Most AEC firms can name their team β not everyone who still has a login. What a project file access audit finds, and the six checks to run first.
BLOG
Who Still Has Access to your project files right now?
A question most architecture, engineering, and construction firms cannot answer from memory β and what a proper file access audit usually turns up.
Take thirty seconds and try to answer it. Not the version on the org chart β the real list. Everyone who could open your last completed project’s drawings, models, specs, and contracts today, if they decided to.
Most firms can name their own team in a few seconds. Very few can name the consultant who came in for two weeks during design development, the sub whose contract closed out in March, or the client contact who was sent a folder link that is still, quietly, live.
That gap between the list you would give from memory and the list your systems would actually produce is one of the most common security gaps we find at AEC firms. It is not caused by carelessness. It is caused by the way project work actually happens: fast, collaborative, and with a lot of hands.
The Short Answer: Nobody is expected to know this from memory. The point of a file access audit is that your systems can produce the list even when your team can’t β and that somebody owns the job of shortening it when a phase, a contract, or a relationship ends.
A single project has more access points than the org chart suggests
Walk one project from award to closeout and count the connections. A typical AEC project routes files through:
- Your own project team β principals, project architects or engineers, designers, admin staff.
- Outside consultants β structural, civil, MEP, geotechnical, landscape, code, acoustics. Often different consultants in different phases.
- The general contractor and their subs β each needing drawings, specs, and RFI history, and each with their own staff turnover.
- The owner or client representative β sometimes a single contact, sometimes a facilities team, sometimes a lender or insurer downstream.
- Reviewers and agencies β permit submittals, plan review comments, inspection records.
- Service vendors β reprographics, rendering and visualization, specification writers, surveyors, testing labs.
- Contract and temporary staff β the extra set of hands you brought on for a deadline, working from their own laptop.
Every one of those connections is legitimate and necessary. That is the point. A design and construction project cannot happen without them. But each one is also a door β and a door that was opened for a good reason still needs someone to close it when the reason ends.
The access nobody remembers to revoke
Here is the pattern we see most often. A project phase wraps up. The invoice is paid, the relationship ends on good terms, and everyone moves on to the next job. What nobody does is go back and turn off the login.
Β
Four kinds of leftover access account for most of what an audit uncovers:
1. The consultant from an earlier phase
Design development ended eight months ago. The structural consultant’s account still opens the current model folder β including every revision made since they left.
2. The sub whose contract ended
Their contract closed in March. Their access didn’t. Nobody made the decision to leave it open; nobody made the decision to close it either.
3. The share link with no expiry date
Someone needed to send a 4 GB model to a consultant quickly, so they generated a link. Links like that often default to “anyone with this link” and no end date. It is still in an email thread somewhere, and it still works.
4. The folder that lives outside the system
When the official method is slow, people route around it β a personal cloud account, a thumb drive, a home directory. Those copies are invisible to any permission you set on the real file server, and no one is watching them.
Β
And then there is the former employee. When someone leaves an AEC firm, their email usually gets handled the same week. Their access to project folders, the plan-room portal, the licensing account, and the shared drives they set up personally is a longer list β and it is the part that most often gets missed.
Why this matters in business terms, not IT terms
Someone builds from the wrong set.
Old access usually means an old copy is still reachable. When a contractor pulls a drawing that was superseded three revisions ago, the cost shows up as rework, a change order, or a schedule slip β and it does not look like an IT problem when it lands.
Your exposure now includes their security.
If a former vendor’s laptop is compromised, whatever it can still reach is part of the incident. Cyber-insurance applications increasingly ask how third-party access is controlled and removed, so the answer matters at renewal as well as during an incident.
Confidentiality you already promised.
Owner agreements, NDAs, and public-project requirements often define who may see project information. An account that was never turned off does not read the contract.
What good access control actually looks like, in plain language
None of this requires your team to learn a new discipline. It requires six things to be true, and someone to own each of them.
| What it’s called | What it actually means for your firm |
|---|---|
| A single source of truth | Project files live in one system. Not the file server and three personal cloud folders and a chain of email attachments. One place, so “who has access” is a question with one answer. |
| Access by role | People get access to what their job on this project requires this month — not everything the firm has ever produced. A consultant sees their discipline’s folders, not the full contract file. |
| External access with an end date | Guest accounts and share links expire on a date tied to the phase or the contract. Access ending becomes the default instead of a task someone has to remember. |
| Version control | One current set, with earlier versions preserved and clearly marked as superseded. Nobody has to guess which file is the live one. |
| An audit trail | A record of who opened, edited, downloaded, or shared a file, and when. This is what lets you answer a client’s question — or an insurer’s — with a fact instead of an assumption. |
| Offboarding as a step, not a memory | Removing access is a line item on your project-closeout and staff-departure checklists, with a named owner. If it depends on somebody remembering, it will eventually be missed. |
A six-point file access audit you can run this week
You do not need a consultant to get a useful first answer. Pick your most recently completed project and work through these six checks.
1. Pull the actual access list. Ask whoever administers your file system to export everyone β internal and external β who can currently open that project’s folders.
2. Compare it to the invoice list. Every outside company that appears on the access list but not on the closing invoices is a relationship that ended without the access ending.
3. Find every active share link. Look for links with no expiry date and links set to “anyone with the link.” Both should be rare and deliberate, not routine.
4. Search for files living outside the system. Ask your team directly and without blame: where did you put things when the official way was too slow? The honest answers are the useful ones.
5. Check departures. For anyone who left in the last twelve months, staff or contractor, confirm their access to project folders, portals, and shared accounts is gone β not just their email.
6. Confirm ownership. Name the person responsible for removing access at project close and at staff departure, and put it on both checklists in writing. Undocumented ownership is the same as none.
If you find something: Finding leftover access is the normal outcome of a first audit, not evidence that someone was negligent. The useful question is not who left the door open β it is what change makes it close by itself next time.
What we usually find first
The most common gap at an AEC firm is not a missing firewall. It is a roster mismatch: the list of people your IT setup treats as staff does not match the list of people actually working on your projects.
Β
A recent example. A Pacific Northwest architecture studio asked us to move its email to a new Microsoft 365 tenant β eight mailboxes, one cutover weekend, routine on paper. Several of those eight users were contractors rather than employees, which is entirely normal in design firms where project load flexes with contractor support instead of headcount. The common shortcut is to scope security setup for employees and bulk-add everyone else with weaker controls.
Β
We configured every account individually instead β Outlook and multi-factor authentication set up one person at a time, contractors and staff alike. That is the difference between an account that gets forgotten and an account that gets managed.
Frequently Asked Questions
How do I find out who has access to our project files?
Ask whoever administers your file storage to export the full permissions list for one project β every internal user, external guest, and active share link. In Microsoft 365, SharePoint, or a construction document platform, this is a report an administrator can run. Compare that list against the companies on your closing invoices; the difference is your leftover access.
How often should we review file permissions?
Two triggers matter more than a calendar: at the close of every project phase, and whenever anyone leaves β staff or contractor. On top of that, a full review once or twice a year catches the share links and stray folders that phase reviews miss.
Should we remove a subcontractor's access when their contract ends?
Yes, as a default. If they may need to return for warranty work or closeout documentation, the better answer is time-limited access you can renew rather than permanent access nobody revisits. Reinstating access takes minutes; an open account nobody is watching can sit for years.
Is a shared folder link secure enough for construction drawings?
It depends entirely on how the link is configured. A link restricted to named recipients with an expiry date is a reasonable tool. A link set to “anyone with the link” and no end date is effectively a public copy of your drawings that stays live as long as the email it was sent in exists.
Who should own access reviews at a 15-to-75 person firm?
A named person inside the firm should own the decision β usually an operations or office manager who knows which relationships are active. The technical execution can sit with your IT provider. What does not work is leaving the decision with IT, because IT cannot know that a consultant relationship ended last month unless somebody tells them.
OTHER RESOURCES
Most AEC firms can name their team β not everyone who still has a login. What a project file access...
The uncomfortable truth about why deadline-driven firms make the easiest targets β and the three...
Learn why business continuity matters for SMBs and how proactive IT, cybersecurity, and disaster...
Manual refund processes in healthcare often lead to inefficiencies, errors, and increased costs...
Learn how healthcare-focused IT security practices help support HIPAA compliance, protect patient...
stay in the know with greene is
We know IT can get complicated, so we break it down for you. Each month, Greene IS shares easy-to-digest tips, stories, and strategies to help you make sense of technology β and use it to your advantage.
"*" indicates required fields