Construction projects depend on collaboration. Your site teams, project managers, consultants and subcontractors all need timely access to drawings, RFIs, submittals, documents and project communications.
That collaboration shouldn’t require broad access to your business network.
A zero-trust approach allows subcontractors to use Procore and related project systems while limiting what they can see, reach and change. Every request is verified. Every permission has a purpose. Every access path can be reviewed.
For construction firms, this creates a better balance between productivity and security.
Why shouldn’t subcontractors receive ordinary network access?
A Procore user doesn’t automatically need access to your corporate network.
Procore is a cloud platform. In most cases, subcontractors need access to specific Procore projects and tools, not your internal file servers, accounting systems, email environment or office network.
Giving an external user broad VPN or Wi-Fi access can create unnecessary risk. If their account is compromised, or their device contains malware, an attacker may attempt to move from one system to another.
That’s why zero trust starts with a simple principle:
Allow access to the application and information required for the job: not to the wider network.
For example, an electrical subcontractor may need to:
- View project drawings
- Respond to RFIs
- Upload documents
- Complete assigned inspections
- Update relevant forms
- Participate in project communications
They probably don’t need access to:
- Your finance or payroll systems
- Other construction projects
- Internal staff files
- Server administration tools
- Company-wide document libraries
- Unrestricted VPN access
The result is safer collaboration without slowing down project delivery.
What does zero trust mean for Procore access?
Zero trust means that no user, device or connection is trusted automatically.
Instead, access is evaluated using several factors:
- Who is the user?
- Which company or subcontractor do they represent?
- Which project are they working on?
- What task do they need to complete?
- Is their device secure enough to use?
- Does the request look normal?
- Should the access continue?
The model is built around three practical ideas:
- Verify explicitly: Confirm identity and context before allowing access.
- Use least privilege: Grant only the minimum permissions required.
- Assume breach: Design access so a compromised account has limited reach.
This approach is particularly valuable in construction, where project teams change frequently and external users may work across multiple organisations.
How should you structure subcontractor permissions in Procore?
Start with the project, tool and task: not the person’s job title alone.
Procore permissions are assigned on a per-tool, per-project basis. This gives construction firms a useful foundation for least-privilege access.
A subcontractor might receive:
- Read-only access to drawings and documents
- Standard access to RFIs
- Standard access to observations and punch lists
- Standard access to relevant forms
- No access to budgets, payroll information or company administration
Procore’s own subcontractor permissions guidance shows how access can be restricted across individual tools. It also notes that standard permissions for some tools, such as Submittals, may not be the typical setting unless the subcontractor needs to submit a response as part of a workflow.
Build access around clear roles, such as:
- Electrical subcontractor project manager
- Concrete subcontractor supervisor
- Mechanical subcontractor foreman
- Site safety consultant
- Specialist design consultant
For each role, document:
- Which projects the role can access
- Which Procore tools are required
- Whether access is read-only or standard
- Which actions are permitted
- Who approves the access
- When access expires
Avoid giving every subcontractor the same permission template. A person who only uploads site documentation shouldn’t receive the same access as someone managing a formal RFI or submittal workflow.
The best permission is the narrowest one that still lets the person complete their work.

How can you control guest access?
Treat every subcontractor account as a managed business relationship.
Guest access should never be an informal arrangement where someone receives a shared login or is added permanently “just in case”.
Instead, use a controlled process:
- A project or contract owner sponsors the request.
- The subcontractor is invited using their individual business identity.
- Their company and role are recorded.
- The required project and tools are selected.
- MFA is enrolled before access begins.
- An end date is assigned.
- Access is reviewed during the project.
- The account is disabled when the engagement ends.
Never use shared Procore accounts. Individual accounts provide accountability and make it possible to understand who viewed, uploaded, changed or approved information.
Where your identity platform supports it, use guest or business-to-business controls to apply separate policies to external users. Microsoft’s guidance for guest and external access recommends requiring MFA for guest users and limiting access to specifically designated services and resources.
A subcontractor should have a named account, a business reason and a defined end date.
Why is MFA essential for subcontractors?
Passwords alone aren’t strong enough for project collaboration.
Subcontractors may access Procore from offices, vehicles, temporary site offices and mobile devices. Password reuse, phishing and lost devices can put accounts at risk.
Multi-factor authentication adds another verification step, usually through an authenticator app or SMS. Even if a password is stolen, the attacker still needs the second factor.
Procore allows company administrators to enable MFA across the organisation and set an enforcement deadline. Procore recommends allowing users a transition period: its documentation suggests a 30-day window: to complete enrolment before enforcement begins.
A practical rollout could look like this:
- Announce the change to all internal and external users.
- Review and deactivate stale accounts first.
- Provide clear setup instructions.
- Set an enforcement date before the next major project phase.
- Require MFA for all users, including subcontractors and guests.
- Direct SSO users to configure MFA through the organisation’s identity provider.
If your business uses Microsoft Entra ID, Okta or another identity provider for single sign-on, apply MFA policies there as well. Don’t assume that a subcontractor’s home organisation has applied the same level of protection.
MFA should be a condition of access, not an optional extra.
How do device controls protect Procore access?
A valid user can still create risk if their device is unsafe.
Before allowing access, define a baseline for devices used to handle project information. Depending on your environment, this may include:
- Supported operating system
- Current security patches
- Disk encryption
- Endpoint protection or EDR
- Screen lock and password protection
- No jailbroken or rooted mobile devices
- Approved browser and application versions
- Ability to remove business data when access ends
For higher-risk projects, consider requiring subcontractors to use managed devices or a controlled access environment. This gives you greater control over updates, malware protection, browser settings and data handling.
Bring-your-own-device access can still be possible, but it should be risk-based. Options may include:
- Browser-only access
- Blocking downloads for sensitive documents
- Restricting copy and paste
- Session timeouts
- Conditional access checks
- Virtual desktop or application proxy access
Be careful with device-compliance policies for external users. A subcontractor’s device may be managed by their own organisation rather than yours. Microsoft notes that only one organisation can manage a device, so policies should be designed to avoid unintentionally blocking legitimate guests: or allowing unmanaged devices into sensitive systems.
Device controls should reflect the information’s sensitivity and the project’s risk profile.
How should you segment access paths?
Network segmentation limits the damage caused by a compromised account.
The safest design is usually to keep subcontractor access away from the internal LAN altogether. Give them application-level access to Procore rather than a broad VPN connection into the business.
If subcontractors need to access additional systems, separate those systems from critical infrastructure using:
- Guest wireless networks
- Separate VLANs
- Firewall rules
- Application-level access policies
- Zero Trust Network Access
- Privileged access management
- Microsegmentation between critical workloads
For example, a subcontractor may be allowed to access Procore and a specific document portal but blocked from:
- Domain controllers
- Backup systems
- Engineering servers
- Finance platforms
- Office printers and internal file shares
- Other project environments
This is the “assume breach” principle in action. If one account or device is compromised, segmentation reduces the attacker’s opportunity to move sideways through the business.

What should you audit and review?
Access is only secure when you can prove what happened.
Auditability means maintaining enough information to answer practical questions:
- Who accessed the project?
- When did they sign in?
- Which device and location did they use?
- Which tools were accessed?
- What was uploaded, changed or downloaded?
- Who approved the permission?
- When should access have ended?
- Was unusual activity detected?
Review records from multiple layers, including:
- Procore activity and user records
- Identity provider sign-in logs
- MFA events
- Endpoint security alerts
- Firewall or ZTNA logs
- Help desk tickets
- Contract and project records
Set a review cadence that matches the risk. Quarterly reviews may suit standard projects, while high-value or sensitive projects may need monthly or phase-based reviews.
At every review, confirm:
- The subcontractor is still engaged
- Their project assignment is current
- Their permissions still match their role
- Their account has been used appropriately
- Their device or access path meets policy
- Their end date is accurate
If an account no longer has a business reason, remove it.

What is a practical rollout plan for construction firms?
You don’t need to redesign everything at once.
Use this phased approach:
-
Inventory current access
List all subcontractor accounts, projects, permissions and access paths. -
Clean up stale users
Disable accounts for former employees, completed contracts and inactive engagements. -
Create role-based templates
Map common subcontractor roles to the minimum Procore tools and permission levels. -
Enable MFA
Communicate the change, allow time for enrolment and enforce MFA for every user. -
Improve guest governance
Require sponsorship, individual accounts, approval and expiry dates. -
Apply device requirements
Set a baseline for managed and unmanaged devices based on project risk. -
Remove broad VPN access
Replace network-level access with application-level controls wherever practical. -
Schedule regular reviews
Combine project, contract, identity and security reviews.
This process makes security part of project governance rather than an afterthought.
How can Whole IT help secure your construction technology?
The right security model should support your project teams, not obstruct them.
Whole IT helps Melbourne businesses assess their technology environment, strengthen cybersecurity controls and manage cloud-based systems. Our IT consulting services can help you design an access strategy that aligns with your projects, people and risk profile.
We can also support:
- Identity and MFA planning
- Network segmentation
- Firewall and secure remote access configuration
- Cloud security and migration
- Device and endpoint management
- Managed IT support
- Access reviews and technology policies
Our managed IT services provide ongoing support, monitoring and cybersecurity assistance, while our cloud services help businesses manage cloud applications and data more securely.
If your construction firm uses Procore and works with multiple subcontractors, now is the right time to review who can access what: and why. Contact Whole IT to discuss a practical zero-trust access plan for your business.