### Purpose

Use this checklist when contractors, consultants, temporary employees, freelancers, agency personnel, or other non-permanent workers require access to company systems or information.

The objective is to give external or temporary personnel only the access they need, for only as long as they need it.

### Worker Information

Name: ____________________

Company / agency: ____________________

Internal sponsor: ____________________

Project or purpose: ____________________

Start date: ____________________

Expected end date: ____________________

Access owner: ____________________

### Before Access Is Granted

- [ ]  Business need confirmed.
- [ ]  Internal sponsor assigned.
- [ ]  Systems required identified.
- [ ]  Data required identified.
- [ ]  Access level defined.
- [ ]  Access approved.
- [ ]  Confidentiality or contractual requirements completed where applicable.
- [ ]  End date recorded.
- [ ]  High-risk access separately approved.

### Account Requirements

- [ ]  Named account created where practical.
- [ ]  Shared accounts avoided.
- [ ]  MFA enabled.
- [ ]  Password requirements applied.
- [ ]  Access limited to required systems.
- [ ]  Privileged access avoided unless necessary.
- [ ]  Temporary access expiry configured where possible.
- [ ]  Remote access restricted appropriately.
- [ ]  Approved device requirements applied where necessary.

### Data Access

- [ ]  Sensitive data access specifically approved.
- [ ]  File sharing limited to required locations.
- [ ]  Public sharing restricted.
- [ ]  Personal email prohibited for company information.
- [ ]  Personal cloud storage prohibited for company information.
- [ ]  Download/export permissions restricted where appropriate.

### Security Expectations

**Contractor informed of:**

- [ ]  Acceptable Use Policy.
- [ ]  Password and MFA requirements.
- [ ]  Data handling requirements.
- [ ]  Approved tool requirements.
- [ ]  Security incident reporting process.
- [ ]  Lost-device reporting.
- [ ]  Prohibition on credential sharing.
- [ ]  Relevant customer or contractual security requirements.

### During the Engagement

- [ ]  Access reviewed if project scope changes.
- [ ]  Additional access formally approved.
- [ ]  Privileged access reviewed regularly.
- [ ]  Long-running contractor access periodically reconfirmed.
- [ ]  Suspicious activity escalated through normal incident procedures.

### End of Engagement

**Confirm:**

- [ ]  Account disabled or removed.
- [ ]  VPN access removed.
- [ ]  SaaS access removed.
- [ ]  Administrator access removed.
- [ ]  Shared account access removed.
- [ ]  Credentials rotated where necessary.
- [ ]  Company devices returned.
- [ ]  Security keys returned.
- [ ]  Company data returned or retained appropriately.
- [ ]  External copies of company data removed where contractually required.
- [ ]  File ownership transferred.
- [ ]  Vendor portals updated.
- [ ]  Access register updated.

Access removed by: ____________________

Removal date: ____________________

Internal sponsor confirmation: ____________________

Evidence location: ____________________

### Practical Rule

Temporary workers should receive temporary, controlled access.

Their access should have an owner, a business reason, appropriate protection, and a clear end date.
