Enterprise Scale #2

Permission Management at Scale: Clone, Export, Audit

How to clone permissions across ACC projects, bulk export to CSV, and audit user access — the features Autodesk should have built.

#acc #permissions #enterprise #tutorial #bulk-operations
Dmytro Yemelianov - Author
Dmytro Yemelianov
Autodesk Expert Elite • APS Developer

You have 200 projects in ACC. A new team member needs the same folder permissions as an existing team member — across all 200 projects. In the ACC web UI, that is 200 projects times roughly 10 clicks each. Two thousand clicks. Or one RAPS command.

This post covers three operations that ACC administrators need daily and ACC does not provide: cloning permissions between projects, exporting permissions to CSV for audit, and importing modified permissions back. Every command here is copy-paste ready.


The Permission Problem at Enterprise Scale

ACC has a two-layer permission model: project-level roles (Project Admin, Project Member) and folder-level permissions (View, Upload, Edit, Control). In theory, this is flexible. In practice, it breaks at scale because there is no way to:

  • Clone permissions from one project to another
  • Export all permissions for audit or compliance
  • Bulk-modify folder permissions across projects
  • Override inherited permissions on subfolders

That last one — inheritance override — is the #5 most-voted ACC feature request with 175 kudos, still marked “Future Consideration” after years.

For enterprise teams managing 100+ projects, permission management is a full-time job done entirely through mouse clicks.


Clone Permissions Between Projects

When you stand up a new project, it should match your template project’s permission structure. RAPS reads all folder permissions from a source project and applies them to the target.

Preview First with Dry-Run

Always preview before applying:

# See what would change without modifying anything
raps admin folder set-permissions "$ACCOUNT_ID" \
  --project "$NEW_PROJECT" \
  --clone-from "$TEMPLATE_PROJECT" \
  --dry-run
Dry-run output:
Cloning permissions from “Hospital Wing A” to “Hospital Wing B”
Folder mappings:
FolderUsersAction
Project Files12Would apply
Project Files/Plans8Would apply
Project Files/Specs6Would apply
Project Files/Bids3Would apply (2 users not in target)
Total: 29 permission assignments across 4 folders

Apply the Clone

# Clone folder permissions from a template project to a new project
raps admin folder set-permissions "$ACCOUNT_ID" \
  --project "$NEW_PROJECT" \
  --clone-from "$TEMPLATE_PROJECT"

What this does under the hood:

  • Reads all folder permissions from the source project
  • Maps users and roles to the target project
  • Applies permissions in bulk with rate-limit awareness
  • Reports any mismatches (users not in target project, role differences)
Cloning permissions…
29/29
Done in 8 seconds
Warning: 2 users from source not found in target project (skipped)

Export Permissions to CSV

Quarterly audits, compliance reporting, onboarding verification — they all need the same thing: a flat file showing who has access to what.

# Export all folder permissions for a project
raps admin folder set-permissions "$ACCOUNT_ID" \
  --project "$PROJECT_ID" \
  --export permissions.csv
permissions.csv:
project_id,project_name,folder_path,user_email,role,permission_level
b.abc123,Hospital Wing B,Project Files,alice@company.com,Project Admin,control
b.abc123,Hospital Wing B,Project Files,bob@contractor.com,Project Member,edit
b.abc123,Hospital Wing B,Project Files/Plans,alice@company.com,Project Admin,control
b.abc123,Hospital Wing B,Project Files/Plans,charlie@subcontractor.com,Project Member,view
b.abc123,Hospital Wing B,Project Files/Bids,alice@company.com,Project Admin,control

Use Cases for CSV Export

  • Quarterly permission audits — who has access to what, documented for compliance
  • Compliance reporting — produce evidence of access controls for ISO 27001, SOC 2, or owner requirements
  • Migration planning — export from BIM 360, review structure, then import to ACC
  • Onboarding verification — confirm that the new hire received the correct access across all relevant folders

Import Permissions from CSV

The real power is the round-trip: export, modify in Excel or Google Sheets, import back.

# Import permissions from a modified CSV
raps admin folder set-permissions "$ACCOUNT_ID" \
  --project "$PROJECT_ID" \
  --import updated-permissions.csv

The Spreadsheet Workflow

1. Export current permissions to CSV
2. Open in Excel / Google Sheets
3. Filter, sort, review
4. Modify permission_level column as needed
5. Remove rows for users who should lose access
6. Add rows for new users
7. Import the modified CSV back

This is how permission management should work: data in, data out, version-controlled, auditable.

Importing permissions from updated-permissions.csv…
Changes detected:
UserFolderChange
bob@contractor.comProject Filesedit -> view
dave@newpartner.comProject Filesadded (edit)
charlie@subcontractor.comProject Files/Bidsremoved
Applied 3 changes in 4 seconds

Bulk User Permission Audit

Beyond folder-level permissions, you often need to answer a broader question: what does a specific user have access to across all projects?

# See what a specific user has access to across all projects
raps project users list --hub-id "b.$ACCOUNT_ID" --format table \
  | grep "user@company.com"
# Export complete user-project matrix for the entire account
raps admin user list "$ACCOUNT_ID" --format csv > user-matrix.csv
user-matrix.csv (excerpt):
email,project_name,role,status
alice@company.com,Hospital Wing A,Project Admin,active
alice@company.com,Hospital Wing B,Project Admin,active
alice@company.com,Downtown Tower,Project Admin,active
bob@contractor.com,Hospital Wing A,Project Member,active
bob@contractor.com,Downtown Tower,Project Member,active

This gives you a flat, searchable matrix of every user across every project in your account. Filter it, pivot it, share it with stakeholders.


Real-World Scenarios

1

Scenario: New Hire Onboarding

A structural engineer joins the team and needs the same access as the existing structural lead.

Without RAPS

Open each project. Navigate to Members. Add user. Set role. Configure folder permissions for each folder. Repeat for 50 projects.

~45 minutes
With RAPS
raps admin folder set-permissions “$ACCOUNT” <br/> —project “$PROJECT” <br/> —clone-from “$TEMPLATE”
~30 seconds
2

Scenario: Employee Departure

A project manager leaves the company. Remove their access from every project immediately.

Without RAPS

Check every project manually. Open Members panel. Find user. Remove. Hope you did not miss one. No audit trail to confirm.

~2 hours (and you might miss some)
With RAPS
raps admin user remove “$ACCOUNT” <br/> “departing@company.com”
~45 seconds, all projects, guaranteed
3

Scenario: Annual Security Audit

The owner’s compliance team asks: “Who has access to what? Provide documentation.”

Without RAPS

Screenshot each project’s permission page. Compile into a spreadsheet manually. Pray nothing changed while you were documenting.

~1-2 days of tedious work
With RAPS
raps admin folder set-permissions “$ACCOUNT” <br/> —project “$PROJECT” —export audit.csv
raps admin user list “$ACCOUNT” —format csv > users.csv
~60 seconds, complete and accurate

Quick Reference

Permission Management Commands

raps admin folder set-permissions $ACCOUNT —project $P —clone-from $SRC
Clone all folder permissions from one project to another
raps admin folder set-permissions $ACCOUNT —project $P —clone-from $SRC —dry-run
Preview permission clone without applying changes
raps admin folder set-permissions $ACCOUNT —project $P —export file.csv
Export all folder permissions to CSV
raps admin folder set-permissions $ACCOUNT —project $P —import file.csv
Import permissions from a modified CSV
raps admin user list $ACCOUNT —format csv
Export complete user-project matrix
raps admin user remove $ACCOUNT “user@company.com”
Remove a user from all projects in the account

What Comes Next

This post covered permission operations for individual projects and users. But what happens when you have 1,700 projects and need to enforce a permission policy across all of them? That is a different problem — one that requires pipelines, not commands.

Next in the Enterprise Scale series: “1,700 Projects, Zero Automation” — what permission management looks like at true enterprise scale, and how to build pipelines that enforce access policies automatically.


Related: