The instinct is to grant broad access because it is faster and because narrowing it feels like distrust. Neither reason survives examination. Most services distinguish between somebody who can view, somebody who can change things, and somebody who can change the account itself, and choosing the middle level for a contractor takes the same thirty seconds as choosing the highest one.
Use named accounts wherever the service supports them, which is the single most important decision here. Individual logins mean actions are attributable, permissions are adjustable per person, and removing somebody is one click rather than a password rotation that disrupts everybody else. Sharing your own credentials produces the opposite of all three and is the arrangement that causes the most difficulty later.
Keep administrative access to yourself, particularly on the accounts that are painful to lose. Your domain registrar, your business profile, your advertising accounts, and your analytics property should be owned by you with others granted a working level of access. A contractor holding the administrative role on any of those can, deliberately or by accident, lock you out of something you cannot easily recover.
Think about what the access actually exposes beyond the immediate task. Analytics access frequently includes the ability to change how conversions are counted. Advertising access includes spending. Email access includes the reset mechanism for everything else. The question is not whether you trust the person but what a mistake would cost, and that is a different calculation.
Set a review date at the moment you grant it. Access is granted for a project and outlives the project by default, because nobody is prompted to remove it. A note against the engagement, or a calendar reminder at the expected end, converts removal from something you would have to remember into something scheduled.
Enable two factor authentication before adding anybody, not after. Adding a person to an account without it means their credential is now another single point of failure for your business, and asking somebody to enable it later is a conversation most people never have.
Write the list somewhere that is not in your head, with the service, the person, the level, and the date. Six months in, a small business typically cannot enumerate who has access to what, and that uncertainty is what makes offboarding incomplete. The list takes a minute per entry and is the entire mechanism.
Then remove access the day the relationship ends rather than when you next think about it. This is uncomfortable when the parting is amicable and it is not personal, it is procedure, and treating it as routine from the first engagement is what makes it unremarkable when it matters.
Ask what they actually need rather than granting a level and hoping, because contractors frequently request administrative access out of habit when a lower level would do. A short conversation about which specific tasks they will perform usually narrows it considerably, and somebody competent will not object to being asked.
Document the removal alongside the grant, in the same note. Access lists tend to record what was given and not what was withdrawn, which produces a document that overstates your exposure and becomes untrusted. One line per change keeps it accurate enough to rely on.
Check what access was granted through connected applications as well as through logins, since tools linked to your accounts hold permissions that persist after a person leaves and are rarely reviewed.