Construction project manager reviewing job site plans on a tablet wearing a hard hat

Former Subs and Ex-Staff Still Have Your Construction Logins

October 06, 2026•11 min read

Your estimating software knows more about your business than almost anyone. It holds your pricing models, your material cost formulas, and your win history on bids going back years. There's a reasonable chance someone who no longer works for you can still log into it right now.

A general contractor in Coral Gables wrapped up a commercial renovation project last March. The sub who handled electrical was done, paid, and gone. Three months later, someone used that sub's Procore credentials to download bid packages for two open projects. The GC didn't find out until a competing bid came in 4% under his number on both jobs.

He wasn't hacked. His passwords weren't stolen in a breach. He just never removed the login. Nobody on that project had bad intentions. The sub had moved on. The GC had moved on. A set of credentials sat in a system nobody was checking.

Key Takeaways

  • Former subs and ex-employees commonly retain active access to Procore, Builder Trend, and project email for months after leaving.

  • Open logins expose your active bids, change order history, and client data to people who no longer work for you.

  • General contractors are adding access management questions to subcontractor prequalification checklists.

  • A credential audit of your full software stack takes one afternoon and can close dozens of open access points.

  • Enabling MFA on Procore, Builder Trend, and Microsoft 365 is free, takes under an hour, and stops most credential-based breaches cold.

Why Construction Firms Have More Credential Exposure Than Most Industries

Construction isn't like a typical office environment. A law firm with 20 employees changes personnel slowly. A general contracting firm running five simultaneous projects might cycle through 40 subcontractors in a quarter, each needing some level of access to project software, shared drives, or communication tools.

The problem starts the moment access gets provisioned. A new superintendent joins and needs Procore access. The office manager sets it up. Two months later, that superintendent moves to a different firm. Procore doesn't auto-expire the account. Builder Trend doesn't know someone left. Microsoft 365 still has the account enabled unless someone explicitly disables it.

In most construction firms, "someone" is whoever has admin rights and happened to be around that day. When a project wraps and everyone moves on, the offboarding checklist, when one exists, covers keys and lien waivers. Software access is rarely on the list.

The tools most likely to carry stale access

Walk through a typical South Florida GC's software stack:

  • Procore or Builder Trend for project management. Both maintain their own user lists. A sub's project coordinator account persists until an admin manually removes it.

  • Microsoft 365 for email and SharePoint. Shared mailboxes and SharePoint folders don't expire. A departing PM's account can stay active for months if no one submits a deactivation request.

  • Estimating software like Sage Estimating, STACK, or ProEst. These hold your pricing models, material cost databases, and bid history. It's the most competitively sensitive data a construction firm owns.

  • Shared Google Drive or Dropbox folders used for subcontractor document sharing. Once someone is added to a shared folder, they stay added indefinitely.

  • Field communication tools like Teams groups or shared WhatsApp threads. A former employee in a project channel can read every message sent after they leave.

Actionable tip: Pull the user list from Procore or Builder Trend right now. Sort by last login date. Anyone who hasn't logged in for 60 days and is no longer on an active project should be reviewed for removal today.

What a former sub or ex-employee can do with an open login

The most damaging scenarios aren't dramatic. They're quiet.

A former sub downloads your bid packages for active projects. He now knows your pricing approach and can share it with a competitor, or start competing directly. You lose bids you should have won, and you'll never know why.

A former project coordinator still has Microsoft 365 access. She can read emails in the project inbox. She sees which clients are unhappy, which disputes are unresolved, and what's coming up for rebid. If she goes to a competing firm or a plaintiff's attorney, that information is no longer yours.

A disgruntled ex-employee with Procore admin rights archives or deletes project documentation before a dispute goes to mediation. The damage there doesn't need elaboration.

None of these require technical skill. They just require that you forgot to hit deactivate.

What General Contractors Are Now Requiring From Subs

This is where the business case becomes concrete. GCs across South Florida and nationally are tightening their prequalification requirements. Cyber insurance underwriters started requiring it. Owners of larger commercial projects increasingly tie their contractor requirements to documented security practices. After several high-profile fraud cases tied to subcontractor credential misuse, some GCs are asking pointed questions before awarding work.

I sat with a project manager at a mid-size GC in Miami last year, and she showed me the firm's updated subcontractor prequalification checklist. It had an entire section on cybersecurity: access management policies, MFA use on project software, and incident history. Two years ago, that section didn't exist.

If you can't answer those questions, or if your answer is "we don't have a formal policy," you're at a disadvantage before the bid even starts.

What prequalification questionnaires include

The specific questions vary by GC, but you'll typically see versions of these:

  • Do you have a documented offboarding process that includes revoking software access?

  • Do you require multi-factor authentication for your project management tools?

  • Have you had a cybersecurity incident in the past 24 months?

  • Do you have a written data handling policy for client project information?

These are increasingly pass/fail on projects where the GC or project owner has their own cyber insurance requirements. You want to be in the "yes" column before the question is asked.

Actionable tip: Before your next prequalification submission, log into your Procore or Builder Trend admin panel and confirm you can see each user's last login date. If you can't answer the auditor's question with a screenshot, the process fix comes before the paperwork.

For more on how security compliance ties directly to bid results, read our breakdown of what GC security requirements look like in practice.

How to Audit and Clean Up Your Access in One Afternoon

A construction firm with 20 people and a typical software stack can audit and close credential gaps in one focused afternoon. Here's how.

Step 1: list every system with user accounts

Start with a spreadsheet. List every tool in your tech stack that requires a login. For each one, note who holds admin rights and whether the tool provides a user export or list view. The systems that matter most:

  • Project management (Procore, Builder Trend, Autodesk Build)

  • Email and collaboration (Microsoft 365, Google Workspace)

  • File storage (SharePoint, Google Drive, Dropbox)

  • Accounting (Sage 100 Contractor, QuickBooks, Foundation)

  • Estimating software

  • VoIP and phone systems

  • Any client-facing subcontractor portal

Step 2: cross-reference users against your current roster

For each system, pull the full user list. Compare every account against your current employee and active-contractor list. Flag anyone who left in the past 12 months, finished their project more than 90 days ago, or shows up with multiple email addresses, a sign of improper provisioning.

Step 3: deactivate, don't delete

For most systems, disable or deactivate the account rather than permanently deleting it. Deactivating keeps the audit trail intact. If there's ever a dispute about what someone accessed, you want that history available. Deleting the account removes it.

In Microsoft 365, disabling an account blocks email access immediately while keeping the mailbox for 30 days under default retention settings. That's the right sequence: kill access first, preserve data second.

Actionable tip: When you deactivate an account, also check whether that person held admin rights on any system. Admin access needs to be revoked separately. In some tools, disabling a standard account doesn't remove admin-level API tokens the account generated.

Our managed IT services include credential audits and access reviews as part of standard monthly operations, so you're not relying on a one-time cleanup that drifts over time.

MFA: The Control That Stops the Most Credential Damage

Even with good offboarding, credentials get compromised. A former PM might have already shared a password. An active employee might use the same password across personal and work accounts and get phished on a personal device. Passwords alone aren't enough.

Multi-factor authentication (MFA) limits what a stolen credential can do. Even if someone has the right username and password, they need a second factor: typically a code generated by an authenticator app or sent to a registered phone. Without it, the login fails.

Procore, BuilderTrend, Microsoft 365, and Google Workspace all support MFA natively. It takes 15 to 30 minutes to configure and costs nothing beyond what you're already paying. The reason most construction firms don't have it: it's optional by default, and nobody has made it required.

Where to start with MFA enforcement

Work through this order:

  • Microsoft 365 first. A conditional access policy can require MFA for all users connecting from outside your office network. This covers email, SharePoint, Teams, and every Microsoft app in one setting.

  • Procore or Builder Trend second. Your primary project data is here. Enable MFA in the admin settings and set it as required for all user roles.

  • Estimating software third. If it supports MFA, enable it. This is where your competitive edge lives.

  • Accounting software fourth. Sage Contractor, QuickBooks, Foundation. These hold payment terms, banking details, and vendor information.

For a full picture of the cybersecurity controls available to construction firms your size, we've put together a breakdown of what's practical at different staffing levels.

Actionable tip: Check your Microsoft 365 admin center today. Go to Identity, then Security, then MFA. See how many users have it registered. If fewer than 80% of your team is enrolled, that's the gap most likely to matter at your next cyber insurance renewal.

Ready to know exactly where your access gaps are? We run free workflow and security assessments for construction firms across South Florida. Book your assessment here. We'll tell you which systems have open logins and what your insurance renewal is likely to ask for.

Frequently Asked Questions

Can a former sub see my current bids if their Procore account is still open?

Yes. If their account is active and set to the same permission level it had during the project, they can log in and view whatever that role allows. A sub with "All Projects" access who hasn't been deactivated can see every active project you have in the system.

How do I know if someone has already accessed our system after they left?

Procore and Builder Trend both log login events and user activity. Pull the audit log for any account you're concerned about and check the timestamps. Microsoft 365 keeps sign-in logs under Azure Active Directory. If you need help reading them, your IT provider can pull a clean export that shows exactly when and from where each account was accessed.

Does MFA work for subcontractors or just employees?

MFA applies to any account in the system: employees, subs, and owners alike. You can configure Procore to require MFA for all users, including external ones, before they access project data. Some subs push back on it, but a GC can make it a condition of access, and more are doing exactly that.

Is this covered by my existing IT support contract?

It depends on your agreement. Some IT contracts include user account management; others bill by the ticket. Ask your current provider whether credential audits and MFA deployment are included. If they're not, or if you don't have a support agreement, a one-time IT support engagement is a low-cost way to get it done.

We're a small firm with under 10 people. Does this apply to us?

Smaller firms often have more exposure, not less. There's less structure around onboarding and offboarding, and accounts accumulate without anyone auditing them. A five-person GC running three projects can easily have a dozen Procore accounts set up over the past two years with no one having reviewed them. Credential risk doesn't scale by headcount.

Ready to Find Out Who's Still Logged In?

We work with construction firms across South Florida to audit access, deploy MFA, and build the offboarding process your insurance renewal, and your GC clients, are starting to require. The assessment is free and takes about an hour.

Schedule your free security assessment and let's find the open logins before someone else does.

You can also learn more about our construction IT services or explore how credential exposure connects to fraud patterns we see across South Florida GCs.

constructioncybersecurityaccess controlcredential securityprocore security
Back to Blog

Get Your Questions Answered

We're happy to help. Call us at (786) 386-1092 or send us a message.