Resource library

    Expert insight / Temporary access

    Supplier Access Needs a Sponsor and an Ending

    A practical checklist for maintenance access, contract extensions and supplier identities that remain between engagements.

    AIdentX Editorial · · 2 min read

    At a glance

    A supplier account can outlive the work that justified it. A reliable process connects the account to a named person, an internal sponsor, a defined task and an access window that is actively managed.

    • Distinguish the supplier organisation from the individual user.
    • Make the sponsor responsible for confirming continued need.
    • Verify expiry and separately decide whether to retain the identity.

    Identify who will use the access

    Westhaven Logistics, a fictional operator, arranges a warehouse-system repair. The supplier sends a different engineer from the previous visit. Reusing the old engineer’s account would obscure who performed the work. Confirm the named individual and use the approved identity process.

    The internal sponsor should understand the business engagement and know when it changes. If the sponsor leaves or changes role, assign a replacement. An account with a company name but no accountable internal owner is difficult to review.

    Limit the request to the work

    Record the application, permission, task and expected end time. A six-week support contract does not necessarily justify uninterrupted administrator access for six weeks. Separate ordinary collaboration access from elevated permissions needed for a particular maintenance task.

    Before access startsWhen the work changesWhen it ends
    Confirm identity and sponsor.Review a replacement engineer.Verify effective access removal.
    Approve task and permission.Approve any extension.Close or assign exceptions.
    Set the authorised window.Reassess a broader task.Decide whether the identity itself remains needed.

    Use expiry as an operating event

    An end date should trigger a defined action, and someone should be able to confirm the outcome. If the target system cannot remove the permission automatically, assign a manual step with a named owner and evidence requirement.

    IGAX describes temporary access, lifecycle workflows and automatic revocation on its website. Confirm how these work with the chosen supplier identity source and application. A contractor may not be represented in the same HR feed as an employee, so ownership of end-date changes needs particular attention.

    Handle extensions without losing control

    Ask what work remains, why more time is needed and whether the original permission is still appropriate. Record the new approval and end time. Repeated short extensions can indicate an ongoing service relationship that needs a different, explicitly governed arrangement.

    Retaining a supplier identity for future engagements is different from retaining its current permissions. The organisation may choose to keep a recognisable identity record while requiring a fresh authorised grant for the next task. Review the actual deployment options and business requirements.

    After the work, connect the access record to the service record so the owner can explain who acted and under whose authority. Do not treat a closed maintenance ticket as proof that access ended.

    Published by AIdentX Editorial. Illustrative scenarios are fictional and do not represent customer results.

    Continue reading

    Explore the platform behind the guidance. Explore IGAX capabilities.