Registered office
20 Wenlock Road
London N1 7GU
Registered office
20 Wenlock Road
London N1 7GU

Use this contractor access checklist to approve least privilege, protect accounts and devices, review permissions, revoke sessions and verify offboarding.
Secure contractor access should be individually assigned, approved by a business owner, limited to the required systems and dates, protected with MFA, monitored, reviewed and removed through a documented offboarding check. Shared passwords and open-ended administrator access make accountability and safe departure much harder.
Reviewed: 9 September 2026
| Stage | Required evidence | Owner |
|---|---|---|
| Request | Sponsor, purpose, systems, privilege and end date | Hiring manager |
| Provision | Individual identity, MFA, least privilege and accepted terms | IT or system owner |
| Operate | Logging, support route and review of continued need | System owner |
| Change | Updated role, scope, dates and approvals | Sponsor and IT |
| Offboard | Access removed, sessions revoked, assets/data handled and completion recorded | Named coordinator |
Name an internal sponsor and confirm the engagement, start date, expected end date and work location. Identify systems and data required for specific tasks. Record whether the person is an individual contractor, agency worker or supplier technician because contractual and operational routes may differ.
Complete appropriate confidentiality, data-protection, acceptable-use and security arrangements before provisioning. Obtain professional advice for contractual or employment-status questions; this checklist is operational guidance, not legal advice.
Use a named account that the organisation can disable. Avoid shared team credentials and credentials owned by the supplier. Enforce strong MFA, secure recovery and an expiry date where the platform supports it. Keep privileged administration separate from ordinary collaboration.
If external guest identities are suitable, configure them deliberately and test what they can see. Microsoft’s external-user governance guidance explains lifecycle controls for inviting, reviewing and removing access.
Grant only the folders, applications, environments and actions needed. Prefer groups or access packages with named owners over one-off permissions scattered through systems. Make elevated access time-bound and require a reason where tooling allows.
The ICO’s access-control audit framework recommends documented controls for temporary and contract staff, role-based access and accountability for privileged permissions.
Decide whether work requires a company-managed device or whether an assessed personal or supplier device is permitted. Define encryption, screen lock, updates, endpoint protection, local storage and incident reporting. Prevent unmanaged downloads where risk and platform capability justify it.
Issue API keys, SSH keys and other secrets through an approved vault or deployment process. Scope, rotate and revoke them independently of a user account. Never place long-lived production secrets in source code, tickets or shared documents.
Keep useful sign-in and privileged-activity logs according to documented security and privacy requirements. Route relevant alerts to someone who can act. Review access at milestones and extensions, not only on the original end date.
Microsoft’s access-review deployment guidance describes programmes for recurring review of groups, applications and roles. Smaller teams can apply the same principle with a controlled register and named owners.
The sponsor should notify the offboarding coordinator as soon as an engagement ends or risk changes. Do not rely on an inactive-account report weeks later. Agree whether access ends at a specific time, after a handover or immediately for a security event.
Google’s Workspace offboarding guidance covers transfer and removal decisions for users. Platform deletion can have irreversible consequences, so verify retention and ownership before deleting an account.
Check source-code organisations, cloud consoles, domain registrars, analytics, advertising, social accounts, support portals, password vaults, automation connections, API tokens, mailing tools, building access and supplier tickets. Review forwarding rules, delegated mailboxes, shared links and recovery contacts.
Use ACA’s free joiner, mover and leaver checklist to generate a role-specific working list. It supports the process but cannot inspect or remove access automatically.
Have a second appropriate person review high-risk removals. Test that remote and privileged access no longer works without repeatedly attempting suspicious logins. Confirm ownership of scheduled jobs and integrations so offboarding does not break production.
ACA’s startup IT support service can help establish company-owned identity, device and access routines before contractor numbers grow.
Use an identity type and policy that reflects the relationship and platform. It must still be individual, controllable, appropriately licensed and easy to identify in reviews.
Review at defined intervals, project milestones, role changes and extensions. Higher-risk or privileged access should have shorter review and expiry periods.
Removal timing must account for data transfer, retention, audit and platform behaviour. Disable access promptly, then follow the documented and verified deletion process.
Prefer named, time-bound access. If an exceptional shared route is unavoidable, tightly control approval, storage, monitoring, rotation and post-use review.