Skip to content

Contractor Getting Started

Your organization invites you to ARROW for a fixed period and assigns the devices you need. You finish your own account setup, protect your sign-in with two-factor authentication, and connect your workstation to the organization’s VPN.

Have your invitation email, an authenticator app, and your organization’s VPN connection details ready. Your organization administrator manages your assignments, VPN approval, and access expiry.

  1. Open the ARROW contractor invitation email and select Accept your invitation.
  2. Check Organization, Invited email, Invitation expires, and Account access until.
  3. Select Set up your account.
  4. When ARROW shows Check your email, open the new setup email and follow the instructions to finish your account setup.
  5. Return to ARROW and select Continue to ARROW sign in.
Contractor Invitation page with organization, invited email, two expiry dates, and Set up your account

Check your organization and email before starting. The dates shown are from the BeeWare demonstration account.

Contractor Invitation page with organization, invited email, two expiry dates, and Set up your account

Your invitation expiry is the deadline for using that link. Account access until is the separate deadline for your access to ARROW. Completing setup does not restart the access period.

Check your email page with Continue to ARROW sign in

Finish the setup email first, then return here to sign in.

Check your email page with Continue to ARROW sign in

The setup email may use the wording Reset ARROW Password. Use the setup email you just requested to choose your password. If sign-in asks for E-Mail Verification, enter the code from the verification email and select Next. Use Resend Code if needed. After successful verification, select Next to continue.

E-Mail Verification screen with an empty Code field and Resend Code button

Email verification confirms your address. It is separate from authenticator setup.

E-Mail Verification screen with an empty Code field and Resend Code button

If the page says This link is no longer valid, ask your organization administrator for help with a new invitation. Do not forward your invitation or account setup link to anyone else.

Sign in using the identity from your invitation. ARROW requires two-factor authentication before you can use the contractor console.

You may go straight from email verification to 2-Factor Verification. Open your authenticator app, add an account by scanning the QR code shown on your own screen, and enter the current code. Select Next. When 2-factor Verified appears, select Next again to continue to ARROW.

2-factor Verified confirmation with a Next button

Enrollment is complete when this confirmation appears. Select Next to continue.

2-factor Verified confirmation with a Next button

If you reach ARROW’s MFA setup page instead:

  1. Select Continue to sign in and set up MFA.
  2. Follow the identity provider’s instructions to enroll your authenticator app and verify a code.
  3. Return to ARROW. If the setup page remains open, select I’ve finished setup - check again.

If you use Open Zitadel account settings instead, look under Multifactor Authentication and add an Authenticator app (OTP). An empty list means you have not enrolled one yet. If no option to add one appears after reloading, contact your organization administrator.

Keep your password, authenticator codes, and recovery information private. Your administrator can manage your access without asking for them.

You need the NetBird client to reach assigned devices over the private network. Signing in to the ARROW website does not connect your workstation to the VPN.

  1. Follow Setting Up the NetBird Client to install the client.
  2. Ask your organization administrator for the correct management URL and configure the client for that organization.
  3. Connect and sign in using the same identity as your ARROW account.
  4. If approval is required, ask your administrator to approve you in ARROW > VPN > Team.
  5. After approval, reconnect the VPN client if needed and refresh Devices in ARROW.

Use the workstation sign-in flow. Do not use a device setup key for your workstation.

ARROW shows a message above your devices if your VPN access is awaiting approval, blocked, still being enrolled, or cannot be verified. Your administrator handles approval in ARROW; you do not need access to the NetBird administration site.

If the NetBird client says Login Failed with user pending approval cannot add peers, your VPN account needs administrator approval. Ask your administrator to open ARROW > VPN > Team, approve your access, and then retry the client sign-in.

NetBird client login error stating user pending approval cannot add peers

This message requires VPN approval in ARROW before you can connect.

NetBird client login error stating user pending approval cannot add peers

After account setup and MFA, ARROW opens Devices. You use the same device console as the rest of your organization, with the controls that apply to your account.

  • Switch between the grid and list views to browse your devices.
  • Use search and filters to find the device you need.
  • Select Show Details to inspect the device, including its location and available network, software, and status information.
  • Check the access expiry notice above the device list.

Your console contains Devices and Account Settings, with a link to documentation. Organization-wide user administration, billing, requests, and VPN administration are managed by your organization administrator.

Contractor Devices console showing access expiry, VPN enrollment guidance, and no assigned devices

Before assignments, Devices can be empty. The notice above the list shows your access expiry and VPN guidance.

Contractor Devices console showing access expiry, VPN enrollment guidance, and no assigned devices

If a device is missing, ask your administrator to check its assignment. A VPN connection alone does not make unassigned devices appear.

Keep the NetBird client connected, then use the device’s connection control in ARROW. Physical devices open ARROW Manager; virtual appliances open ARROW Control.

Connections provide administrative access to the assigned device. Follow your organization’s instructions for the work you perform there.

If ARROW refuses the connection, check the message before retrying. VPN approval, current account access, a current assignment, and a compatible available device are all required. Do not try to work around a denied connection with a shared administrator login. Ask your organization administrator to check the device and your access.

For the tools available after connecting, see ARROW Manager and ARROW Control.

Use Account Settings for your own profile and account security. Sign out when you finish, especially on a shared workstation.

You cannot change your account’s expiry or reactivate it yourself. Contact your organization administrator before the expiry date if you need more time. They can extend access from your row’s Actions menu in Users.

If access expires or is deactivated, ask the administrator to reactivate the account if the work should continue. You can use the same account after reactivation, but you must sign in again and verify two-factor authentication. Your administrator may also need to review VPN approval.

What you seeWhat to do
No invitation emailCheck spam and confirm your email address with the administrator.
This link is no longer validAsk your administrator for a replacement invitation.
MFA setup keeps appearingFinish authenticator enrollment, return to ARROW, and select I’ve finished setup - check again.
No assigned devicesAsk the administrator to assign you under the device’s Assigned Consultants list.
NetBird says user pending approval cannot add peersAsk the administrator to approve you in ARROW > VPN > Team, then retry VPN sign-in.
VPN access is awaiting approvalAsk the administrator to approve you in ARROW > VPN > Team, then refresh.
VPN access is blockedAsk the administrator to review the block.
VPN status cannot be verifiedRefresh and ask the administrator to check VPN > Team.
Your administrator must enable VPN restrictionsYour organization must finish its VPN access review before connections are available.
Device is listed but will not openCheck that your workstation VPN is connected and the device is available. Give your administrator the error message.
Location or another detail is blankThe device may not have that information recorded. Ask your administrator to check the device record.
Access has expiredAsk your administrator to reactivate your account with a new expiry.

Your administrator’s instructions are in Managing Contractors.