Join our Newsletter — 33% off our NHI Course

What should organisations do immediately after a contractor leaves?

Revoke access across every connected system, confirm that admin roles and data exports are removed, and document the owner who approved the offboarding. The goal is to remove the account, not just mark the engagement as closed.

What changes the moment a contractor leaves?

The immediate job is to remove every live access path the contractor had, not just close the HR or vendor record. That includes interactive sign-in, privileged access, application access, shared credentials, API tokens, remote access paths, and any delegated permissions that could still reach production, data exports, or admin consoles.

A contractor offboarding failure is usually an access governance failure first, and a paperwork failure second. If the account remains usable anywhere, the organisation has not actually offboarded the contractor, it has only documented the departure.

Because contractor access often spans multiple systems and business owners, the first operational question is whether anyone can still authenticate, export data, or approve changes under that identity. If the answer is unclear, the offboarding is not complete.

Which access paths need to be checked first?

Start with the highest-risk paths: privileged roles, production systems, cloud consoles, VPN or remote access, code repositories, data platforms, and any service accounts or shared accounts the contractor touched. A clean termination process should also remove sessions, revoke active tokens, rotate any secrets the contractor knew, and verify that inheritance through groups, roles, or delegated permissions has been removed.

For contractor exits, the most common gap is not the named user account itself but the connected access they enabled elsewhere. That is why NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant here, especially the controls that drive account management, access enforcement, and auditability.

Where contractors worked through non-human access paths such as scripts, integrations, or shared automation, the same principle applies: remove or rebind the secret, key, or token, then verify that the contractor can no longer act through it. OWASP Non-Human Identity Top 10 is a useful reference when those machine-facing access paths are part of the offboarding scope.

What proves the offboarding is actually complete?

Completion should be measured by evidence, not by intent. You want proof that the account is disabled or removed, privileged memberships are gone, active sessions have ended, exports and admin capabilities have been revoked, and the named owner signed off on the change. If the environment uses just-in-time access or time-bounded access, confirm that the entitlement cannot simply reappear through an automation rule or stale approval path.

If the contractor had access to identity providers, cloud platforms, source control, ticketing, or data warehouses, validate each connected system independently. A single central directory action is rarely enough on its own, because the real exposure is often in the downstream systems that cached or extended the original privilege.

In practice, organisations with mature offboarding make the revocation event observable, reviewable, and attributable. The right artefact is not only a closed ticket, but a completed access removal record that shows who approved the action, when it occurred, and which systems were checked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Contractor offboarding is fundamentally account lifecycle and access removal.
AC-6 — Least Privilege Offboarding must remove elevated access and lingering privilege grants.
IA-5 — Authenticator Management Contractor departure often requires rotating or revoking credentials, tokens, and secrets.
Recommendation — Revoke the contractor’s accounts and disable any remaining access paths immediately. Remove privileged entitlements and confirm no excessive access remains. Rotate or revoke authenticators and secrets the contractor could still use.
ISO/IEC 27001:2022 A.5.18 — Access rights This question is about timely revocation of access when staff or contractors leave.
A.5.16 — Identity management Offboarding requires accurate identity removal across connected systems.
Recommendation — Review and remove access rights promptly on contractor departure. Update identity records so the contractor cannot retain valid access.

Practitioner Guidance

What to prioritise: Remove anything that can still authenticate or authorise the contractor before you spend time on low-risk clean-up. If the person had production, admin, or data-export capability, treat revocation and session termination as the first control objective.

What to verify: Check for hidden continuation paths, including shared credentials, group inheritance, service tokens, external collaborator accounts, and offline copies of secrets. The control is only trustworthy when you can show the contractor can no longer reach the environment through any of those routes.

Common mistake: Teams often mark the engagement closed in one system and assume the access problem is solved. The safer rule is to close the access path everywhere first, then close the business record after the technical removal is confirmed.

Practitioner takeaway: Contractor offboarding is complete only when the organisation can demonstrate that no remaining identity, credential, or delegated path still allows action inside the environment.