{"id":3559,"date":"2026-09-09T21:02:43","date_gmt":"2026-09-09T21:02:43","guid":{"rendered":"https:\/\/acatechsolutions.co.uk\/blog\/contractor-access-offboarding-checklist\/"},"modified":"2026-09-09T21:02:43","modified_gmt":"2026-09-09T21:02:43","slug":"contractor-access-offboarding-checklist","status":"publish","type":"post","link":"https:\/\/acatechsolutions.co.uk\/blog\/contractor-access-offboarding-checklist\/","title":{"rendered":"Secure Contractor Access and Offboarding Checklist"},"content":{"rendered":"<p><strong>Secure contractor access should be individually assigned, approved by a business owner, limited to the required systems and dates, protected with MFA, monitored, reviewed and removed through a documented offboarding check.<\/strong> Shared passwords and open-ended administrator access make accountability and safe departure much harder.<\/p>\n<p><em>Reviewed: 9 September 2026<\/em><\/p>\n<h2>Contractor access checklist at a glance<\/h2>\n<figure class=\"wp-block-table\">\n<table>\n<thead>\n<tr>\n<th scope=\"col\">Stage<\/th>\n<th scope=\"col\">Required evidence<\/th>\n<th scope=\"col\">Owner<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Request<\/td>\n<td>Sponsor, purpose, systems, privilege and end date<\/td>\n<td>Hiring manager<\/td>\n<\/tr>\n<tr>\n<td>Provision<\/td>\n<td>Individual identity, MFA, least privilege and accepted terms<\/td>\n<td>IT or system owner<\/td>\n<\/tr>\n<tr>\n<td>Operate<\/td>\n<td>Logging, support route and review of continued need<\/td>\n<td>System owner<\/td>\n<\/tr>\n<tr>\n<td>Change<\/td>\n<td>Updated role, scope, dates and approvals<\/td>\n<td>Sponsor and IT<\/td>\n<\/tr>\n<tr>\n<td>Offboard<\/td>\n<td>Access removed, sessions revoked, assets\/data handled and completion recorded<\/td>\n<td>Named coordinator<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<h2>Before access is requested<\/h2>\n<p>Name an internal sponsor and confirm the engagement, start date, expected end date and work location. Identify systems and data required for specific tasks. Record whether the person is an individual contractor, agency worker or supplier technician because contractual and operational routes may differ.<\/p>\n<p>Complete appropriate confidentiality, data-protection, acceptable-use and security arrangements before provisioning. Obtain professional advice for contractual or employment-status questions; this checklist is operational guidance, not legal advice.<\/p>\n<h2>Create an individual, company-controlled identity<\/h2>\n<p>Use a named account that the organisation can disable. Avoid shared team credentials and credentials owned by the supplier. Enforce strong MFA, secure recovery and an expiry date where the platform supports it. Keep privileged administration separate from ordinary collaboration.<\/p>\n<p>If external guest identities are suitable, configure them deliberately and test what they can see. Microsoft\u2019s <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/entitlement-management-external-users\" target=\"_blank\" rel=\"noopener\">external-user governance guidance<\/a> explains lifecycle controls for inviting, reviewing and removing access.<\/p>\n<h2>Apply least privilege by task and time<\/h2>\n<p>Grant only the folders, applications, environments and actions needed. Prefer groups or access packages with named owners over one-off permissions scattered through systems. Make elevated access time-bound and require a reason where tooling allows.<\/p>\n<ul>\n<li>separate production, finance, HR and customer-data permissions;<\/li>\n<li>restrict bulk export and administrative functions;<\/li>\n<li>use managed secure routes for remote access;<\/li>\n<li>do not send secrets in ordinary email or chat;<\/li>\n<li>record exceptions, compensating controls and expiry;<\/li>\n<li>test permissions with the contractor\u2019s actual account.<\/li>\n<\/ul>\n<p>The ICO\u2019s <a href=\"https:\/\/ico.org.uk\/for-organisations\/advice-and-services\/audits\/data-protection-audit-framework\/toolkits\/information-and-cyber-security\/access-control\/\" target=\"_blank\" rel=\"noopener\">access-control audit framework<\/a> recommends documented controls for temporary and contract staff, role-based access and accountability for privileged permissions.<\/p>\n<h2>Control devices, data and secrets<\/h2>\n<p>Decide whether work requires a company-managed device or whether an assessed personal or supplier device is permitted. Define encryption, screen lock, updates, endpoint protection, local storage and incident reporting. Prevent unmanaged downloads where risk and platform capability justify it.<\/p>\n<p>Issue API keys, SSH keys and other secrets through an approved vault or deployment process. Scope, rotate and revoke them independently of a user account. Never place long-lived production secrets in source code, tickets or shared documents.<\/p>\n<h2>Monitor and review access during the engagement<\/h2>\n<p>Keep useful sign-in and privileged-activity logs according to documented security and privacy requirements. Route relevant alerts to someone who can act. Review access at milestones and extensions, not only on the original end date.<\/p>\n<p>Microsoft\u2019s <a href=\"https:\/\/learn.microsoft.com\/en-us\/entra\/id-governance\/deploy-access-reviews\" target=\"_blank\" rel=\"noopener\">access-review deployment guidance<\/a> describes programmes for recurring review of groups, applications and roles. Smaller teams can apply the same principle with a controlled register and named owners.<\/p>\n<h2>Use an event-driven offboarding trigger<\/h2>\n<p>The sponsor should notify the offboarding coordinator as soon as an engagement ends or risk changes. Do not rely on an inactive-account report weeks later. Agree whether access ends at a specific time, after a handover or immediately for a security event.<\/p>\n<ol>\n<li>Disable or remove the primary identity and external guest access.<\/li>\n<li>Revoke active sessions, tokens, VPN access and trusted devices.<\/li>\n<li>Remove group, repository, application and privileged roles.<\/li>\n<li>Rotate shared secrets the contractor could access.<\/li>\n<li>Transfer company files, code, documentation and operational ownership.<\/li>\n<li>Recover company devices, passes and physical keys.<\/li>\n<li>Confirm data-return or deletion duties through the agreed process.<\/li>\n<li>Record completion, exceptions and the person who verified them.<\/li>\n<\/ol>\n<p>Google\u2019s <a href=\"https:\/\/support.google.com\/a\/users\/answer\/11559716\" target=\"_blank\" rel=\"noopener\">Workspace offboarding guidance<\/a> covers transfer and removal decisions for users. Platform deletion can have irreversible consequences, so verify retention and ownership before deleting an account.<\/p>\n<h2>Do not forget non-obvious access<\/h2>\n<p>Check source-code organisations, cloud consoles, domain registrars, analytics, advertising, social accounts, support portals, password vaults, automation connections, API tokens, mailing tools, building access and supplier tickets. Review forwarding rules, delegated mailboxes, shared links and recovery contacts.<\/p>\n<p>Use ACA\u2019s free <a href=\"https:\/\/acatechsolutions.co.uk\/tools\/joiner-mover-leaver-checklist\/\">joiner, mover and leaver checklist<\/a> to generate a role-specific working list. It supports the process but cannot inspect or remove access automatically.<\/p>\n<h2>Verify rather than assume completion<\/h2>\n<p>Have a second appropriate person review high-risk removals. Test that remote and privileged access no longer works without repeatedly attempting suspicious logins. Confirm ownership of scheduled jobs and integrations so offboarding does not break production.<\/p>\n<p>ACA\u2019s <a href=\"https:\/\/acatechsolutions.co.uk\/startup-it\/\">startup IT support service<\/a> can help establish company-owned identity, device and access routines before contractor numbers grow.<\/p>\n<h2>Frequently asked questions<\/h2>\n<h3>Should contractors use employee accounts?<\/h3>\n<p>Use an identity type and policy that reflects the relationship and platform. It must still be individual, controllable, appropriately licensed and easy to identify in reviews.<\/p>\n<h3>How often should contractor access be reviewed?<\/h3>\n<p>Review at defined intervals, project milestones, role changes and extensions. Higher-risk or privileged access should have shorter review and expiry periods.<\/p>\n<h3>Should the account be deleted immediately?<\/h3>\n<p>Removal timing must account for data transfer, retention, audit and platform behaviour. Disable access promptly, then follow the documented and verified deletion process.<\/p>\n<h3>What if a supplier needs an emergency shared account?<\/h3>\n<p>Prefer named, time-bound access. If an exceptional shared route is unavoidable, tightly control approval, storage, monitoring, rotation and post-use review.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Use this contractor access checklist to approve least privilege, protect accounts and devices, review permissions, revoke sessions and verify offboarding.<\/p>\n","protected":false},"author":1,"featured_media":3560,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23,17],"tags":[],"class_list":["post-3559","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber_hygiene","category-information_technology"],"blocksy_meta":{"page_structure_type":"type-1","styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":7}},"_links":{"self":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3559","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/comments?post=3559"}],"version-history":[{"count":0,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/posts\/3559\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media\/3560"}],"wp:attachment":[{"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/media?parent=3559"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/categories?post=3559"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/acatechsolutions.co.uk\/blog\/wp-json\/wp\/v2\/tags?post=3559"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}