The first step is to review every account, shared folder, and managed application the person used, then remove or disable each access path. That includes named accounts, shared collections, and any app-level permissions on managed devices. A documented offboarding checklist reduces the chance that dormant access survives after the working relationship ends.
What teams should do first when offboarding a freelancer or agency account
Start by treating the offboarding as an access inventory problem, not just an account closure. The first practical move is to enumerate every named account, shared folder, application, token, and delegated permission the freelancer or agency used, then remove or disable each path in a controlled order. That is what prevents dormant access from surviving after the relationship ends.
Why the first pass has to cover every access path
Offboarding fails when teams only disable the most obvious login and miss the rest of the access surface. A freelancer may have direct credentials, shared workspace access, app-level permissions, support portal access, or device-based access that outlives the contract unless each path is explicitly found and closed.
That first pass should be broad enough to include collaboration tools, cloud apps, password vault entries, and any access granted through a sponsor, group, or shared mailbox. In practice, the question is not “is the account disabled?” but “can this person or agency still reach any system, folder, or workflow in any way?”
What to remove before you declare the account closed
The safest sequence is to identify access, revoke it, and then confirm the revocation worked. That includes direct accounts, group membership, shared resources, API keys or tokens tied to the engagement, and any managed-device permissions that were granted for the project.
For Joiner-Mover-Leaver (JML) Guide, the important point is that offboarding is a lifecycle event, so the cleanup should be complete enough to prevent privilege carryover into future work. A broader lifecycle view is also covered in NHI Lifecycle Management Guide, which is useful when contractors or agencies had machine, app, or service-style access alongside human access.
If the relationship involved shared or managed access, teams should also review ownership and accountability so the next operator does not inherit an orphaned path by mistake. NHI Ownership and Accountability Guide is a useful reminder that access cleanup is not complete until an owner can attest that nothing remains in circulation.
Risk and Threat Considerations
The main risk is residual access: a former freelancer or agency may still be able to reach files, systems, or applications long after the engagement has ended. That creates exposure even when the original login looks inactive, because shared links, delegated permissions, cached tokens, and app-level grants can remain valid.
Failure mechanism: Teams disable one account but leave other access paths untouched, such as shared folders, role memberships, or long-lived application permissions. If those paths are not inventoried and removed, the departed party can continue to access or reuse the environment.
Impact: Residual access can lead to data exposure, unauthorized changes, credential reuse, or later compromise through a forgotten app or shared resource. At scale, one missed contractor path can become a repeatable offboarding failure across many engagements.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Offboarding requires removing or invalidating credentials, tokens, and other authenticators. |
| AC-2 — Account Management | The question is about disabling and removing all account access paths after the relationship ends. | |
| Recommendation — Revoke or rotate authenticators tied to the departed account and confirm they no longer work. Disable or remove the account and verify every associated access path is closed. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Offboarding directly depends on removing access rights when the relationship ends. |
| Recommendation — Revoke access rights promptly and confirm that all inherited access is removed. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access removal and review are central to contractor offboarding and dormant access reduction. |
| Recommendation — Review and revoke all contractor access paths before closing the engagement. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The question is specifically about preventing access from surviving after offboarding. |
| Recommendation — Remove every lingering identity, secret, and permission when an external party leaves. | ||
Practitioner Guidance
What to verify: Confirm that the person or agency has no remaining direct login, no group or role membership, no shared-folder access, and no application permissions that can still authenticate on their behalf. If any access was granted through a sponsor or service owner, verify that the sponsor also removed the indirect path.
Decision rule: If you cannot produce a complete list of every place the contractor was granted access, do not consider the offboarding finished. Treat the account as still active until the last access path is reviewed and removed.
Practitioner takeaway: The first offboarding task is not deletion, it is complete access discovery. Teams that remove access without proving the full inventory are usually confident too early.
Related resources from NHI Mgmt Group
- How should teams reduce the risk of orphaned service accounts and stale tokens?
- How do teams decide when to block a loyalty account versus investigate first?
- How do security teams know if internal phishing is spreading beyond the first account?
- How do security teams use user account history to improve offboarding and access control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org