Project management platforms like Procore hold some of the most sensitive material a contractor owns: contracts, budgets, change orders, drawings, pay applications, and contact details for every owner, architect, and subcontractor on the job. They are also shared with outsiders by design. That combination makes a periodic settings review worthwhile.
This checklist is written for the person who administers the platform, which is often a project executive or operations manager rather than an IT specialist. The exact menu names change as vendors update their products, so use this as a guide to what to look for, and confirm details in your own account.
Start with who has access
Review the user list
Export or review the full list of users across the company account and projects. Look for former employees, former subcontractor staff, and accounts using personal email addresses. Remove anyone who no longer needs access. Departed employees with active accounts are one of the most common findings in any software review.
Check permission levels
Most platforms use permission templates. Confirm that each role gets only what it needs. Field staff rarely need access to full budget and prime contract data. Subcontractors should see their own commitments and the documents they are meant to receive, not the whole project directory.
Pay particular attention to the small number of company administrators. Keep them few, name them, and make sure at least two trusted people can manage the account so you are not dependent on one person's availability.
Strengthen sign-in
Require multi-factor authentication
If the platform supports it, require MFA for internal users, and encourage or require it for outside collaborators on sensitive projects. Where your company uses single sign-on through Microsoft 365 or another identity provider, connect the platform to it. That means disabling a departed employee's company login also removes their access here, which is far more reliable than remembering to deactivate each tool by hand.
Stop password reuse
Staff who reuse a work password on other sites create risk that the platform cannot fix on its own. A business password manager and a short policy on unique passwords help here.
Control what leaves the system
External sharing and downloads
Know how drawings and documents can be shared outside the platform. Public or open links can end up forwarded well beyond the intended audience. Where the platform offers expiring links or restricted sharing, use them for anything sensitive, particularly for work on critical infrastructure, government facilities, or defense-related projects where drawings may carry handling requirements.
Integrations and connected apps
Many platforms connect to accounting systems, scheduling tools, and third-party apps. Each connection holds a key that can read or write data. Review the list of connected applications and remove the ones nobody uses. Ask who approved each and what data it can reach.
Watch for scams that target project platforms
Attackers know contractors expect automated notifications from project software. Fake emails that imitate a document-share request or a bid invitation, and that lead to a login page copy, are a common way to steal credentials. Train staff to open the platform directly from a saved bookmark rather than clicking the link in a notification they were not expecting.
Also be alert to payment fraud. A message that appears to come from a subcontractor through the platform or by email, asking to change bank details on a pay application, should be verified by phone using a number you already have.
Make it routine
A one-time review decays quickly. Set a recurring calendar reminder to do the following every quarter:
- Remove inactive and departed users.
- Review administrator and high-permission accounts.
- Check connected apps and integrations.
- Confirm MFA is still enforced.
- Spot-check one active project for appropriate sharing.
Keep a short record of what you found and changed. If a dispute or an incident ever arises, a simple log showing regular access reviews is valuable.
Support from Ironfield Cyber
Ironfield Cyber supports contractors using Procore, Sage, Viewpoint, Autodesk, and Microsoft 365, including identity setup, access reviews, and secure integrations. If you would like a second set of eyes on your configuration, we can walk through it with your project and accounting teams.