Contractors have good reasons to connect their software. Procore synchronizes with accounting. Estimating tools feed project budgets. Timekeeping flows into payroll. Each connection saves hours of double entry and reduces mistakes. It also creates a new path into your data, usually with a service account or token that nobody is watching.
Most companies add integrations one at a time, when a project manager asks or a vendor suggests one. After a few years, there may be dozens of connections that nobody has fully reviewed. This post offers a straightforward method to evaluate integrations before you add them and to keep them under control afterward.
How integrations create risk
- Broad permissions. Apps often ask for more access than they need because it is easier for the developer.
- Long-lived tokens. An authorization granted once may last indefinitely, even after the employee who approved it has left.
- Third-party exposure. If the integration vendor is breached, the access it holds is exposed.
- Shadow integrations. A well-meaning employee connects a free tool to company data without telling anyone.
- Service accounts with admin rights. Created for convenience, never reviewed.
Before you approve a new integration
Ask about purpose and necessity
- What business problem does it solve, and who owns that problem?
- Is there a built-in feature or an already approved tool that does the same thing?
- What happens if we do not connect it?
Ask about access
- What exactly will the integration read, write, or delete?
- Can the permissions be narrowed to specific projects, tools, or data types?
- Does it use individual user authorization or a shared service account?
- How is the authorization revoked?
Ask about the vendor
- How do they protect the credentials and data they hold?
- Do they use multi-factor authentication for their own staff?
- Where is data stored, and for how long?
- Will they notify you of a security incident?
- Do they have a security overview, or independent assessment reports, they can share?
You do not need a long questionnaire for every small tool. Match the effort to the sensitivity of the data. An app that touches payroll or banking deserves more scrutiny than one that syncs a calendar.
Set simple rules
- One owner per integration. A named person is accountable, and a backup person is identified.
- Approval by IT or the controller for anything that touches financial, personnel, or contract data.
- Least privilege. Grant the narrowest permissions that work.
- Dedicated service accounts with unique credentials, not a personal login of the person who set it up.
- Multi-factor authentication wherever the platform allows it, including for the accounts that administer integrations.
- Document it. Record what it connects, why, who owns it, and what permissions it holds.
Review existing integrations
Gather a list from each major platform: Procore, accounting, Microsoft 365, payroll, estimating. Microsoft 365 and similar identity platforms also show which third-party apps have been granted consent. For each one:
- Is it still used?
- Who owns it?
- Does it have more permissions than it needs?
- When were its credentials last changed?
- Is the vendor still operating and supported?
Remove anything you cannot justify. Disconnecting an unused integration is a free security improvement.
Handle credentials carefully
Keep integration credentials in a password manager or secrets vault, not in spreadsheets or emails. Rotate them when staff leave, when a vendor reports a problem, and on a regular schedule where practical.
Plan for failure
If an integration vendor reports a breach, you should know how to revoke access fast. Keep a list of integrations with instructions for disabling each, and practice with one of them. Also consider what happens operationally when a connection is off. Can your team keep working manually for a day?
Watch for employee-installed tools
Set a policy requiring approval before connecting company accounts to outside apps. Configure Microsoft 365 or Google Workspace so that users cannot grant consent to unapproved apps without administrator review.
Annual cadence
Add integration review to your annual calendar, along with user access reviews and backup tests. Thirty minutes per platform is usually enough for the first pass.
Where Ironfield Cyber comes in
Ironfield Cyber supports Procore, Sage, Viewpoint, Autodesk, and Microsoft 365 environments for contractors and energy companies, including integration reviews. If you would like a map of what is connected to what, and who approved it, we can build one with you.