrict the Sheet and Chat space because vendor, data-type, and commercial context may be sensitive.
- Subject to your admin's Studio controls, DLP, and external-user approval policy.
What it does not do
- Does NOT approve or reject the vendor — Workspace Studio has no business approve/reject step; a human decides out-of-band.
- Does NOT connect to the vendor, inspect its security posture, sign a contract, or create a purchase order.
- Chat cannot create a space — the flow posts to an existing one.
Verify
Test it safely
- Workspace Studio test runs take real actions — this test really adds a row, posts to Chat, and sends an email.
- Submit a fictional vendor using your own email, a test Sheet, and a test Chat space.
- Confirm that the acknowledgement says 'logged for human review' and does not imply approval.
Provenance
Official sources
Primary source
Official source
Guide to Starters & Steps in Workspace Studio
Published by Google · Source dated 3 December 2025 · Checked 26 August 2026
Last verified 26 August 2026
Related recipes