Letting people in, and out
Adding someone takes ten seconds. Removing them takes remembering, which is why nobody does it.
Collaborators is where people from outside your organisation get access to specific work — a client on one project, a freelancer for six weeks, an accountant who needs one folder.
Grant the project, not the workspace
The instinct when someone needs to see one thing is to add them to everything, because it is faster and you can sort it out later. You will not sort it out later.
Give access at the narrowest level that lets them do the work. A freelance designer needs the project, not the workspace. A client needs the project they are paying for, not the one next to it with another client's name on it. This is not about distrust — it is that people see what is in front of them, and what is in front of them should be their own work.
Two questions decide the role
Can they change things, and can they invite others? Everything else follows from those.
Give edit rights to anyone whose job is to produce work, and view rights to anyone whose job is to have an opinion. A reviewer with edit rights will eventually change something by accident and nobody will know when. Keep the right to invite others inside your own team — an external collaborator who can add people turns your access list into someone else's decision.
The date is the part people skip
When you add someone for a fixed engagement, write the end date somewhere the same day. A calendar reminder is enough. This single habit is the difference between an access list that reflects reality and one that accumulates for three years.
Do the removal on the day the work ends, not when you next think about it. There is no polite moment to remove access, so there is never a good time, so it never happens. Make it automatic rather than a decision.
A ten-minute review, twice a year
Open the collaborator list and go down it asking one question per name: is this person still working with us? Not "could they still need it" — that answer is always maybe. Just the plain question.
You will find two or three every time. That is the point: the list is never wrong when you check it, only when you don't.
Questions people actually ask
What access should an external collaborator get?
The narrowest level that lets them do the work — the project, not the workspace. People see what is in front of them, and what is in front of them should be their own work rather than another client's.
Should collaborators be able to invite others?
No. Keep invitation rights inside your own team. An external collaborator who can add people turns your access list into someone else's decision.
How do I stop old access from piling up?
Write the end date the same day you add someone, and remove access on the day the work ends rather than when you next think of it. Then review the whole list for ten minutes twice a year.