{
  "slug": "contractor-chain-identity",
  "title": "Four companies deep, someone has your production credentials",
  "summary": "You vetted the managed service provider. You cannot see the three organisations below it, and someone at the far end holds privileged access to your network.",
  "lede": "Every enterprise runs due diligence on the supplier it signs. Almost none can see the three organisations underneath it, and the human who actually holds privileged access sits at the bottom of that stack. This is a walk through why the contractor chain exists, why assurance degrades at every link in it, why privileged access management does not close the gap, and what an identity that travels with the person rather than with the employer would change.",
  "date": "2026-10-01",
  "reading_time": "15 min read",
  "category": "Workforce",
  "tags": ["third party access", "managed service provider", "privileged access", "subcontractor risk", "DORA", "vendor risk", "contractor identity"],
  "image": "https://cdn.twc.sh/images/igcache/Contractor%20Chain%20Identity/1200_630/blog.jpg",
  "url": "/blog/contractor-chain-identity.html",
  "wordcount": 3873,
  "related": ["shared-account-attribution", "delegation-chain-depth", "offboarding-orphaned-authority"],
  "schema": "Article"
}
