Start with the job
The FTC advises businesses to limit vendor access to what the work requires and to the period needed to do it. It also suggests a separate database containing only the information a vendor needs. This is established access guidance, not a report of a new breach. [1]
- Purpose: the work to complete
- Scope: the resources it needs
- End: when access is removed
Permission is narrower than identity
NIST’s glossary describes least privilege as granting only the system resources and authorizations needed for a task. The FTC separately calls for multi-factor authentication for vendors. These address different questions: establishing access through a login and limiting the work that access permits. [1] [2]
Check the arrangement over time
The FTC recommends setting security expectations in vendor contracts, verifying that vendors follow them and updating controls as threats change. A time limit belongs alongside that ongoing oversight. The guidance does not make a successful login or a signed contract proof that the vendor’s security is adequate. [1]
Go a little deeper
Optional reading · about 1 more minute
A bounded maintenance visit
Hypothetical example: A contractor needs to diagnose a reporting fault. The agreed task requires a limited project view during a maintenance window, not permanent access to every customer record. The team can name both the required work and the access it should remove afterward; actual permissions depend on the system.
Make the boundary reviewable
Our interpretation: Write the access request so someone else can understand its purpose, scope and end condition. That gives the later review something concrete to check. This explainer describes a principle, not a configuration recipe or assurance that any particular system is secure.
Original sources
Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.
- FTC: vendor security for small business ↗
Current Vendor Security section read in Chrome September 22, 2026. Page publication date not independently established in this run; existing guidance, not fresh incident news.
- NIST CSRC: least privilege ↗
Glossary definitions read September 22, 2026; publication date not shown. Definition corroboration only, not a compliance assessment.