Contractors

Contractor access without opening the whole network

A contractor joins a project for a few weeks and needs CRM, admin tools or customer portals. A device-wide VPN gives more reach than the job requires and is hard to clean up when the engagement ends.

Real-world situation

A finance contractor needs the order dashboard and one customer portal for three weeks. The security team wants the work to start today, but does not want to install a device VPN, expose internal ranges or keep broad access alive after the contract ends.

What buyers worry about

  • VPN reaches more than the contractor needs, especially on an unmanaged laptop.
  • Shared accounts or remembered credentials are hard to clean up after a short engagement.
  • Security review needs a clear answer to what is routed, logged, revoked and left outside the product boundary.

What you control

Control the verified user, browser routing policy, work domains, domain/category rules, allowed egress region, active sessions, and admin revoke.

What stays outside

The contractor's personal apps, files, calls, banking, local tools, and non-browser traffic stay outside the proxy path. On unmanaged devices, other browsers or unmanaged browser profiles are outside the product boundary.

Review

What administrators can verify

  • Contractors can start with browser-based access instead of receiving a device-wide VPN.
  • Session credentials expire in minutes and can be revoked by an admin at any time.
  • Each session is tied to a verified user and registered device.
  • Domain and category rules are enforced without decrypting HTTPS page content.
  • Selected internal apps can be opened separately through the portal with App Gateway.

Success signals

  • The contractor can open only the approved work sites or assigned internal apps.
  • The project owner can see session history and revoke access when the engagement ends.
  • Personal applications and non-browser traffic stay outside BusinessProxy.

Rollout

What the workflow looks like

  1. Invite the contractor with a work email and assign them to the project workspace.
  2. Choose the browser routing policy: private apps only, work scope, or all-browser traffic.
  3. Let the contractor start from the browser extension or the app portal, depending on the access path.
  4. Review session history during the project and revoke active sessions when the work ends.

FAQ

Does the contractor need a VPN?

No. For this managed-browser scenario, the contractor uses the BusinessProxy browser extension. For selected internal web apps, App Gateway can open the app from the BusinessProxy portal without requiring the extension.

What happens when the project ends?

Admins can revoke active sessions and remove future access from the account. Session credentials are short-lived, so existing proxy credentials expire if they are not refreshed.

Can the contractor reach internal networks?

The extension path is for managed work browsing. Access to selected internal web apps is handled by App Gateway through a portal launch, public app address and outbound connector.

Related use cases

Contractor access without opening the whole network