Cloud-Based Project Management Software: What to Look For
What “cloud-based” really means next to self-hosted, the criteria worth checking before you commit, the security questions CISA suggests asking, how AI assistants should get in, and how to move a team over without losing anything.
7 min read
Cloud-based project management software runs on the vendor’s servers, and your team uses it in a browser, a phone app and, more and more, through AI assistants. The vendor handles hosting, upgrades and backups; you handle who gets in and what they can do. Almost every tool you will shortlist is cloud-based, so that is not the decision. The decision is whether a tool passes the checks that matter once real work and real people are in it: access and roles, sign-in security, data export, integrations, AI assistant access, mobile and offline use, and how hard it is to leave.
This is a checklist, not a ranking. For the case for a smaller tool, read a simple project management tool for small teams; for side-by-side comparisons with specific products, see the compare pages.
What “cloud-based” means, and how it differs from self-hosted
NIST’s definition of cloud computing (opens in a new tab) describes on-demand network access to a shared pool of computing resources that can be provisioned and released with minimal management effort. Cloud project management tools are the software-as-a-service case of that: you rent the finished application, not servers. “Online project management software” and “web-based project management” usually mean the same thing.
- Cloud (SaaS): nothing to install or patch, new features arrive without you, and it works anywhere with a connection. In exchange, your data sits on the vendor’s infrastructure and you live with their release schedule.
- Self-hosted: you run the software on your own servers or cloud account. You control where the data lives and when upgrades happen, and you own the patching, backups, uptime and security of the box.
Self-hosting earns its cost when a contract or regulation dictates where data must live, or when the network cannot reach the internet at all. For most small teams, the time spent running a server is time not spent on the work the board tracks.
The criteria to check
Access and roles
Check who can do what, at what level. Can you give a client read-and-comment access to one project without showing them the rest? Can a role move work between columns without being able to rewrite it? Is a permission enforced on the server, or only hidden in the interface? The longer version of this question is in roles and permissions for humans and AI agents.
Sign-in security: SSO and MFA
CISA’s Secure by Demand guide (opens in a new tab), written for software buyers, asks whether a vendor supports standards-based single sign-on (SSO) at no additional cost, and whether multi-factor authentication or phishing-resistant options such as passkeys are on by default at no cost. It also asks SaaS providers to keep security logs, covering sign-ins, token creation, configuration changes and data access, for at least six months at no extra charge.
If a tool offers no SSO, turn on whatever second factor it does offer for every account. CISA’s guidance on multifactor authentication (opens in a new tab) says users who enable MFA are significantly less likely to get hacked, and calls phishing-resistant MFA the standard to strive for.
History and audit
Every change should be recorded with who made it, and that record should survive the task being edited again. It matters twice over once AI assistants can write to the board; see who changed what.
Data export
Export is the criterion people check last and need most. Ask what leaves: tasks, comments, attachments, history, custom fields, or only a flat list of titles. Ask in which formats, whether an API can pull everything, and what happens to your data when you cancel. Then test it on day one with real data, not in the sales call.
Integrations
Separate what is built in from what needs a paid connector service or code. For software teams, check the repository link, chat notifications and webhooks. Fewer integrations that work beat a directory of hundreds you will never turn on.
AI assistant access over MCP
AI assistants such as Claude, ChatGPT and Cursor reach tools through the Model Context Protocol. The MCP authorization specification (opens in a new tab) makes sign-in optional for implementations and, where a server offers it over HTTP, builds it on OAuth 2.1. So ask: can an assistant sign in through the browser rather than with a pasted key? Can its access be narrowed and revoked without touching yours? Are its changes labeled as the assistant’s? The full list is in MCP server for project management: what to look for.
Mobile and offline
Check what the phone app can actually do, not whether one exists: add a task with a photo, move it, comment. Then ask what happens without a signal. Some tools queue changes offline and sync later; many show an error. If your team works on job sites or on planes, test that before you buy.
Questions to ask a vendor
- Is SSO available on the plan we would buy, and is MFA on by default for every account?
- How long do you keep security and activity logs, and can we read them ourselves?
- Can we export everything, including comments, attachments and history, in an open format?
- What happens to our data, and for how long, after we cancel?
- Do you train models on our content?
- Can AI assistants connect over MCP, with sign-in, narrow access, revocation and attribution?
- Where is our data stored, and do you publish a vulnerability disclosure policy?
- What works in the phone app, and what works with no connection?
- Which features are only on higher plans? Get the answer by plan name, in writing.
How to migrate to cloud project management software
- Inventory what you have: open work, the few closed items people still look up, and every integration and automation that writes to the old tool.
- Archive, do not move, the rest. Most backlogs are half dead; a migration is the cheapest moment to let go.
- Map the old structure onto the new: statuses to columns, labels to categories, people to roles. Write the mapping down.
- Export from the old tool and import into the new, then spot-check twenty items against the original.
- Move one team or project first, for a week or two, before everyone.
- Reconnect integrations and AI assistants to the new tool, then revoke every token that pointed at the old one.
- Keep a dated full export of the old tool somewhere safe, and set the old tool to read-only rather than deleting it on day one.
Long-lived reference material, such as setup guides and runbooks, usually belongs in your repository rather than in task notes; technical documentation covers where each kind goes.
Where fenbs fits, and where it does not
fenbs is a hosted board you use in a browser, on the phone app, or through an AI assistant over MCP at https://fenbs.ai/api/mcp. Assistants sign in through the browser with OAuth, or with a token issued by hand under Settings that has a name, scopes and an optional expiry; revoking either ends it, and your own sign-in is untouched. Roles are defined per company, with Client and Reporter offered as suggested roles, and permissions are enforced on the server for people and assistants alike. History records every change with who made it, including “Claude via” the person it works for.
For migration, Add many takes a pasted list or a Markdown checklist and previews it before creating tasks. For leaving, Copy as Markdown copies the whole board, lane by lane, and the Decisions and rules page downloads as CSV.
What it lacks matters just as much. fenbs has no sprints, due dates, WIP limits, swimlanes or epics, and no assignee you can set on a task. Nobody outside a board’s members can see it; sharing means adding someone with a role. There is no SSO or two-factor sign-in, and no offline mode. If your checklist needs any of those, choose a tool that has them.
Related
How assistants sign in: MCP OAuth, explained. Giving one access safely: how to give an AI agent access to your project board. Specific tools compared: fenbs vs Jira, fenbs vs Trello and fenbs vs Asana.