Identity Governance for Contractors: Avoiding Hidden Access Debt
Contractors, locums, students and vendor engineers arrive through doors HR never sees, so nothing tells the identity system when they leave. How to give non-employees an expiry date.
GuardsArm Team
Security Experts
Employee offboarding usually works, because HR is the trigger and the process is well worn. Everyone else is the problem. Locums, agency nurses, students on placement, research collaborators, vendor engineers and consultants all get accounts — and almost none of them appear in the HR system that drives deprovisioning. Nothing tells identity management when they stop coming.
Sponsorship is the mechanism that works
Every non-employee account needs a named employee who owns it. Not a department, not a distribution list — a person, who is accountable for whether it should still exist.
The sponsored account model:
- A named sponsor, recorded on the account itself
- A mandatory end date at creation, with a hard maximum (90 days is a reasonable default; some estates use the contract end date where it is known)
- Automatic disable at expiry, with no manual step required
- Renewal by positive action from the sponsor, not by silence
- Sponsor changes when they leave — orphaned sponsorship is its own failure mode
The lifecycle, for people HR does not track
That warning about copying permissions deserves emphasis. "Make them the same as Dr Patel" is the fastest way to provision and the most common cause of a contractor holding access to systems they have never needed. Provision from a role definition.
Finding what is already there
Before improving the process, measure the existing debt. Queries worth running against the directory today:
| Query | What it finds |
|---|---|
| Accounts with no expiry date set | The baseline problem |
| Enabled accounts with no sign-in for 90+ days | Dormant, likely departed |
| Accounts whose sponsor has themselves left | Orphaned sponsorship |
| Accounts created outside the standard process | Shadow provisioning paths |
| Non-employee accounts with privileged group membership | The highest-risk subset |
| Vendor accounts with interactive login rights | Should usually be brokered instead |
Disable dormant accounts rather than deleting them: it is reversible within minutes if you get one wrong, which makes the change far easier to get approved.
Vendor accounts are a special case
Manufacturer and supplier engineers should generally not hold standing interactive accounts at all. Broker their access instead — time-boxed, named, recorded, opened on request and closed automatically. That belongs in the contract, which is covered alongside device support in IoMT security.
Where to start
Run the "enabled, no sign-in for 90 days" query. It takes minutes, it needs no project approval, and on most hospital directories it returns a number that makes the case for the rest of the programme on its own.
GuardsArm runs identity governance reviews covering the non-employee population that standard joiner-mover-leaver processes miss. Book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


