Skip to main content

CMiC Integration

Learn how to connect TrustLayer to CMiC, what data syncs between the two systems, and how to fix common setup issues.

Automatically sync your vendors, projects, and subcontracts from CMiC into TrustLayer — and push real-time compliance status back into CMiC.

Learn how to connect TrustLayer to CMiC, what data syncs between the two systems, and how to fix common setup issues.

TrustLayer's native CMiC integration keeps your compliance data in sync with CMiC. Once connected, TrustLayer imports your vendors, projects, and subcontracts from CMiC and writes compliance status back into CMiC automatically.


What gets synced

Data

Direction

Notes

Vendors (parties)

CMiC → TrustLayer

Imported from your CMiC Business Partner records

Contacts

CMiC → TrustLayer

BP primary contact + additional contacts from the syscontact endpoint (each needs a name + email)

Projects

CMiC → TrustLayer

Name, description, and start / end dates

Subcontracts

CMiC → TrustLayer

Associate a vendor to a project (assignments)

Compliance status

TrustLayer → CMiC

Written back as AP Insurance records so project teams see compliance in CMiC


Before you start

  • TrustLayer access — a TrustLayer user with Organization Admin / Owner permissions.

  • API access — TrustLayer connects as a registered CMiC partner; confirm your CMiC API licensing is in place. If you don't already have API access enabled, contact your CMiC Customer Success Manager to get a quote on turning it on — this can take time and may carry a cost, so start early.

  • A CMiC administrator to create the service account and set its security.

  • Your credentials: Client ID (tenant), plus the service-account User ID and Password.

  • One connection per CMiC company — each CMiC company connects as its own TrustLayer integration, with its own credentials and configuration. If you work across multiple companies, set up each one as a separate connection.


How do I connect CMiC to TrustLayer?

Complete these steps in order.

Step 1 — Create a dedicated CMiC API service account

We recommend a dedicated service account rather than a personal login — it keeps the connection stable if employees change roles or leave.

  • Ask your CMiC administrator to create a user account used exclusively by TrustLayer (e.g. TRUSTLAYER).

  • Grant it security to the data the integration uses:

    • Read: Business Partners, AP Vendors, PM Projects, Subcontracts, System Contacts (and company access).

    • Read / write: AP Insurance (where TrustLayer writes compliance status back).

  • Make sure the account's job / project security groups include every job you want visible to TrustLayer.

⚠️ Important: If the service account can't see a job in CMiC, TrustLayer can't either — missing job security is the most common cause of "my project isn't showing up."

Step 2 — Gather your connection details

  • Client ID (tenant) — shown as "Client ID" on your CMiC login screen

  • User ID — the service account from Step 1

  • Password — the service account password

  • Your company code is detected automatically during setup — you don't need to enter it.

Step 3 — Connect CMiC inside TrustLayer

  1. In TrustLayer, go to Integrations and select CMiC.

  2. Enter your CMiC credentials — Client ID, User ID, and Password.

  3. Authorize the connection. TrustLayer detects and stores your company code automatically.

Step 4 — Map your CMiC Projects and Business Partners

  • Manual mapping (recommended for initial setup) — for each CMiC Project or Business Partner you can link it to an existing TrustLayer Project / Party, create it as a new party / project (select Create as a new party), or mark it "Do not add to TrustLayer." When importing, TrustLayer matches by name, so an exact name match links to the existing record instead of creating a duplicate; when there's no match — or you want a fresh record — choose Create as a new party to bring it in as a brand-new TrustLayer party.

  • Automatic import — turn on the Automatically add new CMiC parties and Automatically add new CMiC projects toggles in TrustLayer to have new Business Partners and Projects imported automatically as they appear in CMiC. Subcontract commitments then automatically associate a vendor to a project (creating the assignment) — note this links vendors that are already in TrustLayer; a commitment on its own doesn't import a brand-new vendor.


How does syncing work?

  • Imports from CMiC (vendors, projects, subcontracts) run on a recurring schedule — 6× a day (00:00, 04:00, 08:00, 12:00, 16:00, 18:00 server time); not customer-configurable.

  • Compliance write-back to CMiC is event-driven — when a vendor's compliance changes in TrustLayer, the update is pushed to CMiC on that event rather than waiting for the next scheduled import.

  • CMiC doesn't offer real-time webhooks for inbound data, so changes made in CMiC flow to TrustLayer on each scheduled sync.

  • Need an update sooner? Resync a record now. Hover the integration link icon next to a linked Party or Project to see its last sync time and last-known status, then click Resync now to trigger a manual sync without waiting for the next scheduled run.

📝 Note: Changes made in CMiC won't appear in TrustLayer instantly — they sync at the next scheduled run, or when you trigger a manual Resync now on an individual record. A manual resync refreshes that one record and doesn't show live progress.


What data is imported from CMiC?

  • Business Partners (vendors / parties): legal name, website, address, and the primary contact (name + email, plus phone / fax when available). All Business Partners are imported regardless of their CMiC vendor status (active or inactive). There's no self-serve filter for this in the UI today — if you need to exclude certain vendors (for example, inactive ones), ask your implementation team or account manager to set up an import filter.

  • Contacts: the BP primary contact (above) plus additional contacts from CMiC's syscontact records — each needs a name + email to sync.

  • Projects: name, description, start / end dates.

  • Subcontracts: associate a vendor to a project. TrustLayer uses configurable active-commitment rules (status codes — default Pending / Posted — or executed date) to decide whether a subcontract creates or maintains the association.


Compliance write-back (TrustLayer → CMiC)

TrustLayer writes compliance into CMiC as AP Insurance records on the vendor. You choose the format:

  • Subjects (default) — one insurance record per compliance subject (e.g. General Liability, Auto, Workers' Comp).

  • Summary — one record representing the vendor's overall compliance status.

Each maps to a CMiC compliance type code — one code per Subject, or a single code mapped to the Summary status — and these codes must already exist in CMiC. You provide this mapping (which CMiC code corresponds to each subject, or the code for your summary status) to your implementation team or account manager, and TrustLayer sets up the compliance-code mappings on our end. Records are written at the vendor level (VEN) or, when tied to a commitment, the subcontract level (SC); you can choose all active commitments or just the primary one.

What TrustLayer writes on each AP Insurance record:

Field

Value

Vendor (BP) code + company code

Identifies the vendor and CMiC company

Compliance type

VEN (vendor) or SC (subcontract / commitment)

Coverage type code

The CMiC compliance code you mapped

Compliance flag

Y when compliant, N when not

Effective & expiration dates

Summary: earliest effective + latest expiration across the vendor's coverage. Subjects: that subject's own dates.

When a vendor falls out of compliance, TrustLayer updates the existing record and flips the compliance flag to N — it doesn't delete it. Records are removed from CMiC only when they no longer apply — for example, when a vendor is removed from a linked project, a compliance subject stops applying, or compliance tracking is turned off for the vendor. Removal happens on the next compliance sync. Note that simply unlinking a vendor doesn't delete its existing AP Insurance records in CMiC — those records stop updating but are left in place.


Configuration options

  • Project description sync — always keep in sync (default), or only on import.

  • Active commitment states — which subcontract status codes count as "active" (default Pending / Posted), or base it on an executed date.

  • Compliance code mappings — map TrustLayer's Summary / Subjects output to your CMiC compliance type codes.

  • Compliance sync level — whether compliance is written at the vendor / party level, the project (subcontract) level, or both (default). Configured with your TrustLayer team.

  • Compliance write-back on/off — enable or disable pushing compliance to CMiC.

  • Party type & compliance profile — set the default TrustLayer party type and compliance profile for imported vendors, with optional rules to auto-assign profiles based on vendor data.

  • Contact sync — control how vendor contacts are imported, including an optional contact-title filter.


What isn't supported?

  • Purchase orders — not supported by the CMiC API.


Troubleshooting common issues

  • Projects or business partners aren't showing up — the service account may lack access to the module or job (check job security groups), the item belongs to a different company code, or it was marked "Do not add to TrustLayer."

  • Vendors aren't associated to projects — the project isn't linked, or the subcontract isn't in an active state per your settings.

  • Compliance isn't appearing in CMiC — compliance code mappings aren't configured (or the CMiC code doesn't exist), the vendor / project isn't linked, or the change didn't actually alter compliance.

  • A linked Party or Project looks out of date — hover the integration link icon on the record to check its last sync time and status, then click Resync now to force an immediate sync instead of waiting for the next scheduled run.

  • Authentication errors after setup previously worked — the service-account password was rotated, or the account was disabled / locked in CMiC.

  • Setup finishes but no company is detected (shows "Not available") — TrustLayer couldn't read your CMiC company info during connect; confirm API licensing and that the service account has company access and can authenticate.

  • Syncs seem to pause after heavy activity — CMiC returned a rate limit (HTTP 429); TrustLayer automatically backs off and retries about an hour later.

  • Still stuck? Reach TrustLayer Support from the in-app messenger or email [email protected] — include what happened, steps to reproduce, expected vs. actual, and screenshots.

Did this answer your question?