Permission Management at Scale: Clone, Export, Audit
How to clone permissions across ACC projects, bulk export to CSV, and audit user access — the features Autodesk should have built.
You have 200 projects in ACC🏗️ACCAutodesk's construction management platform.View in glossary. A new team member needs the same folder permissions as an existing team member — across all 200 projects. In the ACC web UI, that is 200 projects times roughly 10 clicks each. Two thousand clicks. Or one RAPS🌼RAPSRust CLI for Autodesk Platform Services.View in glossary command▶️CommandInstruction executed by a CLI tool.View in glossary.
This post covers three operations that ACC administrators need daily and ACC does not provide: cloning permissions between projects, exporting permissions to CSV📊CSVTabular data format for spreadsheets.View in glossary for audit, and importing modified permissions back. Every command here is copy-paste ready.
The Permission Problem at Enterprise Scale
ACC has a two-layer permission model: project📁ProjectContainer for folders and files within a hub.View in glossary-level roles (Project Admin, Project Member) and folder-level permissions (View, Upload, Edit, Control). In theory, this is flexible. In practice, it breaks at scale because there is no way to:
- Clone permissions from one project to another
- Export all permissions for audit or compliance
- Bulk-modify folder permissions across projects
- Override inherited permissions on subfolders
That last one — inheritance override — is the #5 most-voted ACC feature request with 175 kudos, still marked “Future Consideration” after years.
For enterprise teams managing 100+ projects, permission management is a full-time job done entirely through mouse clicks.
Clone Permissions Between Projects
When you stand up a new project, it should match your template project’s permission structure. RAPS reads all folder permissions from a source project and applies them to the target.
Preview First with Dry-Run
Always preview before applying:
# See what would change without modifying anything
raps admin folder set-permissions "$ACCOUNT_ID" \
--project "$NEW_PROJECT" \
--clone-from "$TEMPLATE_PROJECT" \
--dry-run
| Folder | Users | Action |
|---|---|---|
| Project Files | 12 | Would apply |
| Project Files/Plans | 8 | Would apply |
| Project Files/Specs | 6 | Would apply |
| Project Files/Bids | 3 | Would apply (2 users not in target) |
Apply the Clone
# Clone folder permissions from a template project to a new project
raps admin folder set-permissions "$ACCOUNT_ID" \
--project "$NEW_PROJECT" \
--clone-from "$TEMPLATE_PROJECT"
What this does under the hood:
- Reads all folder permissions from the source project
- Maps users and roles to the target project
- Applies permissions in bulk with rate-limit awareness
- Reports any mismatches (users not in target project, role differences)
Export Permissions to CSV
Quarterly audits, compliance reporting, onboarding verification — they all need the same thing: a flat file showing who has access to what.
# Export all folder permissions for a project
raps admin folder set-permissions "$ACCOUNT_ID" \
--project "$PROJECT_ID" \
--export permissions.csv
project_id,project_name,folder_path,user_email,role,permission_level b.abc123,Hospital Wing B,Project Files,alice@company.com,Project Admin,control b.abc123,Hospital Wing B,Project Files,bob@contractor.com,Project Member,edit b.abc123,Hospital Wing B,Project Files/Plans,alice@company.com,Project Admin,control b.abc123,Hospital Wing B,Project Files/Plans,charlie@subcontractor.com,Project Member,view b.abc123,Hospital Wing B,Project Files/Bids,alice@company.com,Project Admin,control
Use Cases for CSV Export
- Quarterly permission audits — who has access to what, documented for compliance
- Compliance reporting — produce evidence of access controls for ISO 27001, SOC 2, or owner requirements
- Migration planning — export from BIM 360🔵BIM 360Legacy Autodesk construction platform (predecessor to ACC).View in glossary, review structure, then import to ACC
- Onboarding verification — confirm that the new hire received the correct access across all relevant folders
Import Permissions from CSV
The real power is the round-trip: export, modify in Excel or Google Sheets, import back.
# Import permissions from a modified CSV
raps admin folder set-permissions "$ACCOUNT_ID" \
--project "$PROJECT_ID" \
--import updated-permissions.csv
The Spreadsheet Workflow
1. Export current permissions to CSV
2. Open in Excel / Google Sheets
3. Filter, sort, review
4. Modify permission_level column as needed
5. Remove rows for users who should lose access
6. Add rows for new users
7. Import the modified CSV back
This is how permission management should work: data in, data out, version-controlled, auditable.
| User | Folder | Change |
|---|---|---|
| bob@contractor.com | Project Files | edit -> view |
| dave@newpartner.com | Project Files | added (edit) |
| charlie@subcontractor.com | Project Files/Bids | removed |
Bulk User Permission Audit
Beyond folder-level permissions, you often need to answer a broader question: what does a specific user have access to across all projects?
# See what a specific user has access to across all projects
raps project users list --hub-id "b.$ACCOUNT_ID" --format table \
| grep "user@company.com"
# Export complete user-project matrix for the entire account
raps admin user list "$ACCOUNT_ID" --format csv > user-matrix.csv
email,project_name,role,status alice@company.com,Hospital Wing A,Project Admin,active alice@company.com,Hospital Wing B,Project Admin,active alice@company.com,Downtown Tower,Project Admin,active bob@contractor.com,Hospital Wing A,Project Member,active bob@contractor.com,Downtown Tower,Project Member,active
This gives you a flat, searchable matrix of every user across every project in your account. Filter it, pivot it, share it with stakeholders.
Real-World Scenarios
Scenario: New Hire Onboarding
A structural engineer joins the team and needs the same access as the existing structural lead.
Open each project. Navigate to Members. Add user. Set role. Configure folder permissions for each folder. Repeat for 50 projects.
Scenario: Employee Departure
A project manager leaves the company. Remove their access from every project immediately.
Check every project manually. Open Members panel. Find user. Remove. Hope you did not miss one. No audit trail to confirm.
Scenario: Annual Security Audit
The owner’s compliance team asks: “Who has access to what? Provide documentation.”
Screenshot each project’s permission page. Compile into a spreadsheet manually. Pray nothing changed while you were documenting.
raps admin user list “$ACCOUNT” —format csv > users.csv
Quick Reference
Permission Management Commands
raps admin folder set-permissions $ACCOUNT —project $P —clone-from $SRCraps admin folder set-permissions $ACCOUNT —project $P —clone-from $SRC —dry-runraps admin folder set-permissions $ACCOUNT —project $P —export file.csvraps admin folder set-permissions $ACCOUNT —project $P —import file.csvraps admin user list $ACCOUNT —format csvraps admin user remove $ACCOUNT “user@company.com”What Comes Next
This post covered permission operations for individual projects and users. But what happens when you have 1,700 projects and need to enforce a permission policy across all of them? That is a different problem — one that requires pipelines, not commands.
Next in the Enterprise Scale series: “1,700 Projects, Zero Automation🤖AutomationReplacing manual processes with software.View in glossary” — what permission management looks like at true enterprise scale, and how to build pipelines that enforce access policies automatically.
Related: