Client-controlled dependency evidence
Held — the dependency record you control.
A continuously maintained record of the outside parties your company relies on, what each one supports, and what the evidence says today. You own it, and you decide who sees it.
Held is pre-launch. The product is in design, the demo runs on synthetic data, and no client data is held.
The problem
Most companies can tell you who they paid last quarter.
Far fewer can say, quickly and in a way they would defend, which outside companies actually keep a given site or critical process running, what evidence proves it, what has changed since anyone last looked, and who owns the response when something goes wrong.
That gap is not a failure of effort. The answer is scattered:
- Accounts payable knows who was paid.
- The contract file knows what was promised.
- Work-order and asset systems know who was on site.
- A certificate network knows whether a status record is current.
- An external intelligence feed may hint at a relationship nobody inside has confirmed.
Each system holds a partial answer, and none of them is responsible for the join. So when a critical provider cancels, a lender asks about the vendors behind a financed asset, or an incident starts, the record is rebuilt by hand in spreadsheets and email, under time pressure. The result is a one-time map that is out of date the week after it is finished.
What Held is
One record of who you rely on, and what the evidence says.
Held is a client-controlled, continuously maintained dependency evidence record and disclosure layer. It joins the sources you already have (AP and ERP, contracts, work-order and asset systems, status sources, and licensed external signals) and concentrates on the critical and high-spend dependencies that would change an operating, continuity, financing, insurance, audit, or procurement decision.
Provenance is explicit
Every fact carries a label saying where it came from. A missing fact is stored as unknown, never left blank.
Seen in a system of record the client authorized, as that system recorded it.
AP/ERP payments, work orders, asset and site records, status-network records
Stated by a party about itself or about an agreement.
Contract terms, vendor evidence-link answers, client reviewer corrections
From a licensed third party that is neither the client nor the counterparty, used as a reference.
Public registries, licensed data providers
A lead or computed suggestion not yet confirmed by evidence. Never published as fact.
External relationship signals, suggested entity matches
Nothing is accepted by accident
New evidence is staged, reviewed by an authorized person, and applied by a separate decision. Nothing silently overwrites the published record, and every version is kept.
Scoped, dated, revocable packages
You issue a reduced package to a named recipient for a stated purpose, with an as-of date and an expiry. The recipient sees the package, not your workspace. Revocation stops future access; Held says plainly that it cannot erase copies already lawfully downloaded.
You own the record
The operating company controls its workspace; Held acts as processor and service provider. The record stays with you even if an adviser changes.
Don't send a questionnaire. Request the Held package.
What Held is not
Narrow on purpose.
Each of these would weaken the promise that the client controls the record.
Not a marketplace
Held does not broker vendors or sell access to a vendor network.
Not an economy graph
Held does not try to map every company's suppliers. Its asset is the confirmed, client-specific record.
Not a questionnaire tool
Held starts from your own records and contacts a vendor only to close a gap that matters for a decision.
Not a risk score
Held reports evidence, gaps, and changes. It does not reduce a vendor to a number from public data.
Not an insurance placement vehicle
Held takes no commissions, does not sell insurance, and makes no coverage, exposure, or loss determinations.
Not a replacement for ERP or TPRM
Held does not replace ERP, TPRM, contract, or certificate systems. It joins them.
Why now
"Show us the register" is becoming a normal expectation.
Systems are fragmented
ERP, procurement, TPRM, certificate, contract, and external-intelligence tools each do their job well. None of them owns the client-specific join across all of them, with provenance and decision history.
Reliance keeps growing
Operating companies depend on more contracted services, outsourced functions, and specialized providers, and those relationships change constantly: new payees, contract changes, cancellations, expirations, new site work.
Regulation shows the direction
The EU's Digital Operational Resilience Act (DORA) requires financial entities to keep a register of ICT third-party arrangements. Australia's CPS 230 requires a register of material service providers. None of these mandates Held; they show where expectations are heading.
Readers want evidence
Boards, lenders, insurers, and auditors increasingly want to be shown the record, not told about it: what you knew, when you knew it, and what you did.
Incident Mode
Start the response from the record, not a blank spreadsheet.
When a facility event, cyber or provider outage, vendor insolvency, natural catastrophe, contract or insurance status change, or equipment failure occurs, Incident Mode opens a workspace that already shows:
- Affected dependencies and sites
- Known alternatives
- Evidence gaps
- Owners and contracts
- Packages already issued
Held does not predict losses or make coverage calls.
Weekly change report
What changed, why it matters, who owns the next action.
The everyday product is a short daily or weekly brief. A new payee, a spend jump, a contract change, an expiring status record, or an unresolved identity becomes an owned action instead of a silent spreadsheet edit.
How the 90-day pilot works
One operating company. One dependency class. One accountable owner.
The pilot covers 25 to 50 critical dependencies, built from three client-authorized, read-only sources: typically AP/ERP, contracts or certificates, and one operating or live evidence source.
- Days 1–30
Authorize and agree
Authorize sources, import AP, agree the priority list, and name owners.
- Days 31–60
Connect and resolve
Connect sources, resolve identities, stage and apply evidence, and open exceptions.
- Days 61–90
Refresh and prove
Run refresh cycles, issue a scoped package, and test an incident or handoff.
The output is a reusable, client-owned dependency record and package, not a slide deck. The pilot succeeds only if the client renews for ongoing maintenance.
Held is designed so the client controls access; every source, fact, decision, and disclosure is scoped, attributable, and auditable. Until pilot security and operating controls are in place and tested, Held works with synthetic data only, and no confidential client evidence is accepted. Held makes no certification claims until an independent assessment supports them.
Request a pilot
Talk to us about a 90-day pilot.
Tell us a little about your company and the dependency question you need answered. Submitting opens your own email app with a pre-filled message to pilot@heldrecord.com. Nothing is sent or stored by this site.