Problem Statement Autodesk currently allows organizations to establish governed business processes through APIs, but users may still be able to perform the same actions directly within Autodesk applications or through AI-powered assistants, effectively bypassing those controls. This creates governance gaps and undermines the purpose of implementing controlled, API-driven workflows. Organizations need the ability to ensure that application features and AI agents adhere to the same governance model as their approved integrations and business processes. Requested Enhancement Provide administrators with granular controls to disable or restrict specific application features while retaining API access. These restrictions should also be enforced for AI-powered assistants and agents. Key capabilities should include: Ability to disable specific application actions while maintaining API functionality. Enforcement of the same restrictions for both end users and AI agents. Centralized administrative controls for governance, compliance, and workflow enforcement. Consistent behavior across all interfaces, roles, modules, and workflows. Ability to designate APIs as the exclusive method for executing specific business processes. Business Justification If an organization has intentionally implemented a governed business process through APIs, Autodesk should not allow users or AI assistants to circumvent those controls through native application functionality. The current model creates situations where automation and governance investments can be undermined by alternative interfaces that bypass established workflows, approvals, and compliance requirements. Autodesk should provide a governance framework that allows organizations to define where actions can occur and ensure those rules are enforced consistently throughout the platform. Expected Outcome Administrators can confidently define and enforce business processes knowing that: API integrations, application features, and AI assistants all follow the same governance rules. Restricted actions remain restricted regardless of user role, module, or interface. Compliance, approval workflows, and organizational standards cannot be bypassed through alternative access paths. Autodesk applications support API-first governance models for enterprise customers. This capability would significantly strengthen enterprise governance, security, compliance, and trust in Autodesk's AI, automation, and platform ecosystem by ensuring that all methods of interacting with Autodesk products adhere to the same administrative controls and business rules. Example 1: AI Agent Governance A comparable platform, CMiC, allows organizations to disable certain features while still exposing API functionality. This ensures that all activities flow through approved business processes. For example, users can ask the CMiC Agent to create a Business Partner. However, organizations can disable that capability if they require Business Partners to be created through a governed process. Autodesk should offer a similar governance model so that AI assistants cannot perform actions that administrators have intentionally restricted. Requested Behavior: Administrators can disable specific actions within Autodesk applications. AI assistants and agents inherit the same restrictions. Business processes enforced through APIs cannot be bypassed via conversational AI experiences. Example 2: Project Creation Permissions Project creation controls currently behave inconsistently based on role assignment. An organization may disable project creation at the hub level to prevent unauthorized project creation. However, users assigned the Standards Administrator role receive access to the Library and are also granted a Create Project button, effectively reintroducing project creation capabilities through another pathway. As a result, organizations may avoid assigning the Standards Administrator role—even when users legitimately need Library access—because it creates an unintended governance exception. Requested Behavior: Allow administrators to disable project creation universally, regardless of role. Ensure the "Create Project" action can be independently controlled from other permissions. Apply the restriction consistently across all roles, interfaces, and workflows. Prevent alternate permission pathways from re-enabling restricted actions. Example 3: Project Member Management Governance Organizations may establish a governed onboarding process for project members through APIs, ensuring proper approvals, role assignments, compliance checks, and system integrations occur before a user is added to a project. Today, project members can potentially be added through multiple interfaces, including: Project Admin Forma Design Even if an organization intends for all project membership changes to occur through an API-driven process, these alternative interfaces could allow users to bypass the established workflow. Requested Behavior: Allow administrators to disable manual project member creation and management while retaining API access. Enforce the restriction consistently across all locations where project members can be added or modified, including both Project Admin and Forma Design. Ensure AI-powered assistants adhere to the same restrictions. Support API-only governance models for project onboarding and access management. Business Value: This ensures that organizations with automated user provisioning, approval workflows, HR integrations, or identity management processes can maintain a single source of truth for project membership without the risk of users bypassing those processes through alternate Autodesk interfaces. Example 4: Mobile App Creates Additional Governance Bypass Autodesk has indicated that future enhancements may allow users to add project members directly through the mobile application. While this functionality may improve convenience, it creates another pathway that can bypass an organization's governed business process. Many organizations utilize API-driven workflows for project member onboarding to enforce approvals, role validation, compliance checks, identity management integrations, and audit requirements. If project members can be added directly through the mobile app, users could circumvent these established controls. This highlights a broader governance challenge: as Autodesk introduces new experiences and entry points (web applications, mobile applications, AI assistants, etc.), organizations have no guarantee that existing restrictions will be consistently enforced across those interfaces. Requested Behavior: Allow administrators to disable project member management regardless of where the feature is exposed. Ensure any restrictions applied to project member creation and management are enforced consistently across: Project Admin Forma Design Mobile Applications AI Assistants and Agents Future Autodesk interfaces Support API-only governance models where project membership changes must flow through approved integrations and business processes. Business Value: Organizations should not have to continuously monitor new Autodesk features to determine whether they create additional governance exceptions. Administrative controls should be defined once and enforced everywhere. This ensures that as Autodesk expands functionality across web, mobile, and AI experiences, enterprise governance, compliance, and security requirements remain intact.
Show More