[{"data":1,"prerenderedAt":272},["ShallowReactive",2],{"globals":3,"cookie-settings":203,"resource-contractor-access-closeout":236,"resource-related-contractor-access-closeout":261},{"id":4,"title":5,"description":6,"logo_light":7,"logo_dark":7,"address":7,"contact_email":8,"contact_phone":7,"header_menu":9,"footer_menu":10,"favicon":7,"public_url":11,"meta_title":12,"meta_description":13,"robots":14,"head_scripts":15,"body_scripts":16,"default_header":17,"default_footer":169,"social_links":7},1,"CredenShare","Secure credential sharing for modern teams. Encrypted in your browser, with time-limited, access-controlled links.",null,"hello@credenshare.io","fafb0437-6fc7-409e-bcce-a2519eacef43","96f782ae-6d59-4601-abd1-a4fca64cc4de","https://credenshare.io","CredenShare - Secure Credential Sharing","Share passwords, API keys and secrets securely with CredenShare. Encrypted in your browser, time-limited access, and detailed access logs.","# CredenShare Robots.txt\nUser-agent: *\nAllow: /\n\n# Sitemap\nSitemap: https://credenshare.io/sitemap.xml\n\n# Disallow admin paths\nDisallow: /api/\nDisallow: /admin/\nDisallow: /dev/\n\n# Allow main content\nAllow: /blog/\nAllow: /features/\nAllow: /pricing/\nAllow: /security/\nAllow: /docs/\n\n# Crawl-delay\nCrawl-delay: 1\n",[],[],{"id":18,"sort":7,"user_created":19,"date_created":20,"user_updated":19,"date_updated":21,"name":22,"logo":7,"show_cta":23,"cta_label":24,"cta_link":25,"cta_style":26,"sticky":23,"transparent":27,"navigation":28},"d16d4c9e-b3f8-4ea8-988b-eab863efb29c","e7d5f744-1dbd-47ad-9e01-63a9303d109e","2026-02-03T16:36:10.957Z","2026-08-17T22:46:13.371Z","Default Header",true,"Get Started","https://app.credenshare.io/register","primary",false,{"id":9,"sort":7,"user_created":19,"date_created":29,"user_updated":7,"date_updated":7,"title":30,"location":31,"items":32},"2026-02-03T16:36:40.078Z","Main Navigation","main-menu",[33,43,51,56,63,71,78,81,88,96,101,108,115,123,130,135,142,146,153,161],{"id":34,"sort":4,"user_created":19,"date_created":35,"user_updated":19,"date_updated":36,"label":37,"type":38,"url":39,"parent":40,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":41,"description":42,"badge":7},"8a9a4df2-3f19-4897-948a-a4d520b9389b","2026-02-11T11:19:20.202Z","2026-08-17T22:46:13.538Z","Documentation","custom","https://docs.credenshare.io","bf76488c-e318-48a2-8561-c32f76c61383","i-heroicons-book-open","Guides and API reference",{"id":44,"sort":4,"user_created":19,"date_created":45,"user_updated":7,"date_updated":7,"label":46,"type":38,"url":47,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":49,"description":50,"badge":7},"fd3cae1e-592b-413d-91e5-b1258e0aff49","2026-02-11T11:19:16.508Z","Team Onboarding","/solutions/team-onboarding","daee37a1-a164-4b63-be67-1f91e4e9b497","i-heroicons-user-plus","Securely onboard new team members",{"id":52,"sort":4,"user_created":19,"date_created":53,"user_updated":7,"date_updated":7,"label":54,"type":55,"url":7,"parent":7,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"0a887c3c-a748-4217-9e34-daf852801d4e","2026-02-11T11:19:13.606Z","Product","dropdown",{"id":57,"sort":4,"user_created":19,"date_created":58,"user_updated":7,"date_updated":7,"label":59,"type":38,"url":60,"parent":52,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":61,"description":62,"badge":7},"1ee916dd-34a1-41fc-ad80-64681d2440ed","2026-02-11T11:19:14.086Z","Features","/features","i-heroicons-sparkles","Everything CredenShare offers",{"id":64,"sort":65,"user_created":19,"date_created":66,"user_updated":7,"date_updated":7,"label":67,"type":38,"url":68,"parent":52,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":69,"description":70,"badge":7},"6eb63ded-6ac9-4595-a55f-8795b193fe04",2,"2026-02-11T11:19:14.648Z","How It Works","/how-it-works","i-heroicons-play-circle","See CredenShare in action",{"id":72,"sort":65,"user_created":19,"date_created":73,"user_updated":7,"date_updated":7,"label":74,"type":38,"url":75,"parent":40,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":76,"description":77,"badge":7},"719ce073-d71f-4450-b45a-f08a05db21b2","2026-02-11T11:19:20.640Z","About","/about","i-heroicons-information-circle","Our mission and team",{"id":48,"sort":65,"user_created":19,"date_created":79,"user_updated":7,"date_updated":7,"label":80,"type":55,"url":7,"parent":7,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"2026-02-11T11:19:16.058Z","Solutions",{"id":82,"sort":65,"user_created":19,"date_created":83,"user_updated":7,"date_updated":7,"label":84,"type":38,"url":85,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":86,"description":87,"badge":7},"63e46db0-4bed-4f24-b7bd-a79e821f3d89","2026-02-11T11:19:16.976Z","Third-Party Access","/solutions/third-party-access","i-heroicons-users","Safe contractor credentials",{"id":89,"sort":90,"user_created":19,"date_created":91,"user_updated":7,"date_updated":7,"label":92,"type":38,"url":93,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":94,"description":95,"badge":7},"1cf2f869-1bb4-447a-b9d7-738b45995379",3,"2026-02-11T11:19:17.466Z","Credential Collection","/solutions/secure-requests","i-heroicons-inbox-arrow-down","Request credentials securely",{"id":97,"sort":90,"user_created":19,"date_created":98,"user_updated":7,"date_updated":7,"label":99,"type":38,"url":100,"parent":7,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"790829b5-6e85-45a2-b729-01a224f1c816","2026-02-11T11:19:18.867Z","Pricing","/pricing",{"id":102,"sort":90,"user_created":19,"date_created":103,"user_updated":7,"date_updated":7,"label":104,"type":38,"url":105,"parent":40,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":106,"description":107,"badge":7},"567bc13d-4499-4dc5-a346-5eba54c1c500","2026-02-11T11:19:21.085Z","Tools","/tools","i-heroicons-wrench-screwdriver","Free security & developer tools",{"id":109,"sort":90,"user_created":19,"date_created":110,"user_updated":7,"date_updated":7,"label":111,"type":38,"url":112,"parent":52,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":113,"description":114,"badge":7},"5c9151ac-94e1-4d54-8032-768568b9ad02","2026-02-11T11:19:15.116Z","Security","/security","i-heroicons-shield-check","Our security architecture",{"id":116,"sort":117,"user_created":19,"date_created":118,"user_updated":7,"date_updated":7,"label":119,"type":38,"url":120,"parent":52,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":121,"description":122,"badge":7},"d7882f47-9f94-4860-93df-0025ff5ac8bc",4,"2026-02-11T11:19:15.577Z","Integrations","/integrations","i-heroicons-puzzle-piece","Slack, API, and more",{"id":124,"sort":117,"user_created":19,"date_created":125,"user_updated":7,"date_updated":7,"label":126,"type":38,"url":127,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":128,"description":129,"badge":7},"2ac2df39-fbae-45a2-b87a-313bebb4a87b","2026-02-11T11:19:17.957Z","Development Teams","/solutions/development-teams","i-heroicons-code-bracket-square","Secure credentials for dev workflows",{"id":131,"sort":117,"user_created":19,"date_created":132,"user_updated":7,"date_updated":7,"label":133,"type":38,"url":134,"parent":7,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"e696e64d-65e1-4b67-aef9-60db78b9f4cf","2026-02-11T11:19:19.313Z","Blog","/blog",{"id":136,"sort":117,"user_created":19,"date_created":137,"user_updated":7,"date_updated":7,"label":138,"type":38,"url":139,"parent":40,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":140,"description":141,"badge":7},"1f787a64-8e12-484d-ae97-b6349bc82e52","2026-02-11T11:19:21.524Z","Pastebin","https://paste.credenshare.io","i-heroicons-clipboard-document","Secure encrypted pastebin",{"id":40,"sort":143,"user_created":19,"date_created":144,"user_updated":7,"date_updated":7,"label":145,"type":55,"url":7,"parent":7,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},5,"2026-02-11T11:19:19.768Z","Resources",{"id":147,"sort":143,"user_created":19,"date_created":148,"user_updated":7,"date_updated":7,"label":149,"type":38,"url":150,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":151,"description":152,"badge":7},"e18246ff-9a00-449a-88f8-09490a3cead2","2026-08-24T23:17:28.605Z","Vendor Access","/solutions/vendor-access","i-heroicons-building-office-2","Share credentials with outside vendors",{"id":154,"sort":155,"user_created":19,"date_created":156,"user_updated":7,"date_updated":7,"label":157,"type":38,"url":158,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":159,"description":160,"badge":7},"99bda669-3c3a-4521-815b-a1eb22a4098e",6,"2026-08-24T23:17:28.791Z","AI Agents","/solutions/ai-agents","i-heroicons-cpu-chip","Give agents scoped, expiring credentials",{"id":162,"sort":163,"user_created":19,"date_created":164,"user_updated":19,"date_updated":165,"label":166,"type":38,"url":167,"parent":48,"post":7,"navigation":9,"target":7,"classes":7,"page":7,"icon":151,"description":168,"badge":7},"1f06247b-4633-4341-a388-95ffa524a27a",7,"2026-02-11T11:19:18.416Z","2026-08-24T23:17:03.952Z","Enterprise","/enterprise","Compliance and audit-ready security",{"id":170,"sort":7,"user_created":19,"date_created":171,"user_updated":19,"date_updated":172,"name":173,"logo":7,"tagline":174,"show_social":23,"copyright_text":175,"show_newsletter":23,"newsletter_heading":176,"newsletter_description":177,"navigation_columns":178,"bottom_links":179},"355d9ac1-c909-4cda-9071-cd3abb00a0b5","2026-02-03T16:36:11.825Z","2026-08-25T01:10:16.097Z","Default Footer","Secure credential sharing for modern teams.","© {year} CredenShare Inc. All Rights Reserved.","Stay updated","Security insights and product updates. No spam, unsubscribe any time.",[],{"id":180,"sort":7,"user_created":19,"date_created":181,"user_updated":7,"date_updated":7,"title":182,"location":183,"items":184},"861b9a44-206d-4778-9251-f5269206fdf9","2026-02-03T16:36:41.786Z","Legal Links","legal-menu",[185,191,197],{"id":186,"sort":4,"user_created":19,"date_created":187,"user_updated":19,"date_updated":188,"label":189,"type":38,"url":190,"parent":7,"post":7,"navigation":180,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"3e16a067-ce9f-4e4d-aea6-7a602094f9df","2026-02-03T16:37:32.902Z","2026-08-25T00:24:57.325Z","Terms of Service","/legal/terms",{"id":192,"sort":65,"user_created":19,"date_created":193,"user_updated":19,"date_updated":194,"label":195,"type":38,"url":196,"parent":7,"post":7,"navigation":180,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"6e9bc58b-b6d0-46f8-8c7b-123ea3273f5b","2026-02-03T16:37:32.360Z","2026-08-25T00:24:57.850Z","Privacy Policy","/legal/privacy",{"id":198,"sort":90,"user_created":19,"date_created":199,"user_updated":19,"date_updated":200,"label":201,"type":38,"url":202,"parent":7,"post":7,"navigation":180,"target":7,"classes":7,"page":7,"icon":7,"description":7,"badge":7},"78a410a6-802d-4920-a915-d8e5d2155f0c","2026-02-03T16:37:33.462Z","2026-08-25T00:24:59.086Z","Cookie Policy","/legal/cookies",{"enabled":23,"banner_position":204,"banner_title":205,"banner_text":206,"accept_all_text":207,"decline_all_text":208,"preferences_text":209,"save_preferences_text":210,"policy_page":211,"privacy_page":213,"categories":215,"id":4},"bottom","We value your privacy","We use cookies to enhance your browsing experience, serve personalized content, and analyze our traffic. By clicking \"Accept All\", you consent to our use of cookies.","Accept All","Decline All","Manage Preferences","Save Preferences",{"slug":212},"legal/cookies",{"slug":214},"legal/privacy",[216,221,226,231],{"id":217,"name":218,"key":219,"description":220,"required":23,"default_enabled":23},"1","Essential","essential","Required for the website to function. Cannot be disabled.",{"id":222,"name":223,"key":224,"description":225,"required":27,"default_enabled":27},"2","Analytics","analytics","Help us understand how visitors interact with our website.",{"id":227,"name":228,"key":229,"description":230,"required":27,"default_enabled":27},"3","Marketing","marketing","Used to deliver relevant advertisements and track campaign performance.",{"id":232,"name":233,"key":234,"description":235,"required":27,"default_enabled":27},"4","Preferences","preferences","Remember your settings and preferences for a better experience.",{"resource_code":237,"slug":238,"title":239,"subtitle":240,"purpose":241,"summary":242,"audience":243,"topic":244,"edition":245,"edition_date":246,"body":247,"pdf_path":248,"pdf_bytes":249,"pdf_pages":90,"cover_path":250,"cover_alt":239,"templates":251,"related":258,"interactive":7},"R04","contractor-access-closeout","Contractor & Vendor Access Close-Out","A practical checklist, verification method and reusable messages","Confirm three separate facts: the task is complete, the handoff is retired, and the issuing system has ended the access that should end.","A close-out checklist, a verification method, reusable messages and an editable register for ending contractor or vendor access.","IT, project and system owners","Close out access","1.1","2026-10-03","## Close the job. Then close the access.\n**CONTRACTOR & VENDOR ACCESS CLOSE-OUT**\n\nA contractor finishing their work does not automatically end their access. Use this guide when a project ends, a supplier changes, an engagement pauses, or an access deadline arrives. It is a focused close-out aid, not a complete employee or vendor offboarding program.\n\n> **Three separate facts:** The task is complete. The handoff is retired. The issuing system has ended the access that should end. Confirm each rather than treating one as a substitute for the others.\n\n### 1. Identify what must actually end\n\n| Check | Record without the secret |\n| --- | --- |\n| Confirm the task | Case reference, authorized project owner, completion or termination decision. |\n| Find the access | Account/token identifier or restricted inventory reference; issuing system; privilege and scope. Do not record the credential value. |\n| Identify dependencies | Jobs, integrations, other users or sessions that may use the same credential. A shared key needs a coordinated replacement plan. |\n| Assign responsibility | One issuing-system owner and a backup; an explicit closure deadline and timezone. |\n| Check continuing need | Either end access or approve a narrower, time-bounded continuation. An unanswered question is not an extension. |\n\n### 2. Choose the right close-out action\n\n**Named account:** remove unnecessary permissions or disable the account under the approved process. Check active sessions and other access paths separately where applicable.\n\n**Scoped token/key:** revoke or replace it in the issuing service. For a shared credential, arrange dependent-service updates and a recovery plan before the change.\n\n**Ongoing approved work:** record a fresh approval, narrower scope where possible, an accountable owner and a new review date. Do not simply extend the delivery link.\n\n**Suspected misuse or exposure:** involve the incident lead immediately; normal scheduled close-out must not delay containment. Preserve only the evidence authorized by that process.\n\n### 3. Verify instead of assuming\n\nUse the issuing service's administrative evidence and, where safe and authorized, a controlled check that the old access no longer works. Do not ask a former contractor to log in as your proof. Record sessions, cached access or downstream copies that remain unresolved.\n\n**Reference:** These are original operating instructions applying the distinction between revocation and expiration described in [OWASP Secrets Management](https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html). Follow your system, incident and records policies.\n\n## Finish the handoff and communicate\n\n### 4. Retire the delivery route separately\n\nAfter any authorized retrieval or evidence collection, retire the share or collection route using its supported controls. Do not retire a collection request until the responses still needed have been handled. In CredenShare, a request that reaches its own **Expires On** date only closes the form, but expiring or deleting it in the app destroys the content of every response it still holds, and only the request's creator can open them. Open each needed response and move the value to its approved destination first; export cannot decrypt end-to-end encrypted responses. [C1]\n\nDo not claim that an expired share removed somebody's downloaded copy, revoked their token, or ended every session. Ask the recipient to follow the agreed local-copy disposal process; retain their acknowledgment as a report, not a forensic guarantee.\n\n### 5. Use a clear status\n\n| Status | Meaning |\n| --- | --- |\n| OPEN | Closure has been assigned but is not verified. |\n| IN_PROGRESS | The owner is performing the approved change. |\n| VERIFIED_CLOSED | The required source action is evidenced and remaining limitations are recorded. |\n| APPROVED_EXTENSION | Continued access has a new approval and review date. This is not closure. |\n| EXCEPTION | A dependency, disputed authority, missing record or test failure needs an owned action. |\n\n### Message to the issuing-system owner\n\n> Case [reference] has reached its access end point. Please review [restricted access reference], confirm dependencies, perform the approved closure, and record the verification reference by [time and timezone]. Do not include the credential or a live reading link in your reply. Report any reason the required access cannot yet be ended.\n\n### Message to the contractor or vendor\n\n> The approved task for [case reference] has ended. Please stop using the associated access and follow our agreed handling instructions for local copies. Confirm completion without repeating any secret. Further work requires a new authorization; this message does not extend access.\n\n### Message when continuation is approved\n\n> Continued access for [case reference] is approved for [specific purpose] until [date/time/timezone], with [owner] responsible. The scope is [approved scope]. The next review is [date]. This replaces the previous access deadline, not the rules on storing or forwarding credentials.\n\n[C1] [CredenShare Secure Requests](https://docs.credenshare.io/guides/secure-requests). Product-specific behavior must match the route in use. No customer result is asserted by this guide.\n\n## A worked close-out\n**FICTIONAL TEACHING EXAMPLE — NOT CUSTOMER EVIDENCE**\n\nA contractor finishes a test-environment connector repair. Their token also powers a scheduled test job. Immediately revoking it without checking that dependency would stop the job.\n\n| Stage | Decision and safe reference |\n| --- | --- |\n| Task ends | The project owner marks CASE C-204 complete at 14:00 UTC. Access is due to end at 16:00 UTC. |\n| Dependency found | The system owner records that JOB-J17 uses the same token. The token value is not copied into the register. |\n| Controlled change | The owner issues a separate job credential under the approved process, updates the job and verifies its next test. |\n| Source closure | The contractor token is revoked at 15:20 UTC. Restricted record REV-C204 supports the change. A permitted check rejects the old token. |\n| Handoff retirement | The operator retires the original delivery route after confirming the operational need has ended. |\n| Final note | The packet supports closure of the identified token and delivery route. It does not prove every contractor-held file has been destroyed. |\n\n### Use the companion register\n\nThe companion workbook `access-closeout-register.xlsx` provides an empty working register, a separate fictional example and a small status summary. Keep it in restricted storage once populated. It is not a secrets inventory.\n\nRecord one row per independently controlled access grant. Use case references rather than secret values, full retrieval URLs, private endpoint details or unnecessary personal information. The working register starts empty; the example must not be passed off as your own evidence.\n\n### Closure note\n\n> Case [reference]: [owner] completed [source-system action] at [time]. Verification: [restricted evidence reference]. Handoff retirement: [status/reference]. Remaining limitations: [none identified within scope, or named gap]. Next action: [owner/date, only when needed].\n\n### Before marking closure verified\n\nConfirm that the issuing-system owner supplied evidence, that dependencies and continued access have their own disposition, and that the safe references explain the result without exposing the credential.\n\n> **An honest exception beats a false completion.** Name the missing check, assign an owner and due date, and keep the affected access visible.\n","/downloads/resources/contractor-access-closeout/v1.1/contractor-access-closeout-v1.1.pdf",89325,"/images/resources/contractor-access-closeout/v1/cover.png",[252],{"label":253,"path":254,"sha256":255,"format":256,"note":257},"Access close-out register (Excel)","/downloads/templates/contractor-access-closeout/v1.1/access-closeout-register.xlsx","97c12af6815f4b36","xlsx","An empty working register plus a separate fictional example. Keep it in restricted storage once populated.",[259,260],"R03","R12",[262,267],{"resource_code":259,"slug":263,"title":264,"summary":265,"topic":266},"credential-handoff-evidence-starter","Credential-Handoff Evidence Starter","Build a bounded evidence packet with a completed fictional example, interpretation guidance and an editable record.","Prepare evidence",{"resource_code":260,"slug":268,"title":269,"summary":270,"topic":271},"credential-exposure-response-card","Credential Exposure: First Actions","A two-page card: stop further copies, identify what the material grants, contain under the incident lead, keep only authorized evidence, retire delivery and verify.","Respond to exposure",1791050659797]