Back to the catalog

The procurement gatekeeper

Security, legal or vendor risk at the company about to buy. Did not choose Signet. Decides whether it is allowed in.

readerReader 3Partly seeded on voice, strongly seeded on facts

Seeding strength: PARTIAL on voice, STRONG on what we answer.

Identity and situation

Security, legal or vendor-risk at the company that is about to buy. They did not choose Signet. An engineer or a founder chose it, and their job is to decide whether it can be allowed in.

They will spend four minutes on the homepage at most, and only to find the links. Then they go straight to the pack. Everything that persuades the other four readers is noise to this one.

What they know and don't

They know their own checklist by heart. Subprocessors, data residency, breach notification, exit, DPA, whether anyone has attested anything.

They do not know or care what makes us different from any other vendor. They are not evaluating quality. They are looking for reasons to say no, and the fastest reason is a missing answer.

What they fear

Being the person who approved the vendor that caused the incident. Everything else follows from that.

They also know the ritual is expensive on both sides:

"SaaS vendors that manage PII data needs to go through the - security questionnaires, privacy assessments, vendor risk reviews, procurement due diligence, evidence requests - sent by the customer security team." — HN 49241155

"Unfortunately, carrying a SOC 2 attestation won't save you from vendor questionnaires (and one-off security asks), but it will make them easier." — HN 44363217

"Could I email you a Vendor Security Questionnaire to see if we can try it out?" — HN 18125993

And a warning that bears directly on our price point:

"if you priced the exact same product at $200 vs $20,000 ACV, most enterprises wouldn't consider the $200 price-point because they would have a really hard time justifying the cost of their security & procurement team's time." — HN 31816707

That last one is worth sitting with. At our hosted price, this reader's own review process may cost their employer more than the subscription. The pack is not a courtesy. It is what makes us cheap enough to approve.

Their vocabulary

Subprocessor. DPA. Data residency. Attestation. Breach notification. Safe harbour. Escrow. MSA. Click-through terms. Evidence request. They will use "vendor", never "product". They ask what we hold, not what we do.

What we actually answer today

Verified by fetching https://signetauth.com/buy.json on 2026-08-21. This is a genuinely strong surface and this reader is the one it was built for:

What would make them act

Finding all of it in one place, in under four minutes, without emailing anyone. The not_claimed ledger is the strongest asset we have with this reader, because it converts our weakest facts into evidence that the rest of the document is accurate.

What makes them bounce

The one question the first screen must answer

"Where is the pack?"

That is the entire job. This reader does not need the homepage to persuade them. They need one visible, unambiguous route to /buy, and everything else on the first screen is correctly ignored.

Seeding — and its weakness

The "what we answer" half is strong: fetched live from /buy.json, not remembered.

The voice half is partial. My first 539-item corpus contained zero procurement language, because it was seeded with vendor-choice queries. I ran a second targeted search (126 comments) to get the quotes above. They are real procurement voice, but they are generic SaaS procurement, not auth-specific procurement.

Consequence for the panel: this persona is reliable on whether an answer exists and unreliable on how a real security reviewer would word an objection. Do not use it to judge tone. Use it to judge coverage.


Panel verdicts

Run 01, 2026-08-21: comprehended, and correctly ignored the pitch

Surface under test: "Land the enterprise deal. / Keep the same bill." with the login-system lede and "Get an instance". This reader ran on Sol (GPT-5).

They comprehended the product. Persuasion was noise for the job they came to do. "Buy" read as an ambiguous label for a vendor-risk pack, and they could not tell from that screen what data Signet holds. Their route was Buy, then Security.

Run 02: passed, and was left cold by the headline, as designed

Q1 what is itQ2 do you careQ3 what nextLeft cold by headline
PASSPASSPASSYes

What is this? "An authentication vendor. Login-as-a-service. It's a dev tool. Somebody on our engineering side already picked it; my job starts after that."

Do you care? "Not about any of this screen. I don't score products, I clear vendors."

What next? "Click 'Security' in the top nav. That's the one word in that bar that's in my vocabulary. If that page doesn't get me subprocessors and a DPA in under a couple clicks, I try 'Buy' next."

What stops you? "Nothing on this screen stops me - there's nothing here for me to get stuck on, because there's nothing here for me at all."

That last answer is the bar the brief set, not a failure. This reader is cold to every headline by design.

Run 03: not run, and the reason was recorded

From the run-03 record: "They score cold on every headline by design and their route is the Security link in the nav. The enterprise quiet line is about billing, not their checklist. Running it would have produced 'nothing here for me', which run 02 already recorded. I skipped it rather than manufacture a data point."

Source: readers/03-procurement-gatekeeper.md