Back to Blog
Identity Security
8 min read

Identity Governance for Contractors: Avoiding Hidden Access Debt

Contractors, locums, students and vendor engineers arrive through doors HR never sees, so nothing tells the identity system when they leave. How to give non-employees an expiry date.

GuardsArm Team

Security Experts

December 6, 2025

Contractor identity governance

Employee offboarding usually works, because HR is the trigger and the process is well worn. Everyone else is the problem. Locums, agency nurses, students on placement, research collaborators, vendor engineers and consultants all get accounts — and almost none of them appear in the HR system that drives deprovisioning. Nothing tells identity management when they stop coming.

No HR trigger
Non-employees are not in the system that drives automatic deprovisioning
Multiple front doors
Accounts get created by IT, biomedical, research and departments independently
Indefinite by default
An account created with no end date has no end date

Sponsorship is the mechanism that works

Every non-employee account needs a named employee who owns it. Not a department, not a distribution list — a person, who is accountable for whether it should still exist.

The sponsored account model:

  • A named sponsor, recorded on the account itself
  • A mandatory end date at creation, with a hard maximum (90 days is a reasonable default; some estates use the contract end date where it is known)
  • Automatic disable at expiry, with no manual step required
  • Renewal by positive action from the sponsor, not by silence
  • Sponsor changes when they leave — orphaned sponsorship is its own failure mode
Expiry must be the default, not an option
If the account creation form has an optional end date, it will be left blank. Make it required, cap the maximum, and make renewal a deliberate act. This one form change prevents most of the problem.

The lifecycle, for people HR does not track

Non-employee identity lifecycleNon-employee identity lifecycle1Request with sponsorBefore accessNamed employee sponsor, stated purpose, end date within policy maximum.2Provision minimallyDay 1Role-scoped access only. No copying an existing user’s permissions.3Reconfirm at intervalsEvery 30-90 daysSponsor confirms still needed. No response means disable, not extend.4Disable on expiryAutomaticAccount disabled the moment the date passes, without a ticket.5Delete after retentionPer policyPreserve audit history, remove the credential.
Copying an existing user’s permissions is how a temporary account inherits a decade of accumulated access.

That warning about copying permissions deserves emphasis. "Make them the same as Dr Patel" is the fastest way to provision and the most common cause of a contractor holding access to systems they have never needed. Provision from a role definition.


Finding what is already there

Before improving the process, measure the existing debt. Queries worth running against the directory today:

QueryWhat it finds
Accounts with no expiry date setThe baseline problem
Enabled accounts with no sign-in for 90+ daysDormant, likely departed
Accounts whose sponsor has themselves leftOrphaned sponsorship
Accounts created outside the standard processShadow provisioning paths
Non-employee accounts with privileged group membershipThe highest-risk subset
Vendor accounts with interactive login rightsShould usually be brokered instead
Illustrative contractor account auditIllustrative distribution from a typical first audit of non-employee accounts.Total non-employee accounts840BaselineNo expiry date set512The core problemDormant 90+ days, still enabled296Almost all safe to disableSponsor has left74Nobody is accountable for thesePrivileged and dormant19Fix these first
Illustrative. The last row is small and urgent; the third is large and easy.

Disable dormant accounts rather than deleting them: it is reversible within minutes if you get one wrong, which makes the change far easier to get approved.


Vendor accounts are a special case

Manufacturer and supplier engineers should generally not hold standing interactive accounts at all. Broker their access instead — time-boxed, named, recorded, opened on request and closed automatically. That belongs in the contract, which is covered alongside device support in IoMT security.


Where to start

Run the "enabled, no sign-in for 90 days" query. It takes minutes, it needs no project approval, and on most hospital directories it returns a number that makes the case for the rest of the programme on its own.

GuardsArm runs identity governance reviews covering the non-employee population that standard joiner-mover-leaver processes miss. Book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.