Split-screen: what the admin does (left), what the contractor sees (right). Total time, click to access: under 60 seconds.
The point: Onboarding a contractor on a traditional VPN means creating an AD account, shipping a laptop, installing a VPN client, configuring policies, and giving them a phone number to call when it breaks. This is the Cloudflare version — 60 seconds, no laptop, no account in your AD, scoped to specific apps, and auto-revoke when the project ends.
Speed
Elapsed: 0s
Admin
Cloudflare Zero Trust Dashboard
Step 1 — Open dashboard
Access Controls → Applications
Open the existing "Finance Portal" application. Add a new contractor email.
Add contractor
Q4 audit contractorsEmployeesExecutives
2026-12-31 (90 days from today)
Send the invite
Send invite to contractor
Contractor gets an email with a magic link. No agent install. No account in your AD. When 2026-12-31 hits, access auto-revokes.
Confirmation
✓ Invite sent. Contractor has access to Finance Portal only. Will auto-revoke on 2026-12-31. Audit log entry created.
Hi Mayah, you've been invited to access Acme's Finance Portal for the Q4 audit. Click below to verify your email and continue.
Access Finance Portal →
🔢 Verify with email OTP
Enter the 6-digit code
Sent to mayah.davis@independent-auditor.com
✅ App loads
Acme Financial Portal
Q4 Audit View — Limited Access
📊 Q4 financial statements (read-only)
📁 Approved audit documents (12 files)
📈 Variance reports — Q3 vs Q4
✓ Verified via Cloudflare Zero Trust
Access expires in 90 days. No employee account. No VPN client. No laptop shipped.
⏱ End-to-end timeline
Step 1
Open app
Step 2
Add email + group
Step 3
Send invite
Step 4
Contractor clicks
Step 5
App loads
What just happened: The admin added a contractor email, assigned a group, set an expiration date, and clicked Send. The contractor got an email, clicked a magic link, verified with a 6-digit code, and landed in the app — scoped to just the Q4 audit data, nothing else. No AD account. No laptop. No agent. No phone call. When the audit ends, access auto-revokes — no manual cleanup, no forgotten accounts. Compare that to a traditional VPN onboarding cycle: days, sometimes weeks.