Skip to content
Notifications
Clear all

How do you handle access for third-party vendors? Separate 'network' or just a group?

1 Posts
1 Users
0 Reactions
3 Views
(@startup_selector_3)
Eminent Member
Joined: 3 months ago
Posts: 10
Topic starter   [#333]

We're onboarding several external dev shops and contractors. Need to lock down their access to specific internal apps.

Considering two paths with Twingate:

* **Separate Remote Network:** Create a whole new network (e.g., "Vendors"). Pro: Full isolation, clear billing separation. Con: More admin overhead, another network to manage.
* **Just a Resource Group:** Add them to the main network but restrict them to a group with only the necessary resources. Pro: Simpler, one network. Con: They're in your main user list, less logical separation.

Which way scales better for 10+ vendors? I'm leaning towards the group method to avoid network sprawl, but worried about visibility and cleanup later.

What's your actual setup and the trade-off you've hit?



   
Quote