Renewable energy · supplier access

Give specialist suppliers the access they need, with clear ownership

Renewable energy operators rely on maintenance contractors, application vendors, equipment specialists and project partners. Stratiis helps coordinate approved business IT access, devices and support routes so each supplier can complete agreed work without creating an open-ended route into asset information or systems.

What are supplier permissions for renewable energy systems?

Supplier permissions are the approved identities, devices, applications, data and connection routes that an external organisation may use for a defined task. A sound process names the business or operational owner who approves access, the technical team that implements it, the supplier user who receives it, the date it will be reviewed or removed, and the evidence kept. Stratiis can support agreed business IT and shared platforms; access to generation, storage, SCADA or safety-critical systems remains under the operational owner and qualified specialist unless separately scoped and approved.

Why it matters

Supplier access should be useful, traceable and temporary

Clear permissions help work proceed while keeping responsibility visible across the organisation and its vendors.

Named users

Know which individual is using access and which supplier is accountable for that person.

Defined purpose

Link each permission to an asset, service, task or support agreement.

Approved route

Use the right identity, device and connection controls for the system involved.

End date

Review or remove access when a project, contract or support need changes.

Access map

What should a supplier be able to reach?

Start with the work to be done, then separate information access from platform administration and operational control. The business or operational system owner should approve the scope.

Access area Typical purpose Approval and control question
Project documents and asset records Review designs, warranties, maintenance history or handover material. Which files are needed, who owns them and can sharing expire?
Maintenance application View assigned work, record findings or update agreed asset fields. Which role permits the task without changing unrelated records?
Business IT support Diagnose an approved application or shared platform issue. Who authorises support access and how is the session recorded?
Site connectivity and devices Use an approved path from a managed device or a controlled site endpoint. Which device and network standards apply at this location?
Operational technology Specialist maintenance or fault work on generation, storage or control equipment. Which operational owner, vendor and safety process must authorise the work?

Who should approve an external contractor’s access?

The business or operational owner of the asset and system should approve the purpose, scope and duration. IT can implement the agreed identity, device and connection controls and keep an access record. Product permissions and operational changes may require the application vendor or qualified specialist as well. Approval should be renewed when the supplier’s work changes.

Responsibility and boundaries

Keep decision rights clear across Stratiis, suppliers and operators

A supplier-access request should state who approves, provisions, supervises and removes each route.

Responsibility Typical owner Evidence to retain
Business need and access approval Asset, application or operational owner. Task, systems, named users, permissions and expiry.
Business IT identity and device controls Internal IT or Stratiis under the agreed support scope. Provisioning record, authentication settings and access review.
Application-specific roles Application owner and specialist vendor where required. Role definition, test result and change approval.
Operational and safety-critical routes Operational owner and qualified specialist. Approved method, change record, supervision and restoration plan.
Offboarding Request owner initiates; each technical owner removes its own access. Closure check, account disablement and asset return.

Do not assume that an ordinary remote-support account is suitable for an operational environment. Connections to SCADA, generation, storage or safety-critical systems need the operator’s approved architecture and change process.

Practical starting points

Six checks for every supplier-access request

A short, repeatable record makes permissions easier to grant, review and remove.

Name the person

Use an individual supplier identity and record their organisation and sponsor.

State the task

Describe the asset, system and work that requires access.

Set the scope

Choose the smallest suitable role, data set and connection route.

Check the device

Agree equipment, authentication and security requirements before access starts.

Record expiry

Set a review or end date tied to the assignment or contract.

Plan removal

Name who closes each account, connection and application role.

Day-to-day control

Handle changes and incidents without losing track of access

Permissions need attention after setup, especially when suppliers, projects and sites change.

Review what is still needed

Compare active supplier accounts with current contracts, named contacts and assigned work. Confirm the owner, role and next review date. Remove access that no longer has a clear business purpose.

For shared asset records, see Connected Information. For broader identity controls, see Cybersecurity.

Respond to a concern

If a supplier account or device may be compromised, use the agreed incident route to contain access, preserve relevant records and involve the operational owner before any action that may affect a live asset. Then review replacement access and supplier communications.

See Monitoring and Response for the wider cyber response approach.

How support starts

Put supplier permissions on a four-step cycle

Begin with the highest-impact supplier routes and work through the rest by risk and operational importance.

1

Inventory

List suppliers, named users, systems, sites and current access routes.

2

Approve

Confirm the task, owner, role, method and end date for each route.

3

Control

Apply the agreed identity, device, connection and recording measures.

4

Review

Recheck access after changes and remove it when the need ends.

Related Stratiis services

Connect supplier permissions to the wider support plan

Access decisions depend on the systems, devices and support boundaries around them.

Frequently asked questions

Supplier permissions for renewable energy explained

Why should suppliers use named accounts?

Named identities make it easier to approve access for the right person, review activity and remove access when that person changes role or leaves the supplier.

How much access should a maintenance contractor receive?

Enough for the agreed task and no more. The asset or system owner should define the records, applications and actions required, with a date for review or removal.

Can suppliers use their own devices?

That depends on the system and risk. The owner should agree the device standard and access route before work starts; some environments may require managed or site-provided equipment.

Does MFA replace an access approval?

No. MFA helps protect sign-in, while approval establishes who may access which system, for what purpose and for how long. Both are needed where appropriate.

How often should supplier permissions be reviewed?

Set a review date based on the assignment and system risk, and review sooner when a contract, named contact, scope or incident changes.

What happens when a supplier contract ends?

The sponsor should trigger offboarding. Each system owner should remove accounts, roles and connections within their scope, then confirm closure and recover any business equipment.

Can Stratiis approve access to SCADA or control systems?

No. The operational owner and qualified specialist must approve operational and safety-critical access under the relevant site process. Stratiis can coordinate agreed business IT dependencies.

What should an initial supplier-access review produce?

An inventory of suppliers and routes, named owners, priority gaps, expiry and removal actions, and a practical plan for ongoing review.

Make supplier access easier to govern

Review the routes into your renewable asset systems

We can help map agreed business IT access, clarify responsibilities with specialist suppliers and identify permissions that need an owner, a narrower scope or a clear end date.

Book a technology reviewExplore asset system co-ordination