ALLMSP Blog

Autodesk Construction Cloud Access, SSO, and Offboarding

An Autodesk Construction Cloud access-governance guide for contractors that need controlled member onboarding, role and product reviews, identity integration, and complete offboarding.

Autodesk Construction Cloud members-roles-sso-offboarding support for a Georgia business

Autodesk Construction Cloud access is assembled from several layers. A person can exist in the hub, join one or more projects, receive a project member or project administrator level, gain product access, hold a subscription or trial, inherit tool settings from roles, and receive Docs folder permissions through a user, role, or company.

Autodesk roles make that model repeatable, but their behavior requires care. Current Autodesk help says a member with multiple roles receives the combined access, role changes do not automatically affect existing project assignments, and removing a role does not remove the product access associated with members who already have it.

Identity controls add another boundary. SSO changes how supported workforce identities authenticate, while directory sync can automate eligible user, group, product-assignment, and deprovisioning workflows. Neither replaces the construction handoff required to reassign open issues, RFIs, submittals, files, cost work, and other responsibilities before access is closed.

Key decisions at a glance

  • Treat hub membership, project membership, project access level, product access, subscription availability, tool permissions, and Docs folder permissions as separate controls.
  • Audit users with multiple Autodesk roles carefully because their effective access combines the roles assigned to them.
  • Do not assume that changing or deleting a hub role repairs existing project assignments or removes the product access a member already holds.
  • Use SSO and directory sync for eligible employee identity workflows while maintaining a controlled process for external construction collaborators and project-specific access.
  • Reassign open project work before removal, then close project, hub, subscription, directory, device, integration, and vendor-support access at the appropriate scopes.

Separate Hub, Project, Product, and Subscription Decisions

Autodesk Construction Cloud support workflow: Separate Hub, Project, Product, and Subscription Decisions
Autodesk Construction Cloud support workflow: Separate Hub, Project, Product, and Subscription Decisions

Create an access record that identifies the member, verified email, company, default role, project role, project access level, required products, subscription source, start date, sponsor, and planned end date. A person added to the hub without project access is different from a project member, and neither fact alone proves entitlement to use a licensed product.

Autodesk distinguishes product access from subscription assignment or an active trial. A project administrator can enable a product for a project member, but the person still needs an applicable subscription, trial, or eligible external subscription. Record both sides so support can diagnose an entitlement failure without repeatedly changing project permissions.

Reserve hub administrator, standards administrator, executive overview, and project administrator access for named duties. A broad title such as manager is not evidence that someone needs every administrative surface; document the exact settings, members, templates, projects, or analytics the person is responsible for.

  • Use individual Autodesk identities and verify each person's employer, sponsor, project, and requested duration.
  • Record project product access separately from the subscription or trial that permits use of that product.
  • Require explicit approval for hub, standards, executive, and project administrator access.
  • Review invited and not-invited records as well as active users so abandoned invitations do not become forgotten access paths.

Design Roles and Permissions Around Effective Access

Autodesk Construction Cloud support workflow: Design Roles and Permissions Around Effective Access
Autodesk Construction Cloud support workflow: Design Roles and Permissions Around Effective Access

Autodesk roles can set default project access and help assign product or tool permissions. Model roles on durable construction responsibilities such as project administrator, document controller, superintendent, design lead, owner representative, and subcontractor lead instead of cloning one broad external role across unlike participants.

A member with multiple roles receives the union of those roles' access. Autodesk also notes that changing a role affects members when they are added to new projects; an existing project member must have the role removed and reassigned for the change to apply there. Include existing-project remediation in every role-change plan.

Tool and folder permissions still need their own test. Docs access may be inherited through member, role, company, or administrator status, and Build tools have workflow-specific permission levels. Test the effective experience with a representative account, then preserve the role definition, assignment, exceptions, and result.

  • Map each role to required project actions, products, tools, and information areas before inviting members.
  • Review users with multiple roles for combined access that exceeds the person's current responsibilities.
  • When a role changes, identify existing projects that require removal and reassignment rather than assuming automatic propagation.
  • Use folder and tool reports plus persona testing to detect access retained through another role, company, or individual grant.

Coordinate SSO and Directory Sync With Construction Membership

Autodesk Construction Cloud support workflow: Coordinate SSO and Directory Sync With Construction Membership
Autodesk Construction Cloud support workflow: Coordinate SSO and Directory Sync With Construction Membership

Verify the organization's email domain and configure SSO according to Autodesk's current identity-provider guidance. Decide whether just-in-time provisioning is appropriate and test a small group before broad activation; SSO should prove the sign-in path, not silently assign construction projects or elevated project permissions.

Autodesk directory sync can push users and groups, user deactivation and reactivation, and supported profile or group updates into Autodesk Account. Its current SCIM guidance identifies Azure AD and Okta as supported identity providers, while an on-premises Directory Agent is a separate option subject to Autodesk eligibility and prerequisites.

Keep employee provisioning and external-collaborator onboarding distinct. An architect, owner, consultant, or subcontractor may use an identity outside the contractor's managed directory, so that person's hub, project, role, product, folder, and end-date approvals still require an accountable ACC process.

  • Verify domains and test SSO with a controlled group before changing the sign-in path for the wider workforce.
  • Document whether just-in-time provisioning, directory-synced groups, or manual invitation creates each Autodesk identity.
  • Assign product access and project membership through reviewed groups only where group behavior matches the construction role.
  • Maintain a manual lifecycle for outside collaborators whose identities are not governed by the contractor's directory.

Close Project Work Before Removing the Member

Choose the removal scope deliberately. Project removal ends membership in one project, while removing a member from the hub removes that person from all projects in the hub. Turning off Docs access in the project member profile also removes the member from the project and all project products, so review the impact before using that control as a shortcut.

Before removal, identify open issues, RFIs, submittals, forms, correspondence, meetings, reviews, files, assets, cost items, reports, and integration ownership associated with the person. Reassign or close each live responsibility, confirm the replacement can see the required records, and preserve the audit trail instead of deleting project evidence.

Complete the surrounding controls after the project handoff: hub membership, Autodesk Account product assignment, directory group or SCIM status, SSO access, managed device and browser sessions, shared mailboxes, integration credentials, and vendor-support portals. The offboarding record should state who approved each scope and when it was verified.

  • Inventory open responsibilities and confirm the replacement owner before changing project membership.
  • Use project removal for a finished assignment and hub removal only when all hub projects have been reviewed.
  • Revoke subscriptions, directory groups, devices, integration access, and support relationships that sit outside the ACC project.
  • Retain dated evidence of approvals and completed checks without copying passwords, tokens, or confidential project content.

Frequently Asked Questions

What access layers should an Autodesk Construction Cloud review include?

Review hub membership, project membership, project access level, product access, subscription or trial, assigned roles, tool-specific permissions, Docs folder permissions, identity-provider groups, integrations, and external support access.

Does inviting an ACC project member automatically provide a subscription?

No. Autodesk treats project product access and a subscription or active trial as separate requirements. A member needs both the project-side access and an eligible subscription path to use the product.

What happens when an ACC member has multiple roles?

Autodesk states that the person's access from those roles is combined. Review the effective union rather than evaluating each role in isolation, especially when one role grants administration or broad information access.

Do changes to an Autodesk role update existing project members automatically?

Not generally. Autodesk's role guidance says role changes affect members when they are added to a new project; for an existing project, remove and reassign the role to apply the revised settings, then retest access.

Does deleting an Autodesk role remove members' product access?

No. Autodesk specifically notes that removing a role does not remove product accesses already associated with the members. Product access must be reviewed and changed through its own control.

Can ACC folder access remain after an individual permission is removed?

Yes. Access may remain through a role, company, another individual grant, or project-administrator status. Inspect all effective permission paths and use a representative user test before declaring the access closed.

What is the difference between Autodesk SSO and directory sync?

SSO controls the supported sign-in path. Directory sync provisions and updates eligible users and groups and can automate product assignment and deprovisioning. Neither one alone assigns the correct project role or completes the construction-work handoff.

Should external subcontractors be provisioned through the contractor's directory sync?

Usually they need a separate controlled collaborator process because their identities are owned outside the contractor's directory. Verify the email, company, sponsor, project, role, products, folders, start date, and planned removal date.

Is removing someone from one ACC project the same as removing them from the hub?

No. Project removal addresses one project; Autodesk states that hub removal removes the member from every project in that hub. Review all current assignments and open work before choosing the wider scope.

How can ALLMSP help with Autodesk Construction Cloud access governance?

ALLMSP can inventory identities and projects, map roles and permissions, review product and subscription paths, coordinate SSO and directory controls, prepare collaborator intake, and document open-work reassignment and offboarding evidence.

Facebook
LinkedIn
WhatsApp
X
Email
Print
Threads
Reddit

Related Articles