Vanta integration: Set up security reviews for procurement
Overview
The Vanta integration allows you to add a Vanta security review step to any Intake workflow in Ramp. This allows your security team to conduct their reviews in Vanta at whatever point in the workflow you choose. Vanta decisions and the comments attached to those decisions sync back to Ramp. Ramp uses the decision to advance or stop the request from being approved.
What you can do
- Trigger a Vanta review during a purchase request.
- Assign an owner to complete the review in Vanta.
- Add instructions and a due date for the reviewer.
- Auto-advance if the vendor has a current Approved or Conditionally approved decision in Vanta.
- Auto-stop if the vendor has a current Not approved decision in Vanta.
- See Vanta decisions and decision comments in the Ramp request.
Prerequisites
- Ramp: Permission to manage apps and edit Programs/Intake workflows.
- Vanta: Admin access to create a webhook and an OAuth application.
- At least one Program with an Intake workflow in Ramp.
Set up the Vanta integration
Step 1: Start the connection in Ramp
- In Ramp, go to Company > Integrations > Productivity.
- Select Vanta and click Connect.
Step 2: Create and connect a webhook in Vanta
- In Vanta, open the webhook settings.
- Subscribe to the events required for the integration.
- Paste the endpoint URL provided by Ramp.
- Create the webhook.
- Copy the signing secret from Vanta.
- In Ramp, paste the signing secret into the Vanta connection page.
Step 3: Create an OAuth application in Vanta
- In Vanta, open the Developer Console.
- Create a new application. Add a name and description, then save and click Manage.
- Copy the OAuth client ID.
- Generate and copy the client secret.
Step 4: Complete the connection in Ramp
- In Ramp, paste the client ID and client secret into the Vanta connection page.
- Click Finish. The integration is now connected.
Add Vanta to an intake workflow
Step 1: Open your program
- In Ramp, go to Manage Spend > Programs.
- Open the program you use for software procurement (or any program).
Step 2: Edit the workflow
- Go to the Intake tab.
- Edit the approval workflow.
- Click the plus (+) on the canvas and add the Security review > Vanta step.
Step 3: Configure the Vanta step
- Owner: Choose the person in Ramp who will start the review in Vanta.
- Instructions: Add any guidance the reviewer needs.
- Due date: Set a deadline for the review step.
Reviewer experience
- The assigned owner gets an email and a task on the Ramp home screen.
- Open the task to view the request details, then click Complete in Vanta.
- Clicking the button opens Vanta to start the review, add evidence, and set a due date.
- The reviewer chooses a decision in Vanta: Approved, Conditionally approved, or Not approved.
- Comments attached to the decision in Vanta sync back to the Ramp request.
How Ramp responds to the Vanta decision
- Approved or Conditionally approved: Ramp advances to the next step in the workflow.
- Not approved: Ramp rejects the request.
- Vendor has a current Approved or Conditionally approved decision in Vanta: Ramp skips the step and moves to the next step. Ramp records the prior decision in Activity & comments.
- Vendor has a current Not approved decision in Vanta: Ramp stops the workflow. Ramp records the prior decision in Activity & comments.
Where to see status in Ramp
- Open the purchase request in Ramp.
- Activity & comments shows events from Vanta, including vendor creation, the decision, and any decision comments.
- The current step will be highlighted under ‘Approval workflow.’
Tips and troubleshooting
- Webhook issues: If updates do not appear in Ramp, confirm the endpoint URL and signing secret in Vanta match the values shown in Ramp.
- OAuth issues: If connection fails, verify the client ID and secret are current and pasted exactly (no extra spaces).
- Permissions: Ensure you can manage apps and Programs in Ramp and have admin access in Vanta to create webhooks and apps.
- Testing: Create a test vendor and run a review to confirm end-to-end sync.
- Missing Vanta step: If a request does not wait at the Vanta step, the vendor may already have a current decision in Vanta. Check Activity & comments.
- Ensure the users you assign to Vanta steps have Vanta access, otherwise reviews could get delayed.
Maintain or remove the integration
- To change the owner, instructions, or due date, edit the Vanta step in your Intake workflow.
- To disconnect, go to Company > Integrations > Vanta and click Disable Vanta integration.
Support
- For setup help, contact Ramp Support.
- For webhook or OAuth configuration help, contact your Vanta admin or Vanta Support.