Revoke access when work ends
Projects finish and contractors rotate. Bstrapr makes offboarding an access decision rather than an infrastructure rebuild.
The recommended offboarding flow
- Identify the collaborator and the Sites they could reach
- Remove the individual Site assignment or revoke the relevant group grant
- If needed, remove the collaborator from the provider group
- Confirm the access overview no longer shows the intended Site access
- Review access activity history for the engagement
What revocation changes
Revocation ends Bstrapr-mediated access for the collaborator or grant. The underlying Site stays connected and remains under your ownership. You do not need to move workloads, delete a server, or rebuild the environment just because an engagement ended.
Group membership and access
Removing a specialist from one provider group affects access derived only from that group. Membership in other groups and direct individual assignments are not changed. Disabling the specialist is a broader organization-level offboarding action.
A precise record
Access activity history helps you see who was granted access, which Sites they could reach, and when access changed. It is intended for operational accountability and should not be confused with a formal immutable compliance evidence system.
This public guide explains the workflow. Environment-specific setup commands, connection details, and administrative controls are available inside the authenticated dashboard.