Shared project platforms such as Autodesk Construction Cloud bring designers, builders, and owners onto the same set of documents and models. That shared space is the point, but it is also a security and coordination challenge. If permissions are loose, a project can accumulate outside users who have far more access than they need, long after their work is finished.
This post offers general access-control practices for shared construction platforms. Specific menu names and options change over time, so use them as a checklist and confirm details in your platform's current administration guide.
Start with the project structure
Before inviting anyone, decide how the project will be organized. Clear structure makes secure permissions possible.
- Create a folder hierarchy that separates content by purpose, such as design, contractor submittals, owner records, financials, and closeout.
- Keep drawings under review distinct from published or issued sets.
- Separate sensitive material, such as pricing or contract documents, into folders with narrower access.
If everything lives in one open folder, you cannot grant access to one team without exposing the rest.
Define roles, not individuals
Rather than customizing permissions for each person, define a small set of roles that reflect real responsibilities. A typical set might include:
- Project administrator: a few trusted people who manage members and settings.
- Design team member: access to design folders and review workflows.
- Contractor or subcontractor: access to their trade packages and submittals.
- Owner representative: read access to relevant records and approvals.
- View-only guest: limited, time-bound access.
Assign people to roles, and use company-level or group-based permissions where the platform allows, so you can add or remove people efficiently.
Limit administrators
Administrator rights allow users to add members, change permissions, and alter settings. Limit them to a small number and require multi-factor authentication for each administrator. Review the administrator list at least every quarter and at project milestones.
Require strong sign-in
Shared platforms often rely on each participant's own identity system. You may not control how an outside company manages accounts, but you can set expectations:
- Require individual named accounts, never shared logins.
- Ask outside firms to enable multi-factor authentication.
- Where your organization uses single sign-on, enforce it for your own employees.
- Remove accounts for people who have left the engagement.
Manage guests and external parties
External users tend to be the largest source of stale access. Control them with a few habits:
- Invite external users only through approved administrators.
- Grant access to specific folders and roles, not the entire project.
- Set an end date, linked to the person's scope of work.
- Review the external-user list at each phase of the project.
- Disable accounts that no one can justify.
Control downloads and sharing
Find out what the platform allows: whether users can download entire sets, create shared links, or export model data. Where the project is sensitive, restrict bulk download and public links for users who do not need them. Even where you cannot block downloads, understand which users have the capability.
Use logs and notifications
Most platforms record activity such as downloads, permission changes, and invitations. Someone on the team should know where to find these records and look at them periodically, especially after unusual events: a large export, a new administrator, or a burst of invitations. If the platform offers notifications for administrative changes, enable them.
Plan for closeout
When the project ends, the access picture should shrink quickly.
- Convert members to read-only or remove them according to contract.
- Disable external accounts no longer needed.
- Export and archive records as required by the contract.
- Document what was archived and where.
- Revoke shared links and integrations.
Review integrations
Connected applications can read and write project data. Review which integrations are authorized, who approved them, and whether they remain needed. Remove those that are not.
Document your approach
Write a short project access plan listing roles, who approves them, how long outside access lasts, and who reviews it. Include it in the project kickoff.
How Ironfield Cyber helps
Ironfield Cyber helps construction firms review permissions across project platforms, set up role-based access, and run periodic access reviews. If your last project ended with a long list of leftover users, we can help you prevent that next time.