Guide · 6-minute read
Let contractors track work without exposing what you bill.
A contractor needs enough context to deliver and record time, not automatic access to client rates, invoice totals, profitability, or every project in the workspace. The right permission model makes that boundary structural rather than a training request.
Last updated August 18, 2026
Start with project scope, then add task scope
Enroll the contractor only in projects they are expected to see. Within those projects, assign the relevant tasks and let the person update delivery fields, comment, attach work, and track their own time. A global workspace role without a project boundary creates unnecessary exposure and a harder offboarding job.
Assignment and project membership should agree. If assigning a task adds the contractor to its project, make that behavior visible to the manager. When work moves to another project, revalidate access instead of carrying an invisible permission across client boundaries.
Hide money at the server boundary
Removing invoice navigation is not enough. Rates, amounts, profitability, client billing fields, invoice routes, exports, reports, notifications, search results, and API responses all need the same role rule. Otherwise a hidden column can reappear through a download, alert, or direct URL.
Contractors can still see hours, estimates, dates, task content, and their own delivery history. That is useful operational context. Financial privacy should remove money-bearing data without making the work itself impossible to understand.
Offboard without erasing the record
Remove the contractor’s workspace access when the engagement ends. Their historical time, task comments, attachments, and audit events should remain attached to the project because those records explain completed work and may support an invoice. Access removal is not historical deletion.
Review running timers, open assignments, pending mentions, and unbilled time before removal. Rotate any separate credentials shared outside the product. If the person needs financial or client administration responsibility, grant a documented manage-tier role deliberately rather than carving one-off exceptions into the contractor role.
How Hoursmith does it
How Hoursmith implements money-blind membership
Members see projects they are enrolled in, can work on assigned tasks, and track their own time. Money-bearing fields and routes are stripped server-side: no rates, amounts, invoices, profitability, client billing records, or revenue/uninvoiced report tabs.
Owners and Admins retain financial and team visibility. Task assignment supports multiple assignees, and project-scoped choices prevent a collaborator from being selected into work they cannot access. The role and task tools are available on every recurring plan within its member cap.