THE MACHINE THRESHOLD
Cybersecurity / EXPLAINER / 2 MIN READ + OPTIONAL DEEP DIVE

A vendor needs access. How much—and for how long?

A useful connection has a job, a boundary and an ending. Knowing who signed in does not settle what they should be allowed to do.

AI-assisted synthesis · Published 2026-09-22 · Updated & sources checked 2026-09-22
How we research and correct our work

A trusted working relationship still needs specific limits on the connection it opens.

Start with the job

The FTC advises businesses to limit vendor access to what the work requires and to the period needed to do it. It also suggests a separate database containing only the information a vendor needs. This is established access guidance, not a report of a new breach. [1]

Give a connection a clear boundary
  1. Purpose: the work to complete
  2. Scope: the resources it needs
  3. End: when access is removed
Access control and vendor oversight work together

Permission is narrower than identity

NIST’s glossary describes least privilege as granting only the system resources and authorizations needed for a task. The FTC separately calls for multi-factor authentication for vendors. These address different questions: establishing access through a login and limiting the work that access permits. [1] [2]

Check the arrangement over time

The FTC recommends setting security expectations in vendor contracts, verifying that vendors follow them and updating controls as threats change. A time limit belongs alongside that ongoing oversight. The guidance does not make a successful login or a signed contract proof that the vendor’s security is adequate. [1]

Go a little deeper

Optional reading · about 1 more minute

A bounded maintenance visit

Hypothetical example: A contractor needs to diagnose a reporting fault. The agreed task requires a limited project view during a maintenance window, not permanent access to every customer record. The team can name both the required work and the access it should remove afterward; actual permissions depend on the system.

Make the boundary reviewable

Our interpretation: Write the access request so someone else can understand its purpose, scope and end condition. That gives the later review something concrete to check. This explainer describes a principle, not a configuration recipe or assurance that any particular system is secure.

Original sources

Attributed synthesis, not original reporting. Examples labeled hypothetical or illustrative are explanatory. Reviewing a source does not independently validate its findings.

  1. FTC: vendor security for small business ↗

    Current Vendor Security section read in Chrome September 22, 2026. Page publication date not independently established in this run; existing guidance, not fresh incident news.

  2. NIST CSRC: least privilege ↗

    Glossary definitions read September 22, 2026; publication date not shown. Definition corroboration only, not a compliance assessment.

Suggest a correction

Know someone who would find this interesting?

Share this story on Facebook ↗ ·

Follow on Facebook ↗ for story highlights and questions to explore next.

Where this question leads next

Follow new explainers and updates →