Procore tends to become the system of record for a construction company faster than anyone plans for. It starts with one project, then the drawings, RFIs, submittals, budgets, and subcontractor contacts all land there. A few years later, nobody remembers who set up the permission templates, and half the people with access no longer work on those jobs.
This post walks through a practical Procore admin review that an operations manager or controller can run with IT, without needing to be a software specialist. The goal is simple: the right people see the right projects, financial data stays with finance, and outside parties only see what the contract requires.
Why permissions drift
Permissions drift because projects move faster than administration. A superintendent needs access today, so someone grants broad rights to save time. A project closes, but the team members stay on the roster. A subcontractor's office manager leaves, and their login lives on. None of this is malicious, but each leftover account is a door that nobody is watching.
Start with the company-level directory
Export or review the full company directory and sort it by last activity where the platform allows. Then ask these questions:
- Does every internal user still work here?
- Does every external user (subs, architects, owners' reps, consultants) still have an active role on at least one open project?
- Are there shared logins used by more than one person? Replace them with named accounts.
- Who holds company-level admin rights? Two or three named people is plenty. More than that is a risk.
Remove or deactivate, do not just ignore
An account that has not been used in months should be deactivated, not left alone. If the person returns, reactivating takes a minute. If the account is compromised, nobody will notice until damage is done.
Review permission templates
Permission templates control what each role can do in each tool. Over time, companies create one-off templates and then forget why they exist. Review each template and confirm:
- Standard users cannot see budget, prime contract, or commitment values unless their job needs it.
- Field staff have the rights to submit daily logs, photos, and inspections, but not to delete project records.
- Subcontractors see only the tools needed for their scope, such as drawings, RFIs, and their own submittals.
- Only designated roles can change directory entries or permission settings.
If a template is described by someone's name or "temp," that is a good sign it needs a second look.
Control multi-factor authentication and sign-in
Whatever the platform offers for single sign-on and multi-factor authentication, use it. If your company uses Microsoft 365, tying Procore sign-in to the same identity provider means that when an employee is offboarded, access ends in one place. Without that link, offboarding depends on someone remembering to log into every app.
For external users who cannot use your identity provider, require strong, unique passwords and encourage the use of authenticator apps where available.
Watch the integrations
Procore often connects to accounting, estimating, scheduling, and document tools. Each connection uses a token or service account with its own rights. Review them annually:
- List every connected app and who authorized it.
- Remove integrations that no one can explain.
- Confirm that service accounts have only the access the integration needs.
- Change credentials when the person who set them up leaves the company.
Tie administration to HR events
The most reliable fix is process, not a one-time cleanup. Build Procore into your onboarding and offboarding checklists:
- New hire: role assigned, template chosen by job title, projects added by the project manager.
- Role change: old project access reviewed and removed.
- Termination: access removed the same day, with confirmation from the administrator.
- Project closeout: external access reviewed and trimmed, and the roster archived.
Schedule a quarterly review
Put a recurring 45-minute review on the calendar. Look at new users, removed users, admins, templates, and integrations. Keep a short log of what you changed and when. If your insurer or a prime contractor ever asks how you control access to project data, that log is a simple, credible answer.
Where Ironfield Cyber fits
Ironfield Cyber supports Procore and other construction platforms alongside Microsoft 365 for contractors across Texas. If you would like a second set of eyes on your permission templates, admin roles, and integrations, we can run a short access review and hand you a prioritized list of fixes.