Contractor security onboarding checklist for small teams: your freelancer is a new hire you forgot to onboard

Small teams onboard external people constantly — a designer for the rebrand, a contractor for the migration sprint, a part-time bookkeeper, a dev shop for the app — and almost never onboard them as security decisions. The employee gets an orientation day; the freelancer gets a Slack invite and the wifi password. Three weeks later that person holds accounts, seats, and secrets that nobody inventoried, and when the engagement ends, half of it stays behind. This checklist is the fifteen-minute version of doing it right: scope the access, route the secrets through the password manager, write the security clause, stamp every grant with an end date, and run the revocation with the same discipline you'd use for a full-time employee offboarding.

1. Before day one: the decision that gates everything else

2. The accounts (create these, exactly these)

3. Scope like a vendor, not a teammate

4. The secrets you hand over (and how)

5. The paper trail (cheap now, priceless later)

6. Machines and networks (their laptop is your new office)

7. The audit trail (what your future self needs)

8. The end date (revocation day is part of onboarding)

9. Production, sensibly

10. When something goes wrong anyway

Contractor security in a small team is one page: the scoping sentence, named accounts, vault-routed secrets, the ten-line clause, expiry dates, and a revocation day that actually happens. The Ops Starter Kit ($14) includes the access-audit sheets that turn this into a per-engagement table — account, scope, issued, expiry, owner — and the Automation Starter Pack ($19) automates the expiry checks so grants end when the contract says they end. Launch week: 30% off any paid kit with code HIVE-LAUNCH30 at checkout.