This article explains the four supplier invitation statuses in the Strategic Sourcing module, how the supplier login flow works from the supplier's point of view, and how to fix the most common access problems. An invitation is the personal, single-use link each supplier contact receives by email when a sourcing event is published; its status tells you whether the contact can still use that link.
Where can I see whether a supplier has accessed the event?
Supplier access is visible on the Supplier Responses page of the sourcing event. The metrics row shows Invited, Submitted, response rate, In Progress, and Not Started. Per supplier, the Login Status column shows Never logged in or Logged in, and Last Active shows the most recent activity (or "Never"). A supplier whose contacts have never logged in and whose status is Awaiting Response is the natural target for a reminder.
What do the invitation statuses mean?
Each invitation moves through a fixed set of statuses. The following table lists every status, what it means, and what happens next.
Status | Meaning | What happens next |
Pending | The invitation was created and emailed, but the contact has not opened the link yet. | The link works until it expires (30 days after creation) or is revoked. Send a reminder if the deadline approaches. |
Accessed | The contact opened the link and verified successfully at least once. | The contact can keep signing in; from now on they can also use the email login page directly. |
Expired | More than 30 days passed since the invitation was created, or its expiry date was reached. | The old link stops working. Send the contact a reminder; it issues a fresh valid link automatically. |
Revoked | The invitation was withdrawn. | The link is permanently dead. A new invitation is required for that contact to regain access. |
An invitation can additionally become blocked after 5 failed verification attempts; the supplier then sees "This invite has been blocked due to too many failed attempts. Please contact the buyer for a new invite."
How does the supplier login flow work?
Suppliers authenticate with a one-time password (OTP), a 6-digit verification code sent by email, instead of a permanent password. From the supplier's perspective:
The supplier opens the invitation link from the email. The Supplier Portal Access page explains that identity verification is needed.
The supplier selects Request Verification Code. A 6-digit code is emailed to the invited address; the code expires after 5 minutes.
The supplier enters all 6 digits on the Enter Verification Code screen and selects Verify Code. If the code expired, Request New Code sends a fresh one.
After successful verification the supplier lands directly in the sourcing event (behind the NDA screen first, if the event requires an NDA), and the invitation status changes to Accessed.
On later visits the supplier can also sign in at the Supplier Portal Login page by entering their email and requesting a code. This works only for contacts who have accessed at least one event via an invite link before.
Which limits protect supplier access?
Several fixed limits protect the invitation and login flow against abuse. The following table lists each limit and its exact value.
Limit | Value |
Invitation link validity | 30 days from creation |
Verification code length | 6 digits |
Verification code validity | 5 minutes |
Code requests per email address | 3 per 60-minute window |
Failed attempts before an invite is blocked | 5, with a growing cooldown between wrong entries |
Email-login lockout | 15 minutes after 5 failed login attempts |
Buyer reminders | 1 per contact per hour per sourcing event |
How do I fix common access problems?
Most supplier access problems map to one of the situations below, each with an exact fix:
"This invite has expired": the 30-day validity has passed. Open Supplier Responses and select Send Reminder for that supplier; the reminder automatically carries a fresh, valid link.
"This invite has been revoked": the link was withdrawn. If access should be restored, re-add the contact or send a reminder so a new invitation is issued.
"Too many failed attempts": the supplier hit the attempt cooldown or the 5-attempt block. Ask the supplier to wait and retry; if the invite is fully blocked, issue a new link via Send Reminder.
Verification email not received: first ask the supplier to check spam and wait a minute; codes count against the limit of 3 requests per hour, so repeated clicking exhausts the quota. Confirm the contact's email address is correct in the Suppliers step.
Wrong contact email: the invitation always goes to the email stored on the contact. Correct the contact (Manage contacts), then send a reminder so the corrected address receives its own link. Remove the wrong contact if the address should get no access.
"Invalid invite link": the URL was truncated or altered in the email client. Ask the supplier to copy the full plain-text link from the email, or send a reminder / copy the invite link from the row actions and share it directly.
Link from an earlier round: the supplier sees "Invite Link Outdated" and can select Resend Email themselves to receive their current-round link.


