Contractor access
Give a contractor a workstation, not a path into your corporate network.
Spin up an isolated workstation, send the URL, delete it when the engagement ends. Per-tenant network, source-stays-in-the-cloud streaming, every action audited. No corporate VPN credential to revoke, no laptop to ship, no MDM-on-personal-device negotiation.
The pain
- Shipping a corporate laptop to a contractor in a different country, then chasing it down at the end of the engagement.
- VPN credentials that need provisioning, monitoring, and revoking — but the contractor still has the saved profile, and the credentials still work for three weeks after termination because nobody got around to it.
- The source code, design files, and customer data sitting on a personal laptop you don't own, can't audit, and can't wipe.
- Onboarding friction so high that contractors are paid for the first week of setup before any work happens.
With Canvex
- Create an isolated workstation, send the contractor the connect URL. No client to install, no VPN to configure — just a browser tab.
- Per-tenant private network: the contractor's workstation can talk to the resources you mount on its network, nothing else. Add an internal staging server, drop it on the same network, contractor can hit it.
- Source, files, and data live on the cloud workstation. The contractor's local machine renders pixels. Watermarking + session recording on the regulated tier for sensitive work.
- End the engagement: delete the workstation. The corporate network never had a path to it, the contractor never had source on their machine, the cleanup is a button click.
Recommended config
Most contractor workstations
For a contractor doing application work or document review, Standard tier (3–4 vCPU, 5–8 GB RAM) is the right pick. Bump to Performance for build workloads or design tools. GPU only if the engagement involves CAD, 3D, or ML.
Pair with the Business or Enterprise platform tier for shadow-on-consent (look over the contractor's shoulder during onboarding) and the audit log surface (see every workstation action, every connection, every download).
What's working for you under the hood
Per-tenant network isolation
Each org gets its own isolated private network. Contractor workstations talk to what you grant them, nothing else.
Source stays in the cloud
The contractor's local machine renders a stream. No code, design files, or data ever lands on a device you don't own.
Burn-on-end
Engagement ends; you delete the workstation. Cleanup is a button click; there's no laptop to recover or VPN credential to revoke.
Session shadowingBusiness+
Org admin can join a contractor's live session view-only or view+control, after the contractor clicks Allow. Every join is logged.
Connection schedulesBusiness+
Restrict contractor access to business hours, or to specific calendar windows. After-hours connections drop at the firewall.
Audit log + session recordingEnterprise
Full audit trail of every action. Session recording on the Enterprise tier for evidence-grade review.
The traditional answer — VPN credential + corporate laptop — optimizes for the contractor's convenience and the security team's pain. Cloud desktops invert that: the contractor opens a tab, the security team gets isolation by default, and the cleanup at engagement end is a delete button instead of a three-week ticket queue.
Your first desktop, in five minutes.
3-day free trial. Cancel anytime before it ends.