Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do immediately after a contractor…
Governance, Ownership & Risk

What should organisations do immediately after a contractor leaves?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Revoke access across every connected system, confirm that admin roles and data exports are removed, and document the owner who approved the offboarding. The goal is to remove the account, not just mark the engagement as closed.

What changes the moment a contractor leaves?

The immediate job is to remove every live access path the contractor had, not just close the HR or vendor record. That includes interactive sign-in, privileged access, application access, shared credentials, API tokens, remote access paths, and any delegated permissions that could still reach production, data exports, or admin consoles.

A contractor offboarding failure is usually an access governance failure first, and a paperwork failure second. If the account remains usable anywhere, the organisation has not actually offboarded the contractor, it has only documented the departure.

Because contractor access often spans multiple systems and business owners, the first operational question is whether anyone can still authenticate, export data, or approve changes under that identity. If the answer is unclear, the offboarding is not complete.

Which access paths need to be checked first?

Start with the highest-risk paths: privileged roles, production systems, cloud consoles, VPN or remote access, code repositories, data platforms, and any service accounts or shared accounts the contractor touched. A clean termination process should also remove sessions, revoke active tokens, rotate any secrets the contractor knew, and verify that inheritance through groups, roles, or delegated permissions has been removed.

For contractor exits, the most common gap is not the named user account itself but the connected access they enabled elsewhere. That is why NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant here, especially the controls that drive account management, access enforcement, and auditability.

Where contractors worked through non-human access paths such as scripts, integrations, or shared automation, the same principle applies: remove or rebind the secret, key, or token, then verify that the contractor can no longer act through it. OWASP Non-Human Identity Top 10 is a useful reference when those machine-facing access paths are part of the offboarding scope.

What proves the offboarding is actually complete?

Completion should be measured by evidence, not by intent. You want proof that the account is disabled or removed, privileged memberships are gone, active sessions have ended, exports and admin capabilities have been revoked, and the named owner signed off on the change. If the environment uses just-in-time access or time-bounded access, confirm that the entitlement cannot simply reappear through an automation rule or stale approval path.

If the contractor had access to identity providers, cloud platforms, source control, ticketing, or data warehouses, validate each connected system independently. A single central directory action is rarely enough on its own, because the real exposure is often in the downstream systems that cached or extended the original privilege.

In practice, organisations with mature offboarding make the revocation event observable, reviewable, and attributable. The right artefact is not only a closed ticket, but a completed access removal record that shows who approved the action, when it occurred, and which systems were checked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementContractor offboarding is fundamentally account lifecycle and access removal.
AC-6 — Least PrivilegeOffboarding must remove elevated access and lingering privilege grants.
IA-5 — Authenticator ManagementContractor departure often requires rotating or revoking credentials, tokens, and secrets.
Recommendation — Revoke the contractor’s accounts and disable any remaining access paths immediately. Remove privileged entitlements and confirm no excessive access remains. Rotate or revoke authenticators and secrets the contractor could still use.
ISO/IEC 27001:2022A.5.18 — Access rightsThis question is about timely revocation of access when staff or contractors leave.
A.5.16 — Identity managementOffboarding requires accurate identity removal across connected systems.
Recommendation — Review and remove access rights promptly on contractor departure. Update identity records so the contractor cannot retain valid access.

Practitioner Guidance

What to prioritise: Remove anything that can still authenticate or authorise the contractor before you spend time on low-risk clean-up. If the person had production, admin, or data-export capability, treat revocation and session termination as the first control objective.

What to verify: Check for hidden continuation paths, including shared credentials, group inheritance, service tokens, external collaborator accounts, and offline copies of secrets. The control is only trustworthy when you can show the contractor can no longer reach the environment through any of those routes.

Common mistake: Teams often mark the engagement closed in one system and assume the access problem is solved. The safer rule is to close the access path everywhere first, then close the business record after the technical removal is confirmed.

Practitioner takeaway: Contractor offboarding is complete only when the organisation can demonstrate that no remaining identity, credential, or delegated path still allows action inside the environment.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org