## TL;DR
Every contractor gets: a sponsored request with an end date, a contractor-type account with expiry, least-privilege access, a mid-engagement review for long contracts, and automatic revocation on the end date. The end date is the whole system; everything else is detail.

## The error
```text
(Lifecycle process; no error.)
```

## Steps
1. Request: sponsor submits the business need, scope, and end date. Expected: approved request with a date. No date, no account.
2. Provision: create the contractor account (contractor OU, account expiry = end date), grant only the requested access. Expected: time-boxed least-privilege account.
3. Communicate: tell the contractor what they can access, the rules (no data exfiltration, MFA required), and the end date. Expected: acknowledged.
4. Review: for engagements over 3 months, check at the midpoint whether access is still needed and still correct. Expected: reviewed. Scope creep is the norm; the review catches it.
5. Revoke: on the end date, disable the account automatically (expiry does this), remove access, collect equipment. Expected: clean exit. Verify with a spot check.

## When to use
- Every contractor engagement
- Vendor and temp access

## When not to use
- Employee onboarding
- One-day visitors (use guest access)

## Compatibility
- AD/Entra with account expiry; any ITSM for the workflow

## Variants
### Extension
Requires fresh sponsor approval and a new end date; never auto-extend.
### Conversion to employee
Provision a new employee account; do not convert the contractor account (history and expiry semantics differ).

## Why it happens
Contractors are temporary by definition but their access becomes permanent by default. The lifecycle makes "temporary" actually true.

## Edge cases
- Contractors with access to regulated data need the same background checks as employees in many regimes.
- Track contractor headcount; shadow contractors outside the process are the real risk.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_r-LiTQlFGYLS2GH-6mzW9g
