Give specialist suppliers the access they need, with clear ownership
Renewable energy operators rely on maintenance contractors, application vendors, equipment specialists and project partners. Stratiis helps coordinate approved business IT access, devices and support routes so each supplier can complete agreed work without creating an open-ended route into asset information or systems.
What are supplier permissions for renewable energy systems?
Supplier permissions are the approved identities, devices, applications, data and connection routes that an external organisation may use for a defined task. A sound process names the business or operational owner who approves access, the technical team that implements it, the supplier user who receives it, the date it will be reviewed or removed, and the evidence kept. Stratiis can support agreed business IT and shared platforms; access to generation, storage, SCADA or safety-critical systems remains under the operational owner and qualified specialist unless separately scoped and approved.
Supplier access should be useful, traceable and temporary
Clear permissions help work proceed while keeping responsibility visible across the organisation and its vendors.
Named users
Know which individual is using access and which supplier is accountable for that person.
Defined purpose
Link each permission to an asset, service, task or support agreement.
Approved route
Use the right identity, device and connection controls for the system involved.
End date
Review or remove access when a project, contract or support need changes.
What should a supplier be able to reach?
Start with the work to be done, then separate information access from platform administration and operational control. The business or operational system owner should approve the scope.
| Access area | Typical purpose | Approval and control question |
|---|---|---|
| Project documents and asset records | Review designs, warranties, maintenance history or handover material. | Which files are needed, who owns them and can sharing expire? |
| Maintenance application | View assigned work, record findings or update agreed asset fields. | Which role permits the task without changing unrelated records? |
| Business IT support | Diagnose an approved application or shared platform issue. | Who authorises support access and how is the session recorded? |
| Site connectivity and devices | Use an approved path from a managed device or a controlled site endpoint. | Which device and network standards apply at this location? |
| Operational technology | Specialist maintenance or fault work on generation, storage or control equipment. | Which operational owner, vendor and safety process must authorise the work? |
Who should approve an external contractor’s access?
The business or operational owner of the asset and system should approve the purpose, scope and duration. IT can implement the agreed identity, device and connection controls and keep an access record. Product permissions and operational changes may require the application vendor or qualified specialist as well. Approval should be renewed when the supplier’s work changes.
Keep decision rights clear across Stratiis, suppliers and operators
A supplier-access request should state who approves, provisions, supervises and removes each route.
| Responsibility | Typical owner | Evidence to retain |
|---|---|---|
| Business need and access approval | Asset, application or operational owner. | Task, systems, named users, permissions and expiry. |
| Business IT identity and device controls | Internal IT or Stratiis under the agreed support scope. | Provisioning record, authentication settings and access review. |
| Application-specific roles | Application owner and specialist vendor where required. | Role definition, test result and change approval. |
| Operational and safety-critical routes | Operational owner and qualified specialist. | Approved method, change record, supervision and restoration plan. |
| Offboarding | Request owner initiates; each technical owner removes its own access. | Closure check, account disablement and asset return. |
Do not assume that an ordinary remote-support account is suitable for an operational environment. Connections to SCADA, generation, storage or safety-critical systems need the operator’s approved architecture and change process.
Six checks for every supplier-access request
A short, repeatable record makes permissions easier to grant, review and remove.
Name the person
Use an individual supplier identity and record their organisation and sponsor.
State the task
Describe the asset, system and work that requires access.
Set the scope
Choose the smallest suitable role, data set and connection route.
Check the device
Agree equipment, authentication and security requirements before access starts.
Record expiry
Set a review or end date tied to the assignment or contract.
Plan removal
Name who closes each account, connection and application role.
Handle changes and incidents without losing track of access
Permissions need attention after setup, especially when suppliers, projects and sites change.
Review what is still needed
Compare active supplier accounts with current contracts, named contacts and assigned work. Confirm the owner, role and next review date. Remove access that no longer has a clear business purpose.
For shared asset records, see Connected Information. For broader identity controls, see Cybersecurity.
Respond to a concern
If a supplier account or device may be compromised, use the agreed incident route to contain access, preserve relevant records and involve the operational owner before any action that may affect a live asset. Then review replacement access and supplier communications.
See Monitoring and Response for the wider cyber response approach.
Put supplier permissions on a four-step cycle
Begin with the highest-impact supplier routes and work through the rest by risk and operational importance.
Inventory
List suppliers, named users, systems, sites and current access routes.
Approve
Confirm the task, owner, role, method and end date for each route.
Control
Apply the agreed identity, device, connection and recording measures.
Review
Recheck access after changes and remove it when the need ends.
Connect supplier permissions to the wider support plan
Access decisions depend on the systems, devices and support boundaries around them.
Asset system co-ordination
Map asset platforms, suppliers and responsibilities.
Renewable energy IT support
Support distributed teams, remote sites and shared business systems.
Mobile device management
Set device enrolment and policy controls for approved mobile work.
Co-managed IT
Bring specialist capacity around an internal technology team.
Supplier permissions for renewable energy explained
Why should suppliers use named accounts?
Named identities make it easier to approve access for the right person, review activity and remove access when that person changes role or leaves the supplier.
How much access should a maintenance contractor receive?
Enough for the agreed task and no more. The asset or system owner should define the records, applications and actions required, with a date for review or removal.
Can suppliers use their own devices?
That depends on the system and risk. The owner should agree the device standard and access route before work starts; some environments may require managed or site-provided equipment.
Does MFA replace an access approval?
No. MFA helps protect sign-in, while approval establishes who may access which system, for what purpose and for how long. Both are needed where appropriate.
How often should supplier permissions be reviewed?
Set a review date based on the assignment and system risk, and review sooner when a contract, named contact, scope or incident changes.
What happens when a supplier contract ends?
The sponsor should trigger offboarding. Each system owner should remove accounts, roles and connections within their scope, then confirm closure and recover any business equipment.
Can Stratiis approve access to SCADA or control systems?
No. The operational owner and qualified specialist must approve operational and safety-critical access under the relevant site process. Stratiis can coordinate agreed business IT dependencies.
What should an initial supplier-access review produce?
An inventory of suppliers and routes, named owners, priority gaps, expiry and removal actions, and a practical plan for ongoing review.
Review the routes into your renewable asset systems
We can help map agreed business IT access, clarify responsibilities with specialist suppliers and identify permissions that need an owner, a narrower scope or a clear end date.


