In this release: Upgraded security for VMP XSite clients, new notifications and more

For several months, we’ve been talking about upcoming security enhancements for VMP XSite clients, and now those security improvements are here. We’d like to tell you a little about the new features and how this impacts your workflow as you create new XSite client users and manage login credentials for existing users.

This update also includes several other improvements, including new notifications which can be enabled for client group members, and an adjustment to bidding so that your minimum number of vendors will be selected to receive bid requests, regardless of priority rankings. Read on for the highlights, and check the release notes for complete details.

 

Changes when creating and managing VMP XSite client users

Please note: In light of the current national emergency, we’re delaying the strong password requirements for VMP XSite clients until April 22nd. We are all working together through stressful circumstances, so we want to make it as easy as possible to accommodate these changes. With that in mind, we recommend that all VMP XSite clients begin using a strong password as soon as possible to avoid delays when the change takes effect.

Email address required

When you (the admin or a user with sufficient permissions) create a new VMP XSite client user, you’ll now be required to enter an email address which will serve as the username for that client. In addition to promoting consistency, by using an email address for the username, the process for retrieving forgotten passwords is simplified.

Clients with default permissions

defaultpermissions.png

By default, the user will have permissions to sign in to and place orders via your XSite and integrations, as well as to change their own username and password. If you don’t change the default permissions, after you click Save they’ll receive an email inviting them to create a strong password so they can log in to your client portal. For security, this email will expire immediately when they create their new password, or after 48 hours if they don’t click the link.

forgotunps.png

Forgot password

Clients with permissions to change their username and password can take advantage of a new Forgot password workflow. To do so, they’ll visit your VMP XSite client portal login page and click Forgot password, which will prompt them for their email address. If they enter an email address that matches an existing user, they’ll receive an email with a link to reset their password. This email will expire when the reset their password, or after 48 hours - similar to the “new client” email mentioned above.

Forgot username

In the past, a VMP XSite client’s username might not have been their email address, or they might have more than one username. In such a case, the client can use the Forgot username process by clicking the Forgot username link on your XSite client portal, then entering their email address. If the address they entered matches an existing user, they’ll receive an email containing their username(s) so they can proceed with login.

If you change the client’s default permissions

When creating a new XSite client user, you can disable any of the default permissions, including their ability to change their username and password. If you do, you must enter the username (email address) and strong password for the user. In this case, for security, the system will not send an email to the user, so you must communicate their login information directly to them. The system will no longer send passwords to any user via email.

9742a.jpg

Forgot password or username

Clients who do not have permission to change their username and password cannot reset their own password if they forget it. They must contact you so you can give them their current password or set a new one. To set a new password, go to the Clients view in Mercury Network, double click the client user, click Edit login, enter and confirm the password in the provided fields, then click Save. For your reference, here is a document with complete instructions for managing client permissions and editing their login information. If a client with such restrictions attempts to use the Forgot password process, they’ll see a message asking them to contact their account administrator.

 

New notifications for client group members

Based on information we heard from you, there are two new notifications which you can enable for Client Group members to help them stay in the loop about order updates:

  • Revision Needed (By Client)
    This notification will be sent when a client updates the order status to Revision Needed.

  • Revision Cancelled (By Client)
    This notification will be sent when a client cancels a revision request.

These new notification emails can be enabled for members of a client group by visiting the Members tab of the Client Group Management dialog.

 

Bidding changes ensure your minimum number of vendors are included

When submitting an order for bid requests, there were cases when your vendor selection settings—specifically those requiring a vendor priority rating—resulted in only 1-2 vendors being eligible to receive the request. To resolve this (based on your feedback) if there are not enough high-priority vendors to meet your minimum vendor requirements, the system will consider vendors with a lower priority.