A DFW general contractor’s technology stack has 6 layers, a project record system, an identity layer for outside companies, job cost accounting, field capture, payment controls, and a 10 year archive. Most contractors buy layer 1 and inherit the other 5 by accident.
Short version. Most construction IT advice is a software shopping list, and that is only layer 1 of 6. The layers that decide whether your projects run clean are identity for the outside companies you work with, controls on the money moving through accounts payable, and an archive that stays readable 10 years after substantial completion. Start there. The software argument settles itself afterward.
I’ve sat in a lot of DFW contractor offices where the IT conversation opens with a software name. Procore or Autodesk Build. Sage or Vista. Those are real decisions. They’re also the easiest fifth of the problem. Start higher up.
Here is what makes a general contractor different from every other business we support in North Texas. A manufacturer’s systems hold a manufacturer’s data. A law firm’s systems hold a law firm’s files. A GC’s systems hold everybody else’s. Sub submittals, architect models, owner change directives, vendor invoices, testing lab reports. Every one of them. You are the custodian of a record you did not create and cannot fully control, and you may have to produce a defensible version of it 8 years after the crews leave.
That changes what the stack has to do. So this is the 6 layers as they actually get used on a DFW job, what breaks in each one, and the order I would fix them in.
What belongs in a general contractor’s technology stack
A general contractor’s technology stack is the set of systems that create, move, protect and preserve the project record. It spans 6 layers. Project management, external identity, job cost accounting, field capture, payment controls, and long term retention. Software sits in the first 4. The last 2 are usually inherited rather than chosen.
| Layer | What it holds | Common DFW setup | What breaks |
|---|---|---|---|
| 1. Project record | RFIs, submittals, daily reports, photos, change orders | Procore or Autodesk Build, sometimes the owner’s instance | Access ends when the job does |
| 2. External identity | Who from which company can open what | Microsoft Entra guest accounts, added ad hoc | Nobody ever removes them |
| 3. Job cost accounting | Contracts, pay applications, retainage, WIP | Sage 300 CRE or Viewpoint Vista, often on a server | Built for a wired LAN the field does not have |
| 4. Field capture | Photos, quantities, safety, time and material tickets | Phone and tablet apps, company and personal devices mixed | Sync gaps and unmanaged hardware |
| 5. Payment controls | Wire instructions and vendor banking changes | Email, plus a phone call if you are lucky | Business email compromise |
| 6. Retention | The entire record after closeout | Whatever the subscription happens to keep | The statute of repose outlives the contract |
Read that right column again. Only one of those failures is a software problem. Just one.
Why a DFW stack is not a Houston stack
The Dallas-Fort Worth-Arlington metro is 11 counties. Collin, Dallas, Denton, Ellis, Hunt, Johnson, Kaufman, Parker, Rockwall, Tarrant and Wise. The Bureau of Labor Statistics splits the metro into 2 separate divisions, Dallas-Plano-Irving and Fort Worth-Arlington-Grapevine, because they behave like distinct labor markets. That split is real.
The same release put mining, logging and construction employment across the metro at 261,800 in May 2025, up 8,200 or 3.2 percent over the year, with 172,500 of that in the Dallas division and 89,300 in Fort Worth. Nationally the picture is thinner. The Associated General Contractors of America reported in June 2026 that only 152 of 360 metro areas added construction jobs over the previous 12 months, while 161 lost them. Growth is not universal. DFW is on the right side of that line.
For a technology stack, the county count matters more than the job count. A GC running 6 active DFW projects is running them across as many permitting jurisdictions, inspection calendars and carrier footprints. Our Houston construction clients deal with one enormous county and a ship channel. DFW contractors deal with a grid. Standardization pays here.
Layer 1, the project record you might not own
Every contractor I talk to assumes the project record belongs to them. Sometimes it does. On owner-provided platforms it often does not.
The pattern goes like this. The owner buys the platform for the project and invites your team in. Your PMs push 18 months of RFIs, submittals, daily reports and several thousand photos through it. Then the job closes out, the accounts get deactivated, and the record of your own work sits behind a login you no longer have. It happens constantly.
This one is unglamorous, and it holds up. Decide in writing, at contract execution, who exports what and how often. Monthly, not at closeout. A closeout export is a promise kept by whoever is least motivated to keep it.
Five things worth settling before the first submittal moves.
- Which platform is the system of record, and who pays for it
- Who holds an administrator account on your side, not just a project role
- What the export cadence is, and where the export actually lands
- Which fields survive an export and which are lost in the transfer
- Who exports the photo library, which is the largest and least portable asset you have

Layer 2, identity is the actual stack
Ask a contractor how many companies touch a project and you get a number. Around 30, usually. Ask how many people from outside your company have a live login into your systems right now and you get a shrug. Nobody knows. That gap is layer 2.
Microsoft handles this through business to business collaboration in Entra ID. You invite a person from another organization, they sign in with their own credentials in their own tenant, and you grant access to specific resources without ever creating or resetting a password for them. Microsoft’s documentation is clear that every internal user is enabled for this by default, which is worth knowing before you assume nobody has invited anyone. Check that first.
The control surface is cross-tenant access settings. You set a default posture that applies to every outside organization, then override it per organization, and Microsoft notes there is no limit on how many organizations you can configure that way. You can also choose to trust multifactor authentication and device compliance claims from a partner tenant instead of pushing their people through your MFA a second time.
That last option is where the real decisions live. Trusting a large mechanical contractor’s MFA posture is reasonable. Trusting a 3 person survey outfit’s is not. Same setting, opposite answer.
What outside access should look like on day 1
- Every guest account maps to a named person at a named company on a named project
- Access is granted to a specific site or folder, never to the whole tenant
- Multifactor authentication is required, either theirs or yours
- An expiry date is set at invitation, matched to the subcontract term
What it should look like on day 400
This is the part that never happens. The framer finished in month 7. Their 4 accounts are still active in month 19, still able to open the current drawing set, still sitting in a tenant that a subcontractor employee left the company from a year ago. Nobody is being careless. There is just no trigger.
Build the trigger into a calendar rather than a policy document. A quarterly review of every external account, run against the active project list, takes an afternoon and removes more risk than most of what gets sold as cybersecurity in Dallas. Tie account expiry to substantial completion of the trade, not to a date someone typed once. Put it on the calendar.

Layer 3, the accounting system that still wants a wire
Read the vendor requirements. Sage publishes its own, and they are more revealing than any comparison chart. For Sage 300 Construction and Real Estate versions 24 and 25, the recommended workstation configuration is a high speed network connection, preferably gigabit Ethernet, with a wired connection to the server. Supported server operating systems run from Windows Server 2016 through 2022, with Server 2025 added at version 25.2.
Read that as an architecture statement rather than a nitpick. Your job cost system was designed for a local network. Your job cost users are in trucks. That is the tension. Viewpoint Vista sits in a similar place, with a more modern deployment story but the same underlying assumption about where the data lives.
There are 3 honest ways out, and every DFW contractor we work with has picked one whether they realized it or not. Pick yours deliberately.
- Host the application properly, in a data center with real bandwidth behind it, and publish it to users as a session
- Keep it on-premises and accept that remote access is the exception rather than the pattern
- Move to a platform built cloud-first and pay the migration cost once, deliberately
The wrong answer is the fourth one, which is leaving a server in a closet at the main office and letting 40 people VPN into it while pretending that counts as managed cloud. That is not a hosting strategy. It is a hosting accident.
Layer 4, field capture and the bandwidth math nobody does
A jobsite does not need a fast connection. It needs one that tolerates a 40 minute outage without losing a day of work. Reliability wins. Those are different requirements and they buy different equipment.
Photos are the whole story. Run the arithmetic yourself. A 12 megapixel phone photo lands around 3 MB. At 120 photos a day per superintendent, 4 superintendents and 22 working days, you are moving roughly 32 GB a month in images before anyone annotates a single one. It adds up fast. That is a rounding error on a fiber circuit. It is a serious number on one shared LTE hotspot that 9 people also use at lunch.
So the design rule is sync, not stream. Capture locally, queue, upload on a schedule. Assume the drop. The Texas contractor we moved off a file server had exactly this problem in reverse, with field staff emailing attachments around a system that could not reach them.
One more thing on devices. A tablet that goes back in a truck at demobilization is a tablet nobody wipes. Enroll it or do not issue it. No exceptions.
Layer 5, the money layer, because your AP function is the product
The FBI’s Internet Crime Complaint Center logged 1,008,597 complaints in 2025 with $20.877 billion in reported losses, a 26 percent increase over 2024. Its annual report puts investment fraud first among loss categories, followed by business email compromise and tech support scams. Texas ranked 2nd in the country on both measures, with 97,912 complaints and $1,825,636,181 in reported losses. Second nationally. Only California was worse.
Construction’s exposure to the middle category is structural rather than accidental. Your accounts payable function processes payment applications from companies it has never met in person, using banking details supplied over email, on a schedule the subcontractor is desperate to keep. Every element of that is normal. Every element of it is also the exact scenario the fraud is written for.
The control that matters most costs nothing. When a vendor sends new banking instructions, call back on the number in the executed subcontract. Not the number in the email. Not the number in the signature block. The one in the contract.
Around that, 4 more that hold up under audit.
- Treat a banking change like a change order, with an approver who is not the person who received the request
- Turn on external sender warnings and lookalike domain protection across Microsoft 365
- Enforce multifactor authentication on every mailbox, including shared accounts payable inboxes and service accounts
- Log and retain mailbox rule changes, which is how most of these get discovered weeks too late
That last list is not only fraud prevention. It is increasingly what your carrier is asking about. Cyber insurance underwriting in 2026 turns heavily on multifactor authentication coverage and tested backups, and a contractor who cannot answer those questions cleanly pays for it in premium or gets declined outright. Working through the questionnaire honestly finds more gaps than most paid assessments do.

Layer 6, the 10 year problem
Here is the layer almost nobody budgets for. Texas Civil Practice and Remedies Code Section 16.009 gives a claimant 10 years after substantial completion to bring suit for damages against a person who constructs or repairs an improvement to real property. Ten years. A governmental entity gets 8. On a residence where the contractor provided a written warranty meeting the statute, the window drops to 6.
Now compare that clock to how your record is actually stored. An annual subscription. A laptop that gets reimaged when someone leaves. A photo library in an application whose export format nobody has ever tested. A project you finish in 2026 may need to be defensible in 2036, and 2036 is 3 platform migrations away. Think about that.
| What you are keeping | Why it matters | How long |
|---|---|---|
| Design and as-built record | Construction defect claims under Section 16.009 | 10 years after substantial completion, 8 on public work |
| Daily reports, photos, RFIs | Delay and disruption claims | The same clock |
| Pay applications, lien waivers, retainage | Payment and lien disputes | Per contract, normally shorter |
| Safety and training records | Regulator and insurer requests | Per regulation |
| Email between the parties | It explains everything above | The same clock, and by far the hardest |
Email is the one that catches people out. The project folder gets archived properly. The 4 years of email that explain the project folder walk out with the PM who took a job at another firm. It leaves quietly. If you are already planning backup and recovery in Dallas, extend the same thinking to retention, because they are not the same requirement and a 30 day backup satisfies neither.

Your contract already told you what your IT has to do
There is a document most general contractors have signed and almost none have forwarded to whoever runs their technology. AIA Document E203, the Building Information Modeling and Digital Data Exhibit, exists to establish the parties’ expectations for the use of digital data and BIM on a project and to set up a process for developing the protocols that govern the development, use, transmission and exchange of that data. Almost nobody reads it.
E203 does not contain the protocols itself. It commits you to writing them, into AIA Document G201 for digital data and G202 for the model. G201 is where the agreed rules for electronic project communications, submittals, contract documents and payment documents get recorded. Which means transmission method, file format, naming, model authorship and archive obligations are contract terms. Those are terms. Not preferences.
An honest correction. We treated the digital data exhibit as a design-side document for a long time and started our IT conversations at the software layer. We were wrong. The exhibit sits upstream of the software choice, and reading it first would have saved several clients a migration.
If your provider has never seen your E203 and G201 exhibits, then your digital data protocol was written by whoever happened to be in the room. Sometimes that works out. Usually it does not. It means you agreed to a delivery format your systems cannot produce.
What to fix first, in 90 days
None of this needs a rip and replace. It needs sequence. Sequence beats scale. Here is the order that has worked for the DFW contractors we support, and it deliberately puts the cheap high-value work first.
Days 1 to 30
- Inventory every external guest account across Microsoft 365 and your project platform, with the company and project each one maps to
- Confirm multifactor authentication is live on every mailbox, shared and service accounts included
- Write down which platform is the system of record for each active job, and who holds administrator rights
Days 31 to 60
- Switch on a monthly export from your project platform, then actually restore from one to prove it works
- Move vendor banking verification to a callback on the contract number, in writing, with a second approver
- Set cross-tenant access defaults in Entra and override them per partner organization
Days 61 to 90
- Map retention against Section 16.009 and choose an archive format that will still open in 2036
- Settle the accounting hosting question instead of deferring it another year
- Put the E203 and G201 exhibits from your last 3 contracts in front of whoever runs your IT
If you want the procurement side of this, our DFW IT buyers guide covers how to compare proposals, and the Dallas IT support cost breakdown covers what the numbers actually mean per ticket.
Questions DFW contractors ask before they change anything
Do we need Procore if we already run Sage
Yes, in most cases. They solve different problems. Sage 300 CRE is a job cost and accounting system. Procore is a project record and field workflow system. The value sits in the integration between the two, not in choosing one and forcing it to do both jobs badly.
How many guest accounts is too many
There is no number. What matters is whether every external account maps to a named person, a named company and an active project. If you cannot produce that mapping in an afternoon, the count is already too high, and the cleanup will take longer than the review would have.
Can a jobsite trailer run on cellular alone
Often yes, and on plenty of DFW sites it is the only realistic option. Bonded cellular behind a hardened firewall handles project management, field capture and voice without complaint. It struggles with a wired-network accounting system and with anyone syncing large model files.
What happens to our project data if we leave a platform
That depends entirely on the agreement you signed. Most cloud platforms allow a limited retrieval window after termination and then delete. Read your own termination clause before you need it, and keep exporting monthly regardless of what it promises.
Is cyber insurance worth it for a contractor our size
Usually, though the underwriting is where the real value shows up. Carriers now decline or reprice applications that lack multifactor authentication on email and remote access. Going through the questionnaire honestly surfaces gaps faster than most paid assessments, and it costs nothing.
Who should own this work internally
One person with authority over both operations and money. In a 40 to 200 person contractor that is usually the CFO or a VP of operations, not whoever is good with computers. The decisions here are contractual and financial before they are technical, and they need someone who can sign.
When is the right time to change any of this
Between jobs, or right at the start of one. Mid-project migrations of a live project record are how contractors lose RFI history. If the current job has 8 months left, spend them on identity and payment controls, which do not touch the record, and move platforms after closeout.
Want a second opinion on your stack before the next job starts
We support DFW contractors from a Dallas office at 5757 Alpha Rd, Suite 530, with a 120-day satisfaction guarantee and a year-one rate lock. 25+ years in Texas, 7x MSP 501 winner, SOC 2 Type 1 certified. Ask for a walkthrough of the 6 layers against your current environment.
Working across industrial and plant work as well as commercial building, the DFW manufacturing compliance guide covers the regulatory layer that sits alongside this one. For the statewide picture across all trades, start at the construction IT services overview. Start there.









