Sharing passwords with freelancers without losing control
The freelancer access problem
Working with freelancers is a normal part of modern business. A copywriter needs access to your CMS. A developer needs database credentials. A social media manager needs the brand's account logins. In each case, you face a dilemma: you need to give access, but the freelancer is outside your organisation, outside your IT policies, and outside your control.
The default approach — emailing the password and hoping for the best — solves the immediate problem while creating a longer-term one. Once that email is sent, you have no idea where the credential ends up.
What you don't know can hurt you
When a freelancer has a password in their inbox, consider what that means in practice:
- Their device may not be managed or encrypted
- They may store passwords in a browser on a shared computer
- Their email account may have weaker security than yours
- They may share your credentials with a subcontractor without telling you
- When the engagement ends, they will almost certainly still have that email
None of this is necessarily malicious. It's just the reality of working with people who are not subject to your IT policies. The credential you sent in good faith has escaped your control.
Principles for freelancer access
Grant the minimum necessary access Before sharing credentials, ask whether the freelancer actually needs the master login or whether a limited account would suffice. Most platforms allow you to create user accounts with restricted permissions. A developer working on the frontend doesn't need database root credentials. A copywriter doesn't need admin access — editor access is enough.
Create temporary credentials where possible If the platform allows it, create a dedicated account for the freelancer rather than sharing your own login. This gives you visibility into what they're doing, lets you revoke access cleanly when the engagement ends, and avoids the problem of shared credentials entirely.
Use one-time links for any credential that must be shared When you do need to share a credential directly, use PassTransfer to send it as an encrypted one-time link. The freelancer receives the link, retrieves the password, and the link expires. Nothing sits in either inbox. You have a record of when the link was created; if the link was opened, you know the credential was retrieved.
Set an explicit end date for access At the start of the engagement, agree on when access will be revoked. Put it in the contract. When that date arrives, change the credentials regardless of whether you think the freelancer would misuse them. This is not about distrust — it's about maintaining hygiene.
Rotate after the engagement ends When the freelancer's work is complete, change every credential they had access to. This is non-negotiable. It's the equivalent of collecting a building access card at the end of a contract.
The conversation with freelancers
Many freelancers appreciate clear security practices — it signals that you're a professional client. Frame the one-time link approach as your standard procedure: "We use encrypted one-time links for all credential sharing. You'll receive a link that works once; after that it expires. Please let us know once you've retrieved it." Most freelancers will accept this without question.
Conclusion
Sharing credentials with freelancers doesn't have to mean losing control. With temporary accounts where possible, one-time links when direct sharing is necessary, and a clear rotation policy at the end of the engagement, you can work effectively with outside collaborators without leaving a trail of exposed credentials behind you.