Client-controlled dependency evidence

Held — the dependency record you control.

A continuously maintained record of the outside parties your company relies on, what each one supports, and what the evidence says today. You own it, and you decide who sees it.

Held is pre-launch. The product is in design, the demo runs on synthetic data, and no client data is held.

The problem

Most companies can tell you who they paid last quarter.

Far fewer can say, quickly and in a way they would defend, which outside companies actually keep a given site or critical process running, what evidence proves it, what has changed since anyone last looked, and who owns the response when something goes wrong.

That gap is not a failure of effort. The answer is scattered:

  • Accounts payable knows who was paid.
  • The contract file knows what was promised.
  • Work-order and asset systems know who was on site.
  • A certificate network knows whether a status record is current.
  • An external intelligence feed may hint at a relationship nobody inside has confirmed.

Each system holds a partial answer, and none of them is responsible for the join. So when a critical provider cancels, a lender asks about the vendors behind a financed asset, or an incident starts, the record is rebuilt by hand in spreadsheets and email, under time pressure. The result is a one-time map that is out of date the week after it is finished.

What Held is

One record of who you rely on, and what the evidence says.

Held is a client-controlled, continuously maintained dependency evidence record and disclosure layer. It joins the sources you already have (AP and ERP, contracts, work-order and asset systems, status sources, and licensed external signals) and concentrates on the critical and high-spend dependencies that would change an operating, continuity, financing, insurance, audit, or procurement decision.

Provenance is explicit

Every fact carries a label saying where it came from. A missing fact is stored as unknown, never left blank.

Observed

Seen in a system of record the client authorized, as that system recorded it.

AP/ERP payments, work orders, asset and site records, status-network records

Declared

Stated by a party about itself or about an agreement.

Contract terms, vendor evidence-link answers, client reviewer corrections

External

From a licensed third party that is neither the client nor the counterparty, used as a reference.

Public registries, licensed data providers

Inferred

A lead or computed suggestion not yet confirmed by evidence. Never published as fact.

External relationship signals, suggested entity matches

Nothing is accepted by accident

New evidence is staged, reviewed by an authorized person, and applied by a separate decision. Nothing silently overwrites the published record, and every version is kept.

Scoped, dated, revocable packages

You issue a reduced package to a named recipient for a stated purpose, with an as-of date and an expiry. The recipient sees the package, not your workspace. Revocation stops future access; Held says plainly that it cannot erase copies already lawfully downloaded.

You own the record

The operating company controls its workspace; Held acts as processor and service provider. The record stays with you even if an adviser changes.

Don't send a questionnaire. Request the Held package.

What Held is not

Narrow on purpose.

Each of these would weaken the promise that the client controls the record.

Not a marketplace

Held does not broker vendors or sell access to a vendor network.

Not an economy graph

Held does not try to map every company's suppliers. Its asset is the confirmed, client-specific record.

Not a questionnaire tool

Held starts from your own records and contacts a vendor only to close a gap that matters for a decision.

Not a risk score

Held reports evidence, gaps, and changes. It does not reduce a vendor to a number from public data.

Not an insurance placement vehicle

Held takes no commissions, does not sell insurance, and makes no coverage, exposure, or loss determinations.

Not a replacement for ERP or TPRM

Held does not replace ERP, TPRM, contract, or certificate systems. It joins them.

Why now

"Show us the register" is becoming a normal expectation.

Systems are fragmented

ERP, procurement, TPRM, certificate, contract, and external-intelligence tools each do their job well. None of them owns the client-specific join across all of them, with provenance and decision history.

Reliance keeps growing

Operating companies depend on more contracted services, outsourced functions, and specialized providers, and those relationships change constantly: new payees, contract changes, cancellations, expirations, new site work.

Regulation shows the direction

The EU's Digital Operational Resilience Act (DORA) requires financial entities to keep a register of ICT third-party arrangements. Australia's CPS 230 requires a register of material service providers. None of these mandates Held; they show where expectations are heading.

Readers want evidence

Boards, lenders, insurers, and auditors increasingly want to be shown the record, not told about it: what you knew, when you knew it, and what you did.

Incident Mode

Start the response from the record, not a blank spreadsheet.

When a facility event, cyber or provider outage, vendor insolvency, natural catastrophe, contract or insurance status change, or equipment failure occurs, Incident Mode opens a workspace that already shows:

  • Affected dependencies and sites
  • Known alternatives
  • Evidence gaps
  • Owners and contracts
  • Packages already issued

Held does not predict losses or make coverage calls.

Weekly change report

What changed, why it matters, who owns the next action.

The everyday product is a short daily or weekly brief. A new payee, a spend jump, a contract change, an expiring status record, or an unresolved identity becomes an owned action instead of a silent spreadsheet edit.

New payee
Spend jump
Contract change
Expiring status record
Unresolved identity

How the 90-day pilot works

One operating company. One dependency class. One accountable owner.

The pilot covers 25 to 50 critical dependencies, built from three client-authorized, read-only sources: typically AP/ERP, contracts or certificates, and one operating or live evidence source.

  1. Days 1–30

    Authorize and agree

    Authorize sources, import AP, agree the priority list, and name owners.

  2. Days 31–60

    Connect and resolve

    Connect sources, resolve identities, stage and apply evidence, and open exceptions.

  3. Days 61–90

    Refresh and prove

    Run refresh cycles, issue a scoped package, and test an incident or handoff.

The output is a reusable, client-owned dependency record and package, not a slide deck. The pilot succeeds only if the client renews for ongoing maintenance.

Held is designed so the client controls access; every source, fact, decision, and disclosure is scoped, attributable, and auditable. Until pilot security and operating controls are in place and tested, Held works with synthetic data only, and no confidential client evidence is accepted. Held makes no certification claims until an independent assessment supports them.

Request a pilot

Talk to us about a 90-day pilot.

Tell us a little about your company and the dependency question you need answered. Submitting opens your own email app with a pre-filled message to pilot@heldrecord.com. Nothing is sent or stored by this site.