Skip to content

Managing Contractors

Give a contractor access to the devices they need for a fixed period, then remove that access when the work ends. You manage their account in Users, their device assignments in Devices, and their VPN approval in VPN > Team. You do not need to open the NetBird administration site.

Send contractors the Contractor Getting Started guide when you invite them.

Users page with the Contractor support panel enabled Users page with the Contractor support panel enabled

Start in Users. Contractor support appears above the user list.

Users page with the Contractor support panel enabled Users page with the Contractor support panel enabled

Contractors use expiring accounts and must complete two-factor authentication. Their ARROW Console shows only their assigned devices. Connections to those devices provide administrative access, so assign only the devices needed for their work.

Open Users and check the Contractor support panel. Enabled means contractor support and its VPN restrictions are ready. Open Review settings for assignment details or to request support if it is not enabled yet.

Contractor support review listing demo device assignment counts Contractor support review listing demo device assignment counts

Review settings shows VPN readiness and devices that still need assignments.

Contractor support review listing demo device assignment counts Contractor support review listing demo device assignment counts
  1. Review each device and the people who still need it.
  2. Add those people under Devices > device Actions > Edit Request Details > Assigned Consultants.
  3. Check Users > Contractor support > Review settings for devices with no assigned users or VPN settings that need attention.
  4. If support is not enabled, acknowledge the assignment requirement and select Request contractor support. Wait for the review to finish before inviting contractors.

If the panel says VPN review needed, use Request VPN access review. A request records the review; it does not immediately change your VPN policies.

  1. Open Users and select Add User.
  2. Choose Contractor under User Role.
  3. Enter their First Name, Last Name, and Email Address.
  4. Set Access duration (days) and select Invite contractor.
Add New User dialog with Contractor selected and an access duration Add New User dialog with Contractor selected and an access duration

Choose Contractor under User Role, then set the access duration before sending the invitation.

Add New User dialog with Contractor selected and an access duration Add New User dialog with Contractor selected and an access duration
FieldWhat it does
First Name and Last NameIdentify the contractor in your organization.
Email AddressReceives the invitation and identifies their sign-in account.
Access duration (days)Sets account expiry between 1 and 365 days from the invitation.

You do not choose a staff role for a contractor. Their access comes from their contractor account and device assignments.

The contractor opens the invitation, selects Set up your account, and follows the account setup email. They then sign in to ARROW and complete two-factor authentication. You do not need their password or authenticator code.

Contractor invitation email with Accept your invitation and separate invitation and access expiry dates

The contractor receives an invitation with the organization and access expiry. Example from the BeeWare demonstration.

Contractor invitation email with Accept your invitation and separate invitation and access expiry dates

The invitation has its own expiry, separate from the account’s access expiry. Account time starts when you invite them, so delaying setup reduces the time left. If an invitation is missing or no longer valid, check the email address and contact support for a replacement. Do not deactivate an account just to resend an email.

  1. Open Devices and find the device.
  2. Open its Actions menu and choose Edit Request Details.
  3. In Edit Device Request Details, find Assigned Consultants.
  4. Search by name or email, then turn on the contractor’s toggle. Leave existing users who must keep access turned on.
  5. Select Save Changes.
Edit Device Request Details dialog with Assigned Consultants and Save Changes Edit Device Request Details dialog with Assigned Consultants and Save Changes

Search by name or email, turn assignments on or off, and save.

Edit Device Request Details dialog with Assigned Consultants and Save Changes Edit Device Request Details dialog with Assigned Consultants and Save Changes

Repeat for each device they need. The assignment list includes staff as well as contractors, each listed by name and email, and the count under the search box tells you how many people are assigned. Nothing changes until you save. Removing someone from one device does not deactivate their account or remove their other assignments.

Changing assignments requires organization or device management permission. If the Assigned Consultants list says it cannot load names and emails, check your permissions with an organization administrator.

Ask the contractor to refresh Devices after you save. A contractor with no eligible assigned devices can sign in but has nothing to connect to.

Account setup, device assignment, and VPN approval are separate steps. An active ARROW account does not prove that the person’s VPN account has been approved or that their workstation is connected.

When your VPN requires approval, ARROW notifies administrators that a VPN user needs approval. Open the notification or go directly to VPN > Team. The contractor also sees a message on Devices while approval is pending.

  1. Ask the contractor to sign in to your organization’s NetBird VPN with the same identity they use for ARROW.
  2. Open VPN > Team and select Refresh.
  3. Find the correct person by name and email. Use the approval status filter when needed.
  4. Select Approve access on their row. The row menu also offers Approve VPN access where available.
  5. Check the resulting status, then ask the contractor to refresh ARROW and reconnect their VPN client if needed.
ARROW VPN Team with one user needing approval, Needs NetBird approval status, and Approve access

A pending VPN user appears with an approval notice and an Approve access button in ARROW. This is the BeeWare demonstration account.

ARROW VPN Team with one user needing approval, Needs NetBird approval status, and Approve access

If the contractor reports user pending approval cannot add peers in the NetBird client, complete this approval and have them retry sign-in.

Approval stays inside ARROW. Contractors need the NetBird client on their workstation, but neither they nor your organization administrator need to use the NetBird administration site for this approval.

StatusWhat to do
Needs NetBird approvalVerify the person, then approve their VPN access.
Approval status unavailableRefresh and review the account. Do not assume access has been approved.
VPN blockedReview why access was blocked before restoring it.
Invitation pendingAsk the person to finish their VPN invitation or sign-in.
VPN account readyAccount approval is ready. Still check the workstation connection and device assignment.

Approval does not grant access to unassigned devices. If the VPN section or approval control is missing, ask an organization administrator with VPN management permission to perform the review.

The Access expires column in Users shows the contractor’s expiry date and time. Their Actions menu contains the access controls.

Contractor Actions menu containing Extend access and Deactivate access Contractor Actions menu containing Extend access and Deactivate access

Open the three-dot Actions menu on the contractor's row to manage access.

Contractor Actions menu containing Extend access and Deactivate access Contractor Actions menu containing Extend access and Deactivate access
  1. Open the contractor’s Actions menu and select Extend access.
  2. Set Access duration (days from today).
  3. Check New expiry and select Extend access to save.
Extend access dialog with duration in days from today and a new expiry preview Extend access dialog with duration in days from today and a new expiry preview

Check the proposed new expiry before saving.

Extend access dialog with duration in days from today and a new expiry preview Extend access dialog with duration in days from today and a new expiry preview

The number is measured from today, not added to the old expiry. For example, if ten days remain and you choose 30, the new expiry is 30 days from today. ARROW prevents an extension from ending before the current expiry. The limit is 365 days from today.

Extending an active account keeps its existing device assignments. It does not approve a pending VPN account.

Deactivate access without deleting the account

Section titled “Deactivate access without deleting the account”

Use this when work stops early or someone must lose access now.

  1. In Users, open the contractor’s Actions menu.
  2. Select Deactivate access.
  3. Check the email in the confirmation dialog and select Deactivate access again.
Deactivate access confirmation dialog with Cancel and Deactivate access buttons Deactivate access confirmation dialog with Cancel and Deactivate access buttons

Confirm deactivation only when access should end.

Deactivate access confirmation dialog with Cancel and Deactivate access buttons Deactivate access confirmation dialog with Cancel and Deactivate access buttons

ARROW disables portal access and removes VPN access while keeping the account and its device assignments for later. If ARROW reports that VPN or identity cleanup is still pending, it retries automatically; do not treat that message as confirmation that every external connection has already ended.

Use Deactivate access for a reversible suspension. Accounts are never deleted from Users: the Deactivate item at the bottom of the menu is for staff accounts and ARROW refuses it for a contractor, and changing a role is not a substitute for deactivating contractor access.

  1. Open the contractor’s Actions menu in Users.
  2. Select Reactivate access.
  3. Choose Access duration (days from today) and check New expiry.
  4. Select Reactivate access to save.
  5. Ask the contractor to sign in again and verify two-factor authentication. If their original setup was never completed, have them use the new invitation email.

The same account and assignments are retained. Review those assignments before restoring access, especially if the work has changed. Check VPN > Team again if the contractor reports that VPN approval is needed.

ProblemCheck
Contractor is missing from Add UserCheck Contractor support in Users and your user-management permissions.
Contractor sees no devicesCheck the device’s Assigned Consultants, the account’s status and expiry, and whether the device is still active.
Assigned Consultants will not load or saveChanging assignments requires organization or device management permission. Ask an organization administrator who has it to make the change.
Contractor sees a VPN approval messageReview VPN > Team in ARROW and approve the correct person.
Approval notification is missingCheck VPN > Team directly and select Refresh. Check your notification preferences and management permissions.
Account is active but connections failVerify VPN approval, a connected NetBird workstation client, device assignment, and device availability.
Access has expiredUse Reactivate access with a new duration. The contractor cannot extend their own account.
New expiry cannot be savedChoose a whole number from 1 to 365 that ends after the existing expiry.
An access change reports pending cleanupKeep the account deactivated while ARROW retries. Contact support if it remains pending.

For workstation setup and connection checks, see VPN Management & Access and VPN Connectivity Troubleshooting.