A freelancer finished a project three months ago. Do they still have access?
Probably yes, unless someone removed it. Access does not expire when a project ends. Three months on, a freelancer may still hold a user role, a partner link or a shared password on client platforms. Audit each platform's user and partner lists, remove anyone not on active work, and rotate any shared credential they could see.
Does a freelancer keep access after the project ends?
Nothing in a client platform expires when a project ends. A freelancer who was added as a user, a partner or a collaborator keeps that role until a person with admin rights removes it, and the freelancer has no reason to mention it. For a marketing agency, the gap is easy to create: access is granted on day one under deadline pressure, and the end of a project rarely has an owner. Three months later the invoice is paid, the folder is archived, and the freelancer can still open the client's ad account, analytics property or website login.
The wider breach data shows why the gap matters. Verizon's 2026 Data Breach Investigations Report found third parties involved in 48% of breaches, up from 30% in the previous edition (via Help Net Security, 25 May 2026). A former freelancer is a third party in exactly that sense. Whether a specific ex-freelancer is a risk depends on their devices and habits, which an agency cannot see, so the safe assumption is not that they are dangerous but that their access should not outlive their work.
Where does a former freelancer's access actually live?
A freelancer's access is rarely a single account. It is a set of small permissions spread across tools that each have their own user list, and nobody keeps a combined view. Before removing anything, an agency needs to know where to look. These are the places that most often outlast a project:
- Client ad platforms. A user role or partner link on a Meta business portfolio, or a user on a Google Ads account.
- Client websites and hosting. A CMS login, a hosting control panel user or an FTP account created for a launch.
- Analytics and tag tools. Google Analytics, a tag manager container or a search console property.
- Your own tools. A seat in the project board, a shared drive folder, the team chat or a password manager vault.
- Shared credentials. Any password the freelancer could view, whether it lives in a vault, a document or an old message thread.
How do you check what a freelancer can still reach?
The check takes one pass through each client platform's list of who has access, done by someone with admin rights. Google Ads documents the steps: in the account's Admin menu, open Access and security, find the user, and select Remove access in the Actions column. Manager accounts have their own list. Under Access and security, the Managers sub-page shows every manager account linked to the client, and Remove access there ends that link (Google Ads Help, consulted 29 September 2026). A freelancer who was added as a user and a freelancer whose own manager account was linked appear in different places, so both lists need checking.
Meta separates the same two ideas. Its Business Help Center has a dedicated page titled "Remove partners from your business portfolio", distinct from removing individual people, so an agency that removes a freelancer as a person can still leave their company linked as a partner (Meta Business Help Center, page title consulted 29 September 2026; partner access described in the page consulted 24 September 2026). Check both lists on every client portfolio the freelancer touched, and write down what you removed and the date.
What should an agency do on a freelancer's last day?
The control that fits offboarding is a same-day removal routine. NIST SP 800-53 Revision 5, control PS-4 on personnel termination, requires an organization to disable system access within a time period it defines itself, to revoke the person's authenticators and credentials, and to keep the ability to reach information and systems the person managed (NIST, consulted 29 September 2026). The standard is written for federal systems, but the three ideas translate directly to an agency: set your own deadline, take away the credentials, and make sure the client's assets are still reachable by your team afterwards.
A workable version for a small agency is a short list that one named person runs on the last day of the engagement:
- Remove platform access. Take the freelancer off each client platform's user list and partner list.
- End access to your own tools. Remove the seat in the project board, chat, shared drive and password manager.
- Change what they could see. Rotate any shared credential that was visible to them.
- Confirm the client can still get in. Check that the client, or your team, holds admin rights on every asset.
- Record it. Log the date, the person who did it and the platforms covered.
Do you need to change passwords if there is no sign of a problem?
Rotate any shared password the freelancer could view, even with no sign of misuse. A departure is not evidence of compromise, and this step does not accuse anyone. The reasoning is practical: anyone who can read a password can also have copied it, and an agency has no way to know whether that happened. Changing the credential is the only action that closes the question for good. Mimecast counted 6.4 million detections of Meta Business Manager and Google Ads account theft in four years, and reported that aged accounts with spend history resell at two to four times the price of new ones (via Help Net Security, 29 July 2026). The client accounts an agency holds are the valuable kind, which is one more reason to leave no old credential in circulation.
Rotation is far cheaper when the agency already uses delegated access, since a partner link or manager link ends without any password change. That is the argument for holding fewer client logins in the first place, which the earlier guide on agency password storage covers in more detail. Wherever a platform lets the client grant your agency a role, prefer that over a shared login, because removing the role later is a single action on one list rather than a password change that has to reach every teammate.
How do you stop this happening again?
The lasting fix is to decide the end date when access is granted, not when the project finishes. When an agency adds a freelancer to a client platform, it can write the expected end date next to the entry in a one-page inventory: client, platform, person, role, date granted, date to review. A monthly look at that page, by the same person who runs the offboarding list, catches the freelancer whose project was extended, cancelled or forgotten. A page in the agency's project tool is enough, as long as one person owns it.
Freelancer agreements are the other half of the routine. A clause that states access ends on the last day of work, that the freelancer must not keep copies of client credentials, and that the agency may remove access at any time gives the offboarding list a written basis. Have a lawyer review the wording for your jurisdiction, since a security team cannot supply legal drafting. The routine still works without the clause, but the clause makes the conversation easier when a project ends badly.
Want to know where your own environment stands? The first step is a free, read-only security assessment.
Get a free security assessment