## TL;DR
Contractor AWS access through IAM Identity Center means short-lived assignments: a scoped permission set, assignment to specific accounts, and an end date. Never hand contractors long-lived IAM user credentials.

## The query
```text
aws iam identity center access for contractors: helpdesk guide
```

## Use this when
- contractor needs AWS console or CLI access
- auditing contractor access to AWS
- ending a contractor engagement

## Not for
- creating long-lived IAM users for contractors
- full-time employee AWS access design
- root account handling

## Steps
1. Define a permission set scoped to what the contractor actually needs. Expected output: least-privilege permission set
2. Assign the contractor's Identity Center user to the specific AWS accounts. Expected output: account assignments in place
3. Set a session duration and calendar reminder for the engagement end date. Expected output: time-bounded access
4. Show the contractor how to sign in through the Identity Center portal. Expected output: contractor can access
5. Review assignments monthly during the engagement. Expected output: no scope creep
6. Remove the assignments on the end date and confirm. Expected output: access fully revoked

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_LGzh4jUgPjKYxjGQvjp7zg
