Skip to main content

Supplier invitation statuses and access troubleshooting

What Pending, Accessed, Expired, and Revoked mean, and how to fix supplier access problems.

This article explains the four supplier invitation statuses in the Strategic Sourcing module, how the supplier login flow works from the supplier's point of view, and how to fix the most common access problems. An invitation is the personal, single-use link each supplier contact receives by email when a sourcing event is published; its status tells you whether the contact can still use that link.

Where can I see whether a supplier has accessed the event?

Supplier access is visible on the Supplier Responses page of the sourcing event. The metrics row shows Invited, Submitted, response rate, In Progress, and Not Started. Per supplier, the Login Status column shows Never logged in or Logged in, and Last Active shows the most recent activity (or "Never"). A supplier whose contacts have never logged in and whose status is Awaiting Response is the natural target for a reminder.

The Supplier Responses page showing the invited and submitted metrics, and per-supplier columns for status, login status, and last active date.

What do the invitation statuses mean?

Each invitation moves through a fixed set of statuses. The following table lists every status, what it means, and what happens next.

Status

Meaning

What happens next

Pending

The invitation was created and emailed, but the contact has not opened the link yet.

The link works until it expires (30 days after creation) or is revoked. Send a reminder if the deadline approaches.

Accessed

The contact opened the link and verified successfully at least once.

The contact can keep signing in; from now on they can also use the email login page directly.

Expired

More than 30 days passed since the invitation was created, or its expiry date was reached.

The old link stops working. Send the contact a reminder; it issues a fresh valid link automatically.

Revoked

The invitation was withdrawn.

The link is permanently dead. A new invitation is required for that contact to regain access.

An invitation can additionally become blocked after 5 failed verification attempts; the supplier then sees "This invite has been blocked due to too many failed attempts. Please contact the buyer for a new invite."

How does the supplier login flow work?

Suppliers authenticate with a one-time password (OTP), a 6-digit verification code sent by email, instead of a permanent password. From the supplier's perspective:

  1. The supplier opens the invitation link from the email. The Supplier Portal Access page explains that identity verification is needed.

  2. The supplier selects Request Verification Code. A 6-digit code is emailed to the invited address; the code expires after 5 minutes.

  3. The supplier enters all 6 digits on the Enter Verification Code screen and selects Verify Code. If the code expired, Request New Code sends a fresh one.

  4. After successful verification the supplier lands directly in the sourcing event (behind the NDA screen first, if the event requires an NDA), and the invitation status changes to Accessed.

  5. On later visits the supplier can also sign in at the Supplier Portal Login page by entering their email and requesting a code. This works only for contacts who have accessed at least one event via an invite link before.

The supplier-facing Enter Verification Code screen with six input boxes for the emailed one-time password and the Verify Code button.

Which limits protect supplier access?

Several fixed limits protect the invitation and login flow against abuse. The following table lists each limit and its exact value.

Limit

Value

Invitation link validity

30 days from creation

Verification code length

6 digits

Verification code validity

5 minutes

Code requests per email address

3 per 60-minute window

Failed attempts before an invite is blocked

5, with a growing cooldown between wrong entries

Email-login lockout

15 minutes after 5 failed login attempts

Buyer reminders

1 per contact per hour per sourcing event

How do I fix common access problems?

Most supplier access problems map to one of the situations below, each with an exact fix:

  • "This invite has expired": the 30-day validity has passed. Open Supplier Responses and select Send Reminder for that supplier; the reminder automatically carries a fresh, valid link.

  • "This invite has been revoked": the link was withdrawn. If access should be restored, re-add the contact or send a reminder so a new invitation is issued.

  • "Too many failed attempts": the supplier hit the attempt cooldown or the 5-attempt block. Ask the supplier to wait and retry; if the invite is fully blocked, issue a new link via Send Reminder.

  • Verification email not received: first ask the supplier to check spam and wait a minute; codes count against the limit of 3 requests per hour, so repeated clicking exhausts the quota. Confirm the contact's email address is correct in the Suppliers step.

  • Wrong contact email: the invitation always goes to the email stored on the contact. Correct the contact (Manage contacts), then send a reminder so the corrected address receives its own link. Remove the wrong contact if the address should get no access.

  • "Invalid invite link": the URL was truncated or altered in the email client. Ask the supplier to copy the full plain-text link from the email, or send a reminder / copy the invite link from the row actions and share it directly.

  • Link from an earlier round: the supplier sees "Invite Link Outdated" and can select Resend Email themselves to receive their current-round link.

Did this answer your question?