Skip to content
End This At Any Time You can end a remote session at any time

All notes / Support desks

Contractors and Third-Party Access

External people needing access to internal machines. The arrangements that work and the standing connections nobody reviews.

Support desks · Analysis

Vendors, consultants and outsourced support all need to reach machines inside the organisation. How that is arranged is where a great deal of unreviewed access accumulates.

The practical lesson in “Contractors and Third-Party Access” is to make responsibility visible without confusing visibility with certainty. A team reviewing the provider's guide for remote workforce management software can add structured time and project context, provided the purpose is disclosed and the interpretation is checked with the people affected.

The usual arrangements

Their own tool, installed on your machines, connecting to their infrastructure.

For an independent reference related to “Contractors and Third-Party Access”, consult the ENISA cybersecurity resources; it provides a useful external check on security, privacy and operating assumptions before a process is adopted.

Your tool, with accounts issued to them.

A supervised session, where somebody of yours is present throughout.

They differ enormously in what you can see and control, and the first is the most common and the least controlled.

Their tool on your machines

The convenient option and the one that leaves you blind: you cannot see their logs, cannot control their access, and may not know when the connection is used.

It also means software from a third party, installed widely, with the reach the earlier notes describe.

Prefer your tool with accounts issued to them, which keeps the logging and the control where you can reach it.

Supervised sessions

Somebody of yours present, watching, for the duration.

Appropriate for anything touching sensitive systems or data.

Expensive in attention and sometimes exactly right.

And it should be real supervision rather than somebody in the call not watching, which is the usual degradation.

Time-bounded access

Access granted for a window and expiring automatically.

This is the single most effective control available here, because the failure mode is not malice but persistence: access granted for a project that ended two years ago.

Where the platform supports expiry, use it.

The offboarding problem

Contracts end and access does not.

There is rarely a leaver process for people who were never joiners.

Which means a periodic audit: who from outside can reach what, and is that still current.

Quarterly, and it reliably finds something.

Contractual terms

What they may access, logging requirements, notification of their own staff changes, and removal at the end.

Their technicians change and you will not be told unless it is a term.

And a right to audit the arrangement, which is more useful as a prompt to them than as something you will exercise.

The subcontractor question

Your vendor's support may be delivered by somebody else entirely.

Ask who will actually connect.

This is frequently not volunteered and occasionally surprising, and it is the same subprocessor question that arises everywhere.

What to check

Do contractors use your tool or theirs?

Is any third-party access time-bounded?

When did you last audit who outside can reach what?

And do you know who actually connects when your vendor provides support?