Separate internal and supplier access
Buyers and administrators authenticate to a workspace. Suppliers use high-entropy, expiring, revocable tokens scoped to a specific order response. External routes do not expose workspace navigation or unrelated records.
Protect credentials and tokens
Passwords are hashed, sessions use secure cookie behavior in production, and response tokens are stored as hashes rather than reusable plaintext. Sensitive keys and provider credentials remain server-side environment configuration.
Control roles and provisioning
Workspace permissions protect ownership, administration, buyer operations, billing, and configuration. Scale supports SSO and SCIM surfaces for centralized identity and lifecycle control.
Make events and failures visible
Material order, response, decision, reminder, membership, and configuration changes create attributable audit records. Delivery and integration failures remain explicit rather than being represented as success.
Validate the workflow with one real purchase order
Before buying or replacing software, run one representative multi-line PO from reviewed source through supplier response and buyer resolution. Include at least one accepted line, one proposed date or quantity change, and one delivery or reminder edge case. Confirm that every participant can identify the current owner and next action, that the original order remains unchanged, and that the final commitment can be exported and traced to its response and decision. Also verify the supplier experience on a normal phone and desktop browser, revoke and reissue a response link, inspect a failed delivery, and test the role boundary with a non-owner buyer. This evidence is more useful than a feature checklist because it exposes adoption friction, hidden authority, and incomplete system boundaries before the workflow reaches production volume.
Keep source, proposal, decision, and commitment distinct
Pacteva records supplier responses and authorized buyer decisions. It does not silently alter the reviewed purchase order or claim an ERP changed unless a configured write-back is verified. Requisitions, budgets, receipts, invoices, payments, inventory, and shipping remain in their systems of record.
What buyers usually ask
Does a supplier token expose the workspace?
No. It is scoped to the assigned order response route.
Is SSO available?
SSO and SCIM are included in the Scale plan and require correct workspace configuration.
Does Pacteva claim compliance certification?
This page describes implemented controls and product boundaries; it does not claim an unverified certification.