---
id: KB-CL-008
url: https://app.codecontract.io/help/collaboration/working-with-a-consultant-or-external-specialist
idioma: en
categoria: colaboracion
subcategoria: externos
audiencia: usuario
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-CL-001, KB-ET-008]
citadoPor: [KB-CL-009, KB-LE-011, KB-CS-035, KB-CL-018]
---

# Working with a consultant or external specialist

_Someone external working inside: what to give them and what to recover at the end._

**Responde a:** give a consultancy access · working with an external specialist · consultant preparing our certification · temporary access for an external collaborator

A consultant preparing your certification, a specialist building a process, an engineering firm running a project: outsiders who for months work as if they were inside. It is the relationship that closes worst and leaves the most accesses open.

## What they genuinely need

| They need | They do not need |
| --- | --- |
| To see and create in the area they work on | To see the rest of the organisation |
| To talk to your third parties if the engagement includes it | To be an administrator |
| To leave the work done and documented | To keep access after the engagement |

> [!IMPORTANT]
> Set an end date from day one, even if you do not know when it finishes. Dated access gets renewed if needed; undated access is still open three years later, and nobody misses it because that person was never part of the team.

## What to agree beforehand

1. **What they take at the end** — Normally nothing. What they build stays in your organisation, not theirs.
2. **What they may show third parties** — If they will speak to your suppliers on your behalf, say so expressly.
3. **What happens to what they learned** — A consultant works for more companies in your sector. That is normal and worth bearing in mind.

> [!WARNING]
> If the consultant will handle your clients' or your workers' documentation, that is no longer just an access: third-party data is involved. Review it with whoever handles data protection before granting it.

## At the end

**En corto**

- Close the access that day, not when they invoice the last hour.
- Check that what they built ends up with someone inside.
- And that this someone knows how it works, not merely that it exists.

> [!NOTE]
> The costliest failure in these relationships is not the access left open: it is that the process the consultant built is understood only by them, and six months later nobody knows how to change it.

**Can they work with our suppliers?**

If the engagement includes it and it is clear to everyone, yes.

**Do they see what other teams do?**

Only if you give it. Scope them to their area.

**Is what they did recorded?**

Yes, under their name, like anyone else.

## Ejemplos

**A consultancy builds the documentary system for a certification and finishes the engagement.**

- Their access is closed that day
- Someone inside walks through how it works with them

→ Six months later the team can change the process without re-engaging them.

**A consultancy comes in to set the system up and still has administrator access six months after finishing.**

- Grants the minimum access for their engagement
- Sets an expiry date when granting it
- Reviews at project close which accesses remain

→ The consultant works without friction and access closes itself when the work ends.

**The external technician builds everything on their personal account.**

- Uses a company service account

→ What was built outlives their departure.

**They leave and nobody knows how they configured the process.**

- Asks them to document the decisions before going

→ The team can touch it without fear.

**The consultant sees client files outside their scope.**

- Limits access to the project's files

→ They see theirs and nothing more.

**They are asked for something out of scope and do it unrecorded.**

- Records what was asked and what was delivered

→ The engagement is demonstrable.

**They return a year later and their access was still active.**

- Revokes access on closing

→ Access reflects who is collaborating today.

**Nobody knows what they did during the project.**

- Checks the log of their actions

→ The external party's work is auditable.
