Work accounts usually get set up in a hurry for a task, and ownership is an afterthought. While a contractor is active, the difference between "given access" and "registered under their own name" doesn't show. It becomes critical the moment you part ways: an account tied to a contractor's personal number and email technically belongs to them, not the client. Here's where this mistake starts, what happens at a split, and how to hand off access so resources stay with the company.
The core mistake: the contractor's personal number and email
The common scenario: a contractor registers an ad account, a mailbox, or a messenger profile on their own phone number and personal email — faster than agreeing on separate credentials with the client. At first this looks harmless: the team has access, the account works. But the "number — account" and "email — account" binding fixes the owner at that moment, not the user. Formally it belongs to whoever's number and email are the recovery channel, not whoever pays for it.
What happens when you part ways
While things go smoothly, ownership never comes up — it surfaces exactly at the split, whichever side initiates it. A contractor holding the recovery number can change the password, switch 2FA to their own number, unlink payment methods, or stop responding. The client has no formal leverage: to the service, it's just someone else's profile.
Worse: the account held as leverage in a payment dispute — threatening to shut down live campaigns outweighs any contract clause, and recovering access through support takes weeks and needs evidence the client usually lacks.
The right scheme: access, not ownership
The working model is simple: the verification number, email and payment methods are set up under the client from day one, and the contractor gets a role inside an existing account rather than creating it themselves, connecting as an admin with rights that can be revoked in one action.
The difference in practice: to cut access, the client just removes the contractor from the user list — the account, history and settings stay untouched. If the account was created under the contractor, closing access needs their cooperation. The same applies to the surrounding environment: an antidetect browser profile and its proxy address should also sit on the client's infrastructure.
Handoff as a procedure
Changing contractors is a short procedure with fixed steps, required at every split. Three items: switching the second factor — 2FA moves to a channel the client controls, not the contractor's phone; revoking keys — API tokens and integrations are revoked entirely, not recycled; and transferring bindings — the recovery number, backup email and payment method are reassigned to the client across every service.
Run it right after work wraps up, not after an incident: access left "just in case" eventually gets used. When a contractor team scales up for a new task, build acceptance into the plan from day one — for instance, when preparing a one-week launch of a new direction, with several contractors joining at once.
An acceptance checklist for a contractor handoff
Before closing out with a contractor, run a short checklist instead of a verbal agreement:
- The verification number is registered to the client long-term, not the contractor's personal phone.
- The backup email was created separately, not the contractor's personal inbox.
- Two-factor authentication is switched to a channel the client controls.
- The list of active integrations and API keys is complete, and stale tokens are revoked.
- The former contractor's access is closed across every linked service, not just the main account.
What secures the verification number matters most. A one-off activation confirms the number once and returns it to the pool — a later re-login code may go to someone else. A long-term rental stays assigned the whole period, accepts unlimited inbound SMS, and renews from the dashboard without the contractor — the charge is deducted from the balance automatically, keeping the binding under the client's control.
Frequently Asked Questions
Can I just ask the contractor for the password at the end of the engagement?
You can, but the password isn't the only element of ownership: if the recovery number and email stay with the contractor, they can reset it anytime. What needs to change hands is the full set of bindings — number, email and 2FA, reassigned to the client.
What if the account is already on the contractor's personal number and the work is ongoing?
Reassign it now, without waiting for a split: move the number and email to the client's own infrastructure, switch the recovery binding and 2FA. The longer an account runs on someone else's credentials, the more services record that binding as primary.
Do I still need a rental if 2FA already runs through an authenticator app?
The app covers sign-in, not recovery: the phone number is usually still the fallback if the device is lost. Without a long-term rental under the client, that fallback is effectively controlled by whoever's phone is listed on it.
To keep the verification number under the client's control no matter how many contractors come and go, use turbon.rent number rental — an assigned number renews from the dashboard and never falls back into the shared pool.