← All posts Agencies

Scoping a freelancer into one room, not your whole workspace

Adding a contractor to everything is the fast path and the one that creates the problem. How to set up a boundary that takes two minutes and survives the engagement.

MK Maya Kessler17 May 2026 · 10 min read

Why the fast path wins

A freelancer starts on Monday. Somebody adds them to the workspace on Monday morning, under time pressure, and the default invitation gives them everything. Nobody intended that; it was simply the option that took four seconds.

This is the same dynamic that produces over-permissioned staff accounts. Restricting access is possible in almost every tool and it is never the path of least resistance, so it only happens when someone has decided in advance that it will.

The fix is not discipline. It is deciding the scope before the person arrives, when there is no time pressure and the decision takes two minutes.

What they should and should not see

Work from the engagement rather than from the workspace structure.

They need: the room where their work is discussed, the people they will work with, and any context specific to the job. A developer changing your checkout needs the conversation about the checkout.

They do not need: conversations about other suppliers, anything about staff, customer complaints unrelated to their work, commercial discussion, and the general room where everything else happens.

The general room is the one people add contractors to without thinking, and it is usually the one containing the most incidental information about how your business runs.

Setting it up before they start

Four steps, and none take long if done in advance.

  1. Create the room for the engagement, not for the person. Rooms scoped to a piece of work have a natural end point; rooms scoped to a person accumulate.
  2. Decide the role that determines what they see. If your tool supports it, this should be a role rather than a set of individual invitations, because roles are reviewable and individual invitations are not.
  3. Put the people they need in the room, including whoever will answer their questions. A contractor with access and nobody to ask is blocked in a way that looks like slowness.
  4. Write the end date somewhere that is not somebody's memory. A calendar entry created the same day as the invitation.

The conversation that makes it easy

One sentence when the engagement starts removes any awkwardness: "We scope access per project as standard, so you will have the room for this piece of work and we will close it when we are done."

Almost every professional freelancer expects this and many prefer it. Working across several clients, they generally do not want access to things unrelated to their job, because it makes them a bigger target and a plausible suspect if something goes wrong elsewhere.

Said at the start it is procedure. Introduced halfway through it is a statement about them, which is why the timing does more work than the wording.

When they genuinely need more

Sometimes the scope was wrong and they need something outside it. That is fine and it is exactly how the arrangement should behave.

Grant it, note it, and treat the request as information: if you are granting exceptions weekly, the original scope was too narrow and you are spending more time on approvals than the boundary is saving. Widen it deliberately rather than continuing to approve one thing at a time.

What to avoid is the informal workaround, where somebody screenshots things from a room the freelancer cannot see. That defeats the boundary while keeping the overhead, and it puts the information somewhere with no access control at all.

A scope that needs an exception every week is not a security control. It is a queue.

Closing it out

The end of an engagement is a specific moment and it should have a specific action, because otherwise access simply persists.

Remove the room access, remove anything granted as an exception, and check the things that are not in your workspace at all: shared documents, third-party tool seats, anything set up on their email address. The full checklist is in offboarding contractors without leaving doors open.

If you might work with them again, remove access anyway and say you will reopen it. Reinstating takes a minute; a dormant credential is live risk for however long it sits there.

The version for a store with no roles

Not every tool supports scoped access, and if yours does not, the principle still applies with cruder mechanics.

Create a separate space for the engagement rather than adding the freelancer to your existing one. It is less elegant, it means some duplication, and it achieves the important part: the contractor sees the work and not everything else.

Keep a written note of what they were given, because without roles there is nothing to review later and reconstructing it from memory is where lingering access comes from.

What to do about the general room

Almost every workspace has one channel where everything happens, and it is the one people add contractors to without thinking. It is also the one containing the most incidental information about how the business runs: supplier frustrations, staffing changes, commercial decisions mentioned in passing.

None of it is confidential in a formal sense, which is exactly why nobody guards it. Collectively it is a detailed picture of your operation that a contractor on a two-week engagement has no reason to have.

The practical rule: contractors never go in the general room. If something there is relevant to their work, someone repeats it in the engagement room, which takes ten seconds and keeps the boundary intact.

This feels excessive until the first time a freelancer works for a competitor six months later, at which point it feels obvious.

Multiple freelancers, multiple engagements

The arrangement gets more valuable as you use more contractors, and slightly more work to maintain.

Keep one room per engagement rather than one per person, even where the same freelancer does several pieces of work. Each engagement has its own start, end and scope, and merging them means the boundary drifts: access granted for the first piece quietly persists through the third.

Where two contractors work on the same project, put them in the same room rather than running parallel conversations. The alternative is you acting as a relay between two people who should be talking to each other, which is slow and produces contradictory instructions.

Keep a simple list of open engagement rooms and review it quarterly. Rooms accumulate silently, and a list of six where you expected two is the finding.

The cost of getting it wrong

Worth stating plainly, because the effort only makes sense against a real risk.

The common outcome is not theft. It is a contractor who retains access for a year, whose account is one more way into your systems, and whose credentials you cannot audit because you never recorded what they had. If something goes wrong elsewhere, you cannot rule them out, which is unfair to them as well as unhelpful to you.

The less common but more expensive outcome is a contractor who moves to a competitor with a detailed picture of your operations, gathered incidentally from a room they were added to for convenience.

Doing it in two minutes

The whole argument reduces to a short sequence you can run before any contractor starts.

Create a room named for the engagement. Add the people they need to talk to. Give the contractor a role scoped to that room. Put the end date in a calendar. Send one sentence explaining that access is scoped per project as standard.

Five steps, two minutes, done before they arrive rather than under pressure on their first morning. That timing is the entire difference between a boundary that holds and a default invitation that quietly grants everything.

What this looks like a year later

The payoff is not visible during any single engagement, which is why the habit is hard to establish.

A year in, a store doing this can answer a question that most cannot: who has access to what, and why. Every contractor sits in a room named for a piece of work, with a date attached, and the ones that have ended are closed.

A store that did not do this has an accumulation of people in a general workspace, several of whom finished months ago, and no record of what any of them were given. Reconstructing it means going person by person through memory, which is why it never happens and the access simply persists.

The difference between the two is about two minutes per engagement, spent at the start rather than the end.

Common questions

How much access should a freelancer get?

The room where their work happens and the people they need, and nothing else. Start from the engagement rather than from your existing structure, and grant exceptions individually if needed.

Is it rude to restrict a contractor's access?

No, and most professionals prefer it. Access to things unrelated to their job makes them a bigger target and a plausible suspect if something goes wrong elsewhere.

What if the scope turns out to be too narrow?

Grant the exception and note it. If exceptions are weekly, widen the scope deliberately rather than running an approval queue that costs more than the boundary saves.

Should the room be per person or per project?

Per project. Rooms scoped to work have a natural close-out point; rooms scoped to a person accumulate and never get reviewed.

What if our tool has no roles?

Create a separate space for the engagement rather than adding them to your main one. Less elegant, same outcome, and keep a written note of what was granted.

Keep reading

Giving clients visibility without giving them admin
Agencies

Giving clients visibility without giving them admin

Scoped channels beat weekly status calls. How agencies are running client comms without a Shopify staff seat.

5 June 2026·6 min read
Shopify app affiliate programs: a guide for agencies
Agencies

Shopify app affiliate programs: a guide for agencies

App affiliate programs are the most overlooked revenue line in an agency. How they work, what separates a good one from a bad one, and how to build referrals into delivery.

27 August 2026·11 min read
Shopify App Partner Program: how it works in 2026
Agencies

Shopify App Partner Program: how it works in 2026

What the Shopify Partner Program actually pays app developers, what changed with the revenue share, and the part that trips people up: app affiliate programs are something else entirely.

26 August 2026·12 min read

Run your store team in one room.

Free for teams up to five, and about two minutes to connect your store.