A new project engineer starts Monday. By Wednesday they still cannot open the project folder, their PMIS login is pending, and someone lent them a laptop from the closet. Meanwhile, a superintendent who left three weeks ago still has an active email account and access to the file share.
Neither problem is rare at PM/CM/AEC firms. Both come from the same place: the onboarding and offboarding process lives in one person's head.
Why this keeps happening
Most mid-size firms do not have a dedicated IT department. They have an office manager who handles IT, a partner who "knows computers," or an MSP that responds to tickets. Nobody owns the full lifecycle of a user account.
A single hire at a project-based firm touches a surprising number of systems:
- Email, Teams or Slack, and calendar
- File shares or SharePoint project sites
- PMIS access (Kahua, Procore, or similar) at the right project and role level
- Deltek or accounting system access for timesheets
- Scheduling tools like P6 for some roles
- Plan room, document management, and client portals
- A laptop, phone, MFA enrollment, and security training
Each item is simple. Together, they become a checklist that nobody wrote down.
Where the hours go
Chasing requests. HR tells the office manager, who emails the MSP, who asks which project folders the person needs, which goes back to the PM. Each handoff adds a day.
Guessing access levels. Without a role template, people get copied from "someone similar." That often means too much access, which matters for security and for CMMC.
Forgetting offboarding entirely. Onboarding has a deadline: the person's first day. Offboarding does not. Accounts stay active, licenses keep billing, and former staff keep access to client data.
No record. When an auditor, a client, or an insurance questionnaire asks "how do you remove access when someone leaves?" the honest answer is "we try to remember."
A better workflow
Define roles, not people
Write down what a project engineer, a scheduler, a field inspector, and an accounting user each need. Five to eight role templates cover most firms. New hires get a role, not a copy of someone else.
One trigger, one checklist
The HR event (offer accepted, last day set) should start one checklist that covers every system. Each step has an owner and a due date.
Treat offboarding as urgent
Disable accounts on the last day, not "when someone gets to it." Recover devices, transfer file ownership, and remove PMIS project access.
Keep the evidence
Every completed step should leave a record: who requested it, who approved it, when it was done. That record answers audits and security questionnaires without a scramble.
Where AI helps, and where it does not
AI is useful here because much of the work is routing, follow-up, and documentation.
It helps with:
- Taking a plain request in Teams or Slack ("Maria starts Monday as a project engineer on the Smith Street job") and turning it into the right checklist
- Following up on stalled steps instead of waiting for someone to notice
- Keeping a clean log of every access change
It does not replace:
- A person deciding who should have access to sensitive client data
- Physical device handling
- Judgment on exceptions
What matters: role definitions have to be right first. Automating a messy process just produces mess faster.
How we approach it
IQ-IT gives PM/CM/AEC firms an expert IT team that works where your staff already work, including requests through Teams or Slack. Onboarding and offboarding are usually among the first workflows we clean up, because they touch security, cost, and productivity at once.
A useful next step
Pull the list of active accounts in your email system and compare it to your current staff list. If the two do not match, that gap is your starting point. We are happy to walk through it with you. Talk to us.
Ready to simplify IT and CMMC?
Join hundreds of AEC teams already saving hours every week.