Contractor Identity
A contractor identity is the digital identity an organization creates for a non-employee worker, such as an independent contractor or temporary service provider, so that person can access company systems and resources. Because contractors are not regular employees, their access typically needs to be set up, monitored, and removed on a defined schedule tied to their engagement. Managing these identities carefully helps prevent lingering or unauthorized access after a contract ends.
A contractor identity is a class of non-employee identity representing an external, contract-based worker (for example, an independent contractor providing services under an agreement) within an organization's identity ecosystem. In IGA terms, contractor identity management encompasses the provisioning, governance, and deprovisioning of access for these non-employee users, and typically differs from employee identity in that the authoritative source is often not the HR system of record, engagements are time-bound, and lifecycle events map to contract start and end dates rather than employment status. This is primarily a lifecycle and governance concern, covering onboarding, entitlement assignment, periodic access review, and timely deprovisioning to reduce orphaned or excessive access, and is distinct from runtime authentication and authorization enforcement, which apply to contractor identities as they would to any principal. Depending on deployment, contractor identities may be represented in a directory (for example an LDAP or cloud directory) and governed through SCIM-based or connector-based provisioning; the specific attributes and controls vary by vendor and configuration. Note that external identifiers such as tax or federal contracting numbers (SSN, EIN, or DUNS) are business or regulatory identifiers for the contracting entity and should not be conflated with the digital identity or authentication credentials used for system access.
Why it matters
Contractor identities represent one of the most persistent sources of access risk in an identity program because they sit outside the normal employee lifecycle. Regular employees are typically driven by an HR system of record that fires clear onboarding and termination events; contractors and other non-employee workers often have no such authoritative source, engage under time-bound agreements, and may be managed inconsistently across teams or business units. When a contract ends but the associated access is not promptly removed, the result is orphaned or lingering access that an organization no longer intends to grant, expanding the attack surface and undermining least-privilege objectives.
Because contractor engagements map to contract start and end dates rather than to employment status, governance controls such as periodic access review, entitlement certification, and timely deprovisioning are especially important for this population. Without deliberate lifecycle management, contractor accounts can accumulate excessive entitlements or persist well beyond the engagement they were created for. Treating contractor identity as a distinct governance concern, separate from the runtime enforcement that applies to any principal, helps organizations reduce the risk of unauthorized or stale access.
Who it's relevant to
Inside Contractor Identity
Common questions
Answers to the questions practitioners most commonly ask about Contractor Identity.
