Supply Chain & Fulfillment AI

Vendor Management

Vendor Management is an ecommerce AI skill for Alireza Rezvani, built for teams working with Codex, Claude Code, OpenClaw. Use it to you need to prioritize stocking,…

Provider
Alireza Rezvani
Platforms
Codex · Claude Code · OpenClaw
View original link · GitHub

What this skill helps you do

Operational vendor performance review tool for BizOps, IT, and VMO operators tracking 80-200 SaaS subscriptions. Scores vendors 0-100 across reliability, support, security, commercial, and strategic-fit dimensions with industry-tuned weighting profiles. Tracks SLA compliance with trend classification and credit-claim eligibility, and classifies third-party risk across data sensitivity, financial exposure, operational dependency, and regulatory exposure vectors. Produces KEEP/REVIEW/REPLACE recommendations before renewal deadlines arrive.

Install and get started

Copy the full instructions into your AI tool. Test one low-risk example before connecting real store data.

Original Skill instructions

You are a BizOps/VMO operator. Provide vendor catalog JSON with name, category, annual_spend, criticality (tier-1/2/3), uptime_pct, support_response_hours_p90, incident_count, security_certs, renewal_terms. Run vendor_scorer.py --profile <saas|fintech|healthcare|enterprise> for 0-100 scoring. Verdict: KEEP ≥75, REVIEW 50-74, REPLACE <50. Run sla_compliance_tracker.py for compliance %, trend, credit-claim eligibility (breach_count ≥2 OR actual < target by >0.5pp). Run vendor_risk_classifier.py across data sensitivity, financial exposure, operational dependency, and regulatory exposure. Synthesize: top 3 KEEP, REVIEW, REPLACE; claimable credits; Critical-risk vendors without mitigation.

Useful tasks

  • Quarterly vendor scorecard preparation for leadership with KEEP/REVIEW/REPLACE verdicts
  • Tier-1 vendor incident review quantifying SLA gaps with credit-claim eligibility
  • CISO third-party risk matrix for the next audit cycle
  • 60-90 day pre-renewal defensible recommendation backed by scored data
  • Post-acquisition vendor coverage deduplication across two organizations

How to use it

  • Use healthcare profile for HIPAA-sensitive portfolios — regulatory exposure weight increases to 35%
  • Tier-1 without SOC2 = Critical risk — require SOC2 attestation before next renewal
  • SLA credit is claimable when breach_count_12m ≥ 2 OR actual_quarter < target by >0.5pp
  • Review vendors at least quarterly — reviewing only at renewal is too late to pivot
  • Fork context for large vendor catalogs (50-500 line items) so SLA logs don't pollute the parent thread

More skills for this workflow

Content checked: