Give Contractors Access Without Giving Them Your Network
Third parties often need access to one application, one environment, or one project—not standing access to the surrounding network.
ZTXGate lets organizations provide contractors and external users with access to approved resources, limit that access by policy and time, and keep a record of what happened.
The Contractor Access Problem
Contractor and vendor access is difficult because the user is temporary while the systems they need may be highly sensitive.
Traditional approaches can leave organizations managing a collection of:
- temporary VPN accounts
- firewall rules
- shared credentials
- manually tracked expiration dates
- unmanaged personal devices
- one-off access exceptions
The underlying problem is usually simple:
This person needs access to these specific resources for this specific period of time.
ZTXGate is designed to express that requirement directly.
Give Access to Resources, Not the Surrounding Network
ZTXGate policies can define which protected resources a contractor is allowed to reach.
That might be:
- one private web application
- a development system
- an administrative interface
- a project-specific environment
- a limited set of infrastructure resources
Everything outside the contractor's policy remains unavailable through ZTXGate.
This reduces the need to treat temporary network connectivity as the permission itself.
Clientless Access for Web Applications
If a contractor only needs a private HTTP or HTTPS application, ZTXGate can provide browser-based access through its clientless proxy.
That means the contractor does not need WireGuard connectivity software simply to reach the approved web application.
ZTXGate authenticates and authorizes the access path before connecting the user onward to the protected resource.
Client-Based Access When the Work Requires It
Some contractor tasks require protocols or resources beyond HTTP/HTTPS.
For those cases, managed or enrolled endpoints can use ZTXGate's WireGuard-based connectivity for the resources allowed by policy.
This lets the access model follow the actual work:
- browser-only application → clientless access
- broader protocol requirement → client-based access
The contractor does not need more connectivity than the task requires.
Time-Bound Access
Temporary users should not accumulate permanent permissions.
ZTXGate can grant access for a defined period so the permission expires automatically when the approved window closes.
This is useful for:
- short consulting engagements
- maintenance windows
- vendor troubleshooting
- temporary developers
- audit or assessment work
- project-based access
The expiration is part of the access policy rather than a reminder someone must remember later.
Request and Approval
Sensitive resources can require an approval workflow before access is granted.
A contractor or user requests access, an authorized approver decides whether to permit it, and the approved window can be limited to the time required for the task.
That combines:
Who is asking? → Which resource? → Who approved it? → For how long?
with the access record maintained by ZTXGate.
Identity and Authentication
ZTXGate can integrate with supported identity systems so contractor access can be tied to an identifiable user rather than shared credentials.
The exact onboarding model depends on the customer's identity architecture and whether the contractor identity exists in a reachable identity source.
For sensitive access, step-up authentication can be applied according to policy.
When licensed with ZTXGate, ZTXBAS is tightly integrated and can provide biometric authentication across connected and air-gapped ZTXGate deployment models without a separate ZTXBAS server. Connected environments can also use supported cloud-dependent options such as Okta Verify and Duo.
Managed vs Unmanaged Contractor Devices
A contractor's endpoint may not have the same management controls as an employee device.
That distinction should be visible in policy.
For web-only use cases, clientless access can reduce the need to install connectivity software on the contractor endpoint. For more sensitive access, organizations can require an enrolled device or available posture conditions.
The policy should match the resource sensitivity rather than assuming all contractor devices are equivalent.
Make Offboarding Predictable
Contractor access should end when the work ends.
Depending on the deployment and identity workflow, administrators can remove access by:
- allowing a temporary policy to expire
- revoking an approval
- removing or disabling the user's authorization
- revoking an enrolled device
- synchronizing identity lifecycle changes through available identity integrations
Using explicit resources and time-bound access reduces the number of persistent exceptions left behind after an engagement.
Keep a Record of Third-Party Access
ZTXGate maintains access, authentication, and policy records that can support questions such as:
- Which contractor accessed a protected resource?
- When did access begin?
- Was the access approved?
- Which device was involved?
- When did the permission expire?
Relevant events can also be exported to supported SIEM platforms where connectivity exists.
This helps third-party access become part of the organization's normal monitoring and review process.
Contractor Access in Air-Gapped Environments
An isolated environment can still have temporary users and third-party personnel working inside its approved boundary.
ZTXGate can apply the same resource and time-based access concepts without requiring a CoreZT-hosted control plane.
Integrated ZTXBAS can also provide phishing-resistant biometric authentication inside the isolated ZTXGate deployment without requiring a separate ZTXBAS server.
External cloud identity, MDM, EDR, SIEM, or authentication services are available only when the network architecture intentionally makes them reachable.
Example: Temporary Vendor Maintenance
Consider a vendor that needs a private administrative web application for a two-hour maintenance window.
A ZTXGate policy can be designed so that:
- the vendor has an identifiable user account
- the private application is the only approved resource
- access requires approval
- access lasts only for the maintenance window
- step-up authentication is required if appropriate
- access activity is recorded
- the permission expires automatically
If the vendor instead needs a non-web protocol, the same resource/time principles can be applied using the appropriate client-based access path.
Frequently Asked Questions
Do contractors need network-wide VPN access?
Not when their work only requires specific protected resources. ZTXGate can authorize the resources directly.
Can contractors use a browser without installing WireGuard?
Yes, for private HTTP and HTTPS applications exposed through the ZTXGate clientless proxy.
What if the contractor needs SSH, RDP, or another non-web protocol?
Use the ZTXGate client-based access model for supported network resources rather than the clientless HTTP/HTTPS path.
Can contractor access expire automatically?
Yes. Temporary access can be bounded to a defined access period.
Can we require approval before a contractor reaches a sensitive system?
Yes. Request-and-approve workflows can be used for resources where explicit approval is required.
Does ZTXGate automatically create contractor identities from social providers?
The site does not claim that behavior. Contractor identity follows the supported identity and provisioning model configured by the customer.
Make Temporary Access Actually Temporary
Give contractors access to the work they need, limit the access to the right resources and time period, and keep the activity visible.