THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.



In safety circles, we spend most of our energy controlling hazards. We spend far less talking about controlling access — specifically the contractors and subcontractors who don't work for us but whose hands keep our sites running. On any given day, a large share of the work happening on our property belongs to companies other than us, and much of it happens without an employee walking alongside the crew. Unescorted contractor access is, on its face, the kind of risk most safety leaders instinctively want to avoid. We've taken the opposite position: we'd rather engineer the trust than escort our way around the problem.
The reasoning is practical. Escorting every contractor is neither scalable nor honest. An escort glancing at his phone is not a control — he's a liability in a hi-vis vest. Real assurance doesn't come from a person standing nearby; it comes from knowing that everyone who badges through the gate has already been vetted, trained, and verified before they ever set foot on site. So we built our model around a single principle: nobody comes on site who isn't fully approved and trained to our safety and security rules. No exceptions, no "just this once."
That model works in layers, and the order matters.
Building Trusted Access
The first gate is at the company level. Before any contractor sets boot on our property, the company has to clear our screening process. We use a Contractor Screening Service Provider — a third-party qualification database — to evaluate every contractor and subcontractor against objective EHS criteria: a three-year recordable incident rate, a days-away rate at, an experience modification rate, no regulatory citations and no fatalities in the past three years, and documented EHS programs that meet our requirements. We understand that safety is not just a number but is instead the controls, the awareness, and the attitude to achieve the safest environment possible. The system assigns a flag: green means full approval, red means deficiencies that disqualify the company for the work it performs without further engagement for context. A firm that can't show the right insurance, a real safety process, and a legitimate scope of work simply doesn't make it into the system. This stage filters at the organizational level — it decides whether a company has earned, with proactive systems, the right to send anyone to the site at all.
“We'd Rather Engineer The Trust than Escort Our Way Around The Problem.”
The second gate is at the individual level. Approving the company is not a blanket pass for its people. Every worker expected to perform work here completes a Contractor Safety Certification program through an approved provider, plus a sitespecific orientation, before they're cleared. Their qualification status, their training completion, and their credentials all live in one screening system, tied together and auditable — impossible to fake by waving a paper certificate at the gate. When the system says a worker is cleared, that clearance reflects both a vetted employer and a trained individual.
Verification in Practice
Then comes the part that makes it real: the physical control. Our security team operates a dedicated gate used only by contract employees. It exists for exactly one purpose — to verify, at the moment of entry, that the person standing there has current, valid training and credentials before they're allowed through, with badge scan-in and sign-in logs reconciled against the qualification record. This is where the digital approval meets the steel. The company vetting and the individual training are the policy; the contractor gate is the enforcement. One without the other is theater.
The controls don't stop at the fence line. Crews build a pre-task plan for the job in front of them, our DASH behavioral observation process expects participation from every contractor, and we hold a roughly one-totwenty-five safety-contact-to-worker ratio on larger jobs. Field audits scale to risk: green-flagged contractors quarterly, yellow-flagged monthly, high-risk work like crane lifts every single day regardless of flag. Approval, in other words, isn't a finish line — it's a status we keep re-earning.
What I've come to appreciate is that this reframes access control as a system of preconditions rather than a moment of permission. Too many organizations treat the gate as the control and everything before it as paperwork. We treat the paperwork — the screening, the green flag, the training record, the badge — as the actual control, and the gate as the last verification that all of it is true. Identity here isn't just "who is this person." It's "is this person's employer approved, is this individual trained, and is that training current?" All three have to be true at once.
There's a lesson buried in here that extends well past our property line: the strongest controls make the unsafe path hard to do, not just discouraged. An untrained, unvetted contractor doesn't get a warning at our gate — they get turned around, because the system never cleared them in the first place. That's the kind of access control I trust. Not because we watch every move on site, but because we did the work up front to ensure that everyone on site had already earned the right to be there.