Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What should teams do first when offboarding a…
NHI Lifecycle Management

What should teams do first when offboarding a freelancer or agency account?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: NHI Lifecycle Management

The first step is to review every account, shared folder, and managed application the person used, then remove or disable each access path. That includes named accounts, shared collections, and any app-level permissions on managed devices. A documented offboarding checklist reduces the chance that dormant access survives after the working relationship ends.

What teams should do first when offboarding a freelancer or agency account

Start by treating the offboarding as an access inventory problem, not just an account closure. The first practical move is to enumerate every named account, shared folder, application, token, and delegated permission the freelancer or agency used, then remove or disable each path in a controlled order. That is what prevents dormant access from surviving after the relationship ends.

Why the first pass has to cover every access path

Offboarding fails when teams only disable the most obvious login and miss the rest of the access surface. A freelancer may have direct credentials, shared workspace access, app-level permissions, support portal access, or device-based access that outlives the contract unless each path is explicitly found and closed.

That first pass should be broad enough to include collaboration tools, cloud apps, password vault entries, and any access granted through a sponsor, group, or shared mailbox. In practice, the question is not “is the account disabled?” but “can this person or agency still reach any system, folder, or workflow in any way?”

What to remove before you declare the account closed

The safest sequence is to identify access, revoke it, and then confirm the revocation worked. That includes direct accounts, group membership, shared resources, API keys or tokens tied to the engagement, and any managed-device permissions that were granted for the project.

For Joiner-Mover-Leaver (JML) Guide, the important point is that offboarding is a lifecycle event, so the cleanup should be complete enough to prevent privilege carryover into future work. A broader lifecycle view is also covered in NHI Lifecycle Management Guide, which is useful when contractors or agencies had machine, app, or service-style access alongside human access.

If the relationship involved shared or managed access, teams should also review ownership and accountability so the next operator does not inherit an orphaned path by mistake. NHI Ownership and Accountability Guide is a useful reminder that access cleanup is not complete until an owner can attest that nothing remains in circulation.

Risk and Threat Considerations

The main risk is residual access: a former freelancer or agency may still be able to reach files, systems, or applications long after the engagement has ended. That creates exposure even when the original login looks inactive, because shared links, delegated permissions, cached tokens, and app-level grants can remain valid.

Failure mechanism: Teams disable one account but leave other access paths untouched, such as shared folders, role memberships, or long-lived application permissions. If those paths are not inventoried and removed, the departed party can continue to access or reuse the environment.

Impact: Residual access can lead to data exposure, unauthorized changes, credential reuse, or later compromise through a forgotten app or shared resource. At scale, one missed contractor path can become a repeatable offboarding failure across many engagements.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementOffboarding requires removing or invalidating credentials, tokens, and other authenticators.
AC-2 — Account ManagementThe question is about disabling and removing all account access paths after the relationship ends.
Recommendation — Revoke or rotate authenticators tied to the departed account and confirm they no longer work. Disable or remove the account and verify every associated access path is closed.
ISO/IEC 27001:2022A.5.18 — Access rightsOffboarding directly depends on removing access rights when the relationship ends.
Recommendation — Revoke access rights promptly and confirm that all inherited access is removed.
CIS Controls v8CIS-6 — Access Control ManagementAccess removal and review are central to contractor offboarding and dormant access reduction.
Recommendation — Review and revoke all contractor access paths before closing the engagement.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingThe question is specifically about preventing access from surviving after offboarding.
Recommendation — Remove every lingering identity, secret, and permission when an external party leaves.

Practitioner Guidance

What to verify: Confirm that the person or agency has no remaining direct login, no group or role membership, no shared-folder access, and no application permissions that can still authenticate on their behalf. If any access was granted through a sponsor or service owner, verify that the sponsor also removed the indirect path.

Decision rule: If you cannot produce a complete list of every place the contractor was granted access, do not consider the offboarding finished. Treat the account as still active until the last access path is reviewed and removed.

Practitioner takeaway: The first offboarding task is not deletion, it is complete access discovery. Teams that remove access without proving the full inventory are usually confident too early.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org