External access

Keep contractor access to protected systems under control

The maintenance access for the equipment manufacturer was set up two years ago. It still works today. That is precisely the problem.

August 20, 2026 · CentaurNexus · approx. 3 min read

Keep contractor access to protected systems under control
CentaurNexus: Keep contractor access to protected systems under control
In brief
External service providers need access to protected systems, often at short notice and for a clearly defined task. In practice these access rights outlive their occasion: they are set up, used, and never touched again. Vendor Orbit brings external partner and vendor access together in one place, while Vendor Session Access grants time-limited access with four-eyes approval. External access becomes what it should be: a procedure with a beginning and an end, rather than a permanent state.

Access that outlives its occasion

An external technician is to service a piece of equipment and needs access to an internal system. The access is set up, the maintenance goes ahead, everyone is satisfied. What happens afterwards is the actual point: usually nothing.

The access remains, because nobody has a reason to remove it and because removing it is work nobody gets credit for. Two years later there is a working access route for a task long completed, often for a person who no longer works for the provider.

This is not carelessness on the part of individual organisations but a structural property: granting access is a procedure with an occasion, revoking access is a task without a trigger.

The difference between trust and traceability

The question is rarely whether you trust the provider. In most cases you do, otherwise you would not have hired them. The question is whether it can be traced later who accessed what, when, and with whose approval.

That distinction matters because it takes the pressure off the conversation with the provider. It is not about distrust but about an order both sides benefit from: the provider, too, wants to be able to show that their technician touched only what they were engaged for.

What Vendor Orbit brings together

Vendor Orbit is a central control centre for external partner and vendor access via ZPA. Instead of a collection of individually granted permissions that has grown over years, you see in one place which external access exists and to whom it belongs.

The benefit lies less in any single access right than in the overview. Only when all external access appears side by side does it become apparent which of it nobody needs any more.

Time-limited instead of permanent

Vendor Session Access grants time-limited ZPA access for external technicians, tied to a four-eyes approval. The access ends by itself, instead of waiting for someone to remember it.

That inverts the default. Until now, access is permanent until someone removes it. Afterwards it is limited until someone extends it. The difference sounds small, but it determines what a set of access rights looks like after two years.

The four-eyes approval adds a second property: access does not arise from a single decision but from a confirmed one. For privileged sessions there is a dedicated approval flow with automatic expiry.

What NIS2 and DORA make of it

Both regulations ask about control over access along the supply chain. Not whether external access exists, but whether it is granted in an orderly way, time-limited and traceable.

A set of access rights consisting of individually grown permanent permissions is hard to explain in an audit conversation. A set of time-limited, approved and documented sessions largely explains itself.

The uncomfortable question
How many external access rights in your environment have lasted longer than the engagement that created them? Usually nobody knows, and that is precisely the finding.

Frequently asked questions

What is Vendor Orbit?

A central control centre for external partner and vendor access via ZPA. It brings together which external access exists and who it is assigned to.

How does time-limited access work?

Vendor Session Access grants time-limited ZPA access for external technicians, combined with a four-eyes approval. The access expires automatically instead of lasting until manual revocation.

What does four-eyes approval mean here?

Access does not arise from a single decision but must be confirmed by a second person. For privileged sessions there is a dedicated approval flow.

Why is old contractor access a risk?

Because it outlives the occasion it was created for. It often exists for completed tasks, or for people who no longer work for the provider.

What do NIS2 and DORA require here?

Both ask about control over access along the supply chain: whether external access is granted in an orderly way, time-limited and traceable. The existence of external access is not the problem; its lack of clarity is.

Sources

    See the workflow in context

    Pick the matching role in the demo launcher. The demo uses prepared sample data.

    Open demo launcher