Project management platforms tend to accumulate users the way a jobsite accumulates scrap lumber. Someone adds an architect for a single RFI, a subcontractor's assistant gets invited to a bid package, a project engineer leaves and nobody removes their account. A year later, dozens of people can see budgets, contracts and drawings they have no reason to see.
Procore is common across general contractors and specialty trades, so this walkthrough uses it as the example. The same approach works for other construction platforms.
Why permissions matter more than you think
Project platforms hold contract values, change orders, subcontractor pricing, insurance certificates, schedules and sometimes site security details. An over-permissioned account is a quiet risk in three ways:
- A compromised login exposes far more than it should.
- A departing employee can still reach competitive pricing.
- Licensing and seat costs may be higher than necessary, depending on how your plan is structured.
None of this requires a breach to cause trouble. Pricing leaking between subcontractors on the same bid is a business problem all by itself.
Step 1: Export the current user list
Start with a full list of users at the company level and at the project level. Capture name, email domain, role, permission template, last login date and the projects each person can reach. Put it in a spreadsheet.
Step 2: Sort people into groups
Most users fall into a handful of categories:
- Internal staff with a business reason for access
- Subcontractors and suppliers who should see only their own packages
- Owners, architects and engineers who need specific project access
- Former employees and stale accounts
- Unknown or unrecognized emails, such as personal webmail addresses
Anything in the last two groups goes to the top of your review list.
Step 3: Remove or suspend what is clearly stale
Check the last login date. Accounts with no activity for many months on a project that is closed out can usually be deactivated. Do this first for former employees, since an old account tied to a personal email is the easiest to overlook and the hardest to explain later.
Step 4: Rebuild around permission templates
Instead of granting rights one person at a time, define a small set of templates that match real jobs, for example:
- Executive read-only
- Project manager
- Superintendent and field
- Accounting
- Subcontractor limited
- Owner or design team limited
Compare each person's current rights to the closest template. The goal is not perfection on day one. It is to make access predictable so that new hires and new projects follow the same pattern.
Step 5: Protect the money tools
Budget, prime contract, commitments and change events deserve extra care. Limit who can edit them, and decide who can only view. Pair this with a rule that financial approvals above a set amount require a second person, which also helps against fraud.
Step 6: Require stronger sign-in
Turn on multifactor authentication for your company's users through your identity provider or the platform's own options, and require company email addresses for internal staff. Where possible, use single sign-on so that disabling someone's company account removes access everywhere at once.
Step 7: Tie access to onboarding and offboarding
The cleanup only lasts if the process changes. Add two lines to your HR checklists:
- When someone is hired or changes roles, a manager requests the correct template.
- When someone leaves, the platform administrator removes access the same day.
Also set a reminder to review access each quarter, and again whenever a large project closes.
Common mistakes to avoid
- Making everyone an administrator to avoid support calls
- Sharing one login among several field staff
- Leaving subcontractor accounts active after the contract ends
- Giving external users the same access as internal staff because it was quicker
How Ironfield Cyber helps
Ironfield Cyber supports contractors on construction software administration alongside security, including access reviews, role design and single sign-on setup. If your platform has grown into a maze of users, we can run the audit with your project operations team and leave you with a process you can maintain.