Skip to main content

Community Review Sharing

Learn how to share supplier review signals and details securely with other organisations in your Risk Ledger community.

Written by ish

What is community review sharing?

Community review sharing helps organisations collaborate on suppliers they have in common. You can see review activity from other community members, use their insights to support your own review, and reduce duplicated work.

Sharing is optional and controlled by the organisation that owns the review information. Your organisation decides what to share, with which community, and whether other members can see details automatically or must request access.

šŸ’” Community Review Sharing is available only in communities where Risk Ledger has enabled the feature. It applies to suppliers with a full connection that are part of the relevant community network. Please reach out to your CSM if you would like to enable Community Review Sharing.


What information can be shared?

Depending on the sharing settings selected, community members may be able to see:

  • Review notes and recommendations

  • Open risks

  • Remediation actions

  • Private notes

  • Control notes

  • Control overrides

  • Supplier labels

Supplier assessment answers and evidence aren't shared through community review sharing.

The information shown reflects its current state. For example, if a risk or remediation is updated after access is granted, viewers will see the updated information.


Community sharing access levels

There are three access levels:

Shared with community

Community members can see review signals and the review detail categories your organisation has chosen to share. You must select at least one detail category.

Access on request

Community members can see high-level signals, such as whether a review exists, its recommendation, and counts of open risks or remediations. They must request access to see the review details your organisation allows.

Your organisation can approve or reject each request and choose the information available to that organisation. You can also grant access without waiting for a request.

No access

Community members can see that your organisation is connected to the supplier, but they can't see review signals or request review details.

šŸ’” Your organisation may share the same supplier differently in different communities. If two organisations share more than one community, the most permissive applicable setting currently determines what can be viewed.


Set your organisation's default sharing preferences

Your organisation's setting applies by default to eligible suppliers in each community.

  1. Open Settings [1] > Review sharing [2]

  2. Select the relevant community [3]. Communities where review sharing isn't enabled appear unavailable

  3. Choose Shared with community, Access on request, or No access [4]

  4. If applicable, select the review detail categories you want to share

  5. You can also manage which community members have access granted [5]

Your changes save automatically.

šŸ’” Changing your organisation's default doesn't replace an existing supplier-level override. Suppliers with their own settings continue to use those settings until you revert them.


Change sharing for a specific supplier

You can make a supplier's sharing settings more or less permissive than your organisation's default.

  1. Open the supplier's overview page.

  2. Open the menu in the top-right corner and select the review sharing option. [Confirm final menu label before publishing.]

  3. Choose the relevant community.

  4. Select the access level and, if applicable, the detail categories you want to share.

When a supplier has a different setting from your organisation's default, Risk Ledger shows an override message. Select Revert to remove the supplier-level setting and make the supplier follow your organisation's default again.


View community review signals

When a supplier is in one or more eligible communities, the supplier overview shows a separate community signals panel for each community.

The panel can show:

  • Peer connections and pipeline statuses

  • Completed reviews and review recommendations

  • Open risks

  • Open remediations

  • Active overrides

Select an item in the panel to open the signals drawer. You can filter community members by organisation, pipeline status, review status, review recommendation, or open actions.


Request access to review details

If another organisation uses Access on request:

  1. Open the supplier's community signals panel.

  2. Select the organisation whose review you want to view.

  3. Select Request access.

  4. Wait for the organisation to approve or reject the request.

The organisation receives an email when you request access. If access is approved, you'll receive a confirmation email and can open the permitted review details from the organisation's signal card.

You can request access again after a rejection. A rejection doesn't send a notification.


Who can manage or view sharing?

  • Lead and Admin roles can manage organisation defaults and supplier-level sharing settings.

  • Edit roles can manage sharing for suppliers they can edit.

  • View roles can't change sharing settings, but they can view available signals and details and request access.

Custom roles may have additional permissions configured by your organisation.


Important things to know

  • Sharing settings are configured separately for each community.

  • The most specific setting applies within a community: community default, then organisation default, then supplier override.

  • Across communities shared by the same two organisations, the most permissive applicable setting currently wins.

  • If a supplier becomes a basic connection or leaves the community network, review signals and details are no longer available.

  • If an organisation leaves a community, its shared review information is no longer available to that community.

  • If access granted to a specific organisation is removed entirely, that organisation receives an email. Removing only some shared categories doesn't trigger an email.


šŸ’” If there is anything we haven't covered, please feel free to contact us at support@riskledger.com or alternatively, select the Chat icon in the bottom right corner.

Did this answer your question?