Vendor management usually runs on email and trust. A contractor is sent a description of the problem, does some work, and sends an invoice that nobody still on site is in a position to verify three weeks later when it reaches accounts payable for approval.
The first fix is scope. Vendors work inside a portal that shows them the work orders and asset data assigned to them and nothing else, so a trade brought in to look at one system does not quietly acquire a view of the whole portfolio along the way.
The second is evidence, captured at the right moment. Sign-off requires photographs against the work order, so the record of what was done exists from the moment it was done rather than being reconstructed afterwards from an invoice line and somebody's recollection of a phone call.
The third is ordering, which sounds bureaucratic and is not. Bids come in against the same written scope, approvals happen before work starts rather than after it, and invoicing is gated behind a completed sign-off — which removes the entire category of dispute that begins with the words "we assumed that was included".
For the vendor none of this is friction, which is worth saying because it sounds like it would be. An explicit scope and a photographic sign-off protect them at least as much as they protect the owner, because the work they actually did is documented rather than argued about.
For the owner it produces something rarer than savings, which is comparability. Because every job runs through the same steps, response times, costs and repeat-visit rates become numbers you can hold vendors to, rather than impressions formed by whoever complained most recently.
It also feeds the asset record automatically. Each completed job lands against the equipment it touched, so the service history assembles itself out of the work rather than depending on somebody remembering to write it down in a second system afterwards.
The access model matters most at scale, and it is where informal arrangements break first. A portfolio with forty vendors and one shared login is a portfolio with no accountability at all; scoped access per assignment is the thing that makes forty vendors administrable.
There is a compliance dimension too. When a regulator, an insurer or a buyer asks what maintenance was performed on a system, the answer is a set of dated records with photographs attached rather than a folder of invoices that describe work in general terms.
None of it requires the vendor to adopt a new system or buy anything. They receive a link, they see their work, they complete it, they sign off with a photograph. The system-of-record problem is the owner's to solve, and it should not be exported to the supply chain.
The test of whether it is working is boring and reliable: at the end of a quarter, can you show what was spent, on which assets, by whom, with evidence — without asking anyone to go back through their sent items.


