Procore Integrations Audit: Who Has API Access to Your Data?

Connected apps and API tokens can read your project data long after anyone remembers approving them. Here is a simple audit to find and trim them.

3 min readBy Ironfield Cyber Team

Construction teams love connecting tools. A scheduling app syncs with the project platform, a reporting dashboard pulls cost data, a photo tool uploads to project folders, and an accounting system exchanges information. Each connection saves time. Each one also creates a standing permission that can read, and sometimes change, your project data.

Over a few years, these connections pile up. The employee who approved one has left, the vendor was replaced, and nobody remembers what some of them do. An integrations audit finds them and decides what stays. The steps below apply to Procore and to most construction platforms, though menu names vary and you should check your own administrative settings.

Why Integrations Are a Risk

  • Standing access. A connected app often keeps access until someone removes it, regardless of whether the person who approved it is still employed.
  • Broad permissions. Apps frequently request more access than they need because it is easier for the developer.
  • Third-party security. If the vendor of a connected app is breached, the access it holds can be abused.
  • Credential sprawl. API keys and tokens are copied into scripts, spreadsheets, and shared documents.
  • Invisible data flow. Information may be sent to services you have never reviewed.

Step 1: Build an Inventory

Gather information from several places:

  1. The platform's administrative area, where connected apps, marketplace apps, and API credentials are usually listed.
  2. Your IT provider's records of approved software and single sign-on connections.
  3. Accounting and project teams, who know which tools they use.
  4. Browser and device records of extensions or desktop connectors.

For each integration, record the name, vendor, purpose, who requested it, who owns it today, what access it has, and the date it was last used.

Step 2: Ask Four Questions About Each One

Is it still needed?

If no one can explain what it does, or it has not been used in months, plan to remove it. Confirm with the business owner before turning it off, in case it feeds a monthly process.

Does it have the minimum access it needs?

Review the permission scopes. A reporting tool that only reads data should not be able to edit or delete. If the platform allows narrower access, reduce it.

Is it tied to a person or a service account?

Integrations authorized by an individual's login stop working or become risky when that person leaves. Prefer dedicated service accounts with limited roles, owned by a department rather than an individual.

Do we trust the vendor?

Check whether the vendor provides security documentation, supports multi-factor authentication, and has a way to report issues. Review the contract or terms for how they handle your data.

Step 3: Clean Up

  • Revoke unused integrations and API tokens.
  • Rotate keys and tokens that have been shared widely or stored in insecure places.
  • Replace personal accounts used by integrations with service accounts.
  • Reduce permissions to the minimum required.
  • Document each remaining integration and its owner.

Do this carefully and in stages, communicating with users, so you do not break a process crucial to month-end or payroll.

Step 4: Set Rules for the Future

Approval process

Require that new integrations be requested, reviewed, and approved by a designated person, often the platform administrator together with IT. Include a short review of security and data sharing.

Naming and ownership

Name each integration clearly and assign a business owner who gets a reminder to review it annually.

Storing credentials

Keep API keys in a secrets vault or password manager, not in emails or shared spreadsheets.

Offboarding

Add integration review to the employee offboarding checklist. When someone who created or owned an integration leaves, reassign it immediately.

Monitor Activity

Where the platform offers audit logs or API usage reports, review them occasionally for unusual patterns, such as large exports at night or access from unfamiliar locations. Set alerts if available.

Include Other Systems

The same approach applies to your accounting platform, document storage, Microsoft 365 app registrations, and any system with a marketplace or add-on ecosystem. Microsoft 365 in particular lets users grant apps access to mailboxes and files unless an administrator restricts it. Consider requiring admin approval for new apps.

Make It Routine

Schedule the audit once or twice a year, and keep a short record of what was found and changed. The first review tends to turn up surprises; later ones go quickly.

How We Can Help

Ironfield Cyber can help you inventory connected apps across your construction platforms, trim excess access, and set up a lightweight approval process, so productivity tools do not become the quiet back door to your project data.