procore-security-basics
Installation
SKILL.md
Procore Integration Security Boundary
Overview
Protect construction data by constraining identity, company and project scope, transport, stored artifacts, and operator actions. Procore authorization is permission-based; neither a valid token nor a successful request proves least privilege.
Prerequisites
- Data-flow diagram, asset classification, trust boundaries, and named security owner
- OAuth grant, credential locations, DMSA manifest, and permitted-project inventory
- Webhook destinations, file flows, log sinks, support path, and revocation procedure
Instructions
Step 1: Inventory secrets and principals
Locate client secrets, access and refresh tokens, webhook destination secrets, cookies, and signed URLs. Ensure each secret has an owner, approved store, rotation path, and narrow audience.