Skip to content

Guide · 6-minute read

Let contractors track work without exposing what you bill.

A contractor needs enough context to deliver and record time, not automatic access to client rates, invoice totals, profitability, or every project in the workspace. The right permission model makes that boundary structural rather than a training request.

Last updated August 18, 2026

Start with project scope, then add task scope

Enroll the contractor only in projects they are expected to see. Within those projects, assign the relevant tasks and let the person update delivery fields, comment, attach work, and track their own time. A global workspace role without a project boundary creates unnecessary exposure and a harder offboarding job.

Assignment and project membership should agree. If assigning a task adds the contractor to its project, make that behavior visible to the manager. When work moves to another project, revalidate access instead of carrying an invisible permission across client boundaries.

Hide money at the server boundary

Removing invoice navigation is not enough. Rates, amounts, profitability, client billing fields, invoice routes, exports, reports, notifications, search results, and API responses all need the same role rule. Otherwise a hidden column can reappear through a download, alert, or direct URL.

Contractors can still see hours, estimates, dates, task content, and their own delivery history. That is useful operational context. Financial privacy should remove money-bearing data without making the work itself impossible to understand.

Offboard without erasing the record

Remove the contractor’s workspace access when the engagement ends. Their historical time, task comments, attachments, and audit events should remain attached to the project because those records explain completed work and may support an invoice. Access removal is not historical deletion.

Review running timers, open assignments, pending mentions, and unbilled time before removal. Rotate any separate credentials shared outside the product. If the person needs financial or client administration responsibility, grant a documented manage-tier role deliberately rather than carving one-off exceptions into the contractor role.

How Hoursmith does it

How Hoursmith implements money-blind membership

Members see projects they are enrolled in, can work on assigned tasks, and track their own time. Money-bearing fields and routes are stripped server-side: no rates, amounts, invoices, profitability, client billing records, or revenue/uninvoiced report tabs.

Owners and Admins retain financial and team visibility. Task assignment supports multiple assignees, and project-scoped choices prevent a collaborator from being selected into work they cannot access. The role and task tools are available on every recurring plan within its member cap.

Common questions

  • Can a Member see invoice totals through a direct URL?

    No. Invoice navigation is hidden and the server blocks invoice routes and amount-bearing data for the Member role; this is not a CSS-only restriction.

  • Does removing a contractor delete their time?

    No. Historical task and time records remain with the project. Removing membership ends future access without rewriting the delivery or billing history.

Related

Want this loop in your billing tool?

Hoursmith ships every pattern in this guide as a first-class feature. Free for solo freelancers; flat-fee for teams up to 25.

Free for solo freelancers · No credit card · Cancel any time