Blog · Operations

Contractor Offboarding: Revoke Document Access in Hours

SSO disable is not enough. A same-day runbook to revoke sealed shares, guest Drive links, and shared passwords when contractors leave—plus share design that makes offboarding mechanical.

· 11 min read · Compliance Locker

Most offboarding checklists cover badge, laptop, and SSO. Document access is often an afterthought—until a former contractor still opens last quarter’s diligence folder from a link in their personal email.

This playbook shows how to revoke sensitive document access in hours, not weeks, and how to design shares so offboarding is mechanical instead of forensic.

Where leftover access actually hides

  • Guest links on Drive, Box, and Dropbox that outlive the SOW
  • Email attachments and forwarded threads
  • Password-protected ZIPs with passwords in Slack history
  • Sealed links that were minted with “never expires”
  • Personal devices that synced offline copies

SSO disable is necessary and insufficient. You need a share inventory and a revoke path for every high-sensitivity packet.

Design shares for offboarding day-one

Per-engagement links

One contractor, one packet set, one end date. Do not reuse a mega-folder across vendors—see why in sealed sharing patterns.

Expiry by default

Align share expiry to the SOW end date plus a short grace window. Make extensions an explicit action.

Named owners

Every sealed share needs an internal owner who can revoke without hunting through chat logs.

Activity you can export

When legal asks whether the contractor opened the packet after termination, screenshots will not help. Prefer vault activity—see audit trail expectations.

Offboarding runbook (same day)

  1. Disable SSO / IdP groups for the contractor
  2. Revoke all vault shares owned for that engagement
  3. Remove guest access on collaboration drives for project folders
  4. Rotate any shared passwords that touched the engagement
  5. Export vault activity for the engagement window into the HR ticket
  6. Confirm with the packet owner—no “I’ll check next week”

Compliance Locker makes the vault half of this mechanical: sealed shares with revoke, expiry, and exportable activity. Pair it with your IdP and Drive guest cleanup so nothing is left to tribal knowledge.

What not to rely on

  • “They’re trustworthy” as a substitute for revoke
  • Quarterly access reviews as the only control
  • Email recall or “please delete that file” messages
  • A single shared password for all contractors on a project

FAQ

Is disabling SSO enough?

It stops new logins to apps behind SSO. It does not revoke sealed links already in a contractor’s inbox, shared Drive folders they still open as a guest, or ZIP passwords they saved locally.

How fast should document revoke happen?

Treat high-sensitivity packets like credentials: hours, not the next quarterly access review. Align with your HR/offboarding SLA for badge and laptop return.

What if we only used email attachments?

You cannot reliably unsend. Move future shares to sealed links with revoke, and document residual risk for historical attachments in the offboarding record.

Do watermarks help after offboarding?

They deter casual redistribution and aid attribution. They do not retrieve files already downloaded. Revoke and short expiry matter more.

Should contractors share one eternal project folder?

No. Per-engagement sealed packets with end dates prevent the classic ‘contractor left six months ago and the folder is still open’ failure.

Related: Stop emailing sensitive attachments, diligence rooms without shared Drive.