Team collaborating on BIM project with secure cloud data and coordinated building design using Revit software.

How Do Architecture Firms Securely Collaborate on Large BIM and Revit Files?

July 23, 2026

The Best Way to Securely Collaborate on Large BIM and Revit Files

Most architecture firms should use a centralized BIM collaboration platform rather than sending Revit files by email, copying them through consumer file-sharing services, or opening central models across a traditional VPN. For firms using Autodesk Revit, the most practical approach is often Autodesk Construction Cloud with BIM Collaborate Pro, protected by individual user accounts, multi-factor authentication, controlled permissions, managed workstations, endpoint security, and tested backups.

A secure collaboration system must solve two problems at the same time: employees need fast, reliable access to current project information, and the firm must prevent unauthorized access, accidental deletion, ransomware, version conflicts, and data loss.

For a 25–50 person architecture firm, the right solution usually falls into one of three categories:

  • Cloud BIM collaboration: Best for distributed project teams, multiple offices, and firms collaborating with outside consultants.
  • Centralized on-premises storage: Best when most employees work from one office and the firm has fast local infrastructure.
  • Virtual desktop or hybrid infrastructure: Best when the firm wants applications and project data located close together while users work remotely.

The correct design depends on file size, employee location, consultant access, internet quality, cybersecurity requirements, recovery objectives, and the applications surrounding Revit.

The Five-Pillar BIM Collaboration Framework

1. Centralize Project Data

Architecture firms should establish one approved location for active project information. Employees should not have to decide whether the current file is on a server, laptop, personal cloud drive, email attachment, USB device, or consultant portal.

A centralized system should provide:

  • A clearly defined source of truth
  • Controlled access by project and role
  • Version history
  • Audit information
  • Reliable synchronization
  • Documented ownership
  • A process for archiving completed projects

For Revit cloud worksharing, Autodesk Construction Cloud and BIM Collaborate Pro can centralize cloud models and support collaboration across offices and remote locations. Other project information may remain in Microsoft 365, a document-management platform, or managed file storage, but employees should understand which system owns each type of information.

Avoid creating several overlapping repositories without clear rules. When project files are duplicated across a server, Teams, OneDrive, employee desktops, and outside sharing platforms, staff members can easily work from the wrong version.

2. Secure Every User Identity

The security of a cloud collaboration platform depends heavily on the user accounts that access it. A compromised password can give an attacker access to valuable drawings, models, specifications, contracts, and client communications.

Every architecture firm should require:

  • Unique accounts for every employee and consultant
  • Multi-factor authentication
  • No shared usernames or passwords
  • Role-based permissions
  • Prompt removal of access when a person leaves a project or company
  • Separate administrator accounts for privileged work
  • Regular review of guest and consultant access
  • Documented account-recovery procedures

Where supported, use single sign-on and centralized identity management so access can be governed consistently. 911 IT helps businesses protect identities, cloud accounts, email, and endpoints through its cybersecurity services.

3. Design for Performance, Not Just Access

A technically secure platform can still fail operationally if employees cannot open, synchronize, or navigate models efficiently. Performance should be measured from the user's workstation through every part of the system.

Review:

  • Internet upload and download capacity
  • Latency to the collaboration platform
  • Wired and wireless network performance
  • Firewall inspection capacity
  • Workstation processor, memory, graphics, and storage
  • Revit model size and health
  • Number and location of linked files
  • Local cache performance
  • Remote-access method
  • Security software configuration

Employees performing full-time Revit production should generally use wired Ethernet when available. Business-grade Wi-Fi can support many tasks, but wireless congestion, weak signal, and roaming problems can create inconsistent synchronization performance.

Architecture and engineering firms can work with 911 IT through its IT support for engineering firms to evaluate CAD and BIM workstations, networking, cloud collaboration, security, and data protection as one connected environment.

4. Protect Every Endpoint

Cloud collaboration does not eliminate workstation risk. An infected, stolen, or poorly managed computer can expose project data and user credentials even when the central platform is secure.

Every device accessing BIM information should have:

  • Endpoint detection and response
  • Full-disk encryption
  • Automated operating-system updates
  • Managed application updates
  • Controlled local administrator privileges
  • Secure remote support tools
  • Screen-lock policies
  • Device inventory and monitoring
  • A procedure for lost or stolen devices
  • Approved software and browser configurations

Personal computers should not access sensitive project data unless the firm has a formal bring-your-own-device policy and the technical controls to enforce it. For many firms, company-managed equipment is the safer and simpler standard.

5. Build Backup and Recovery Outside the Daily Workflow

Version history and cloud availability are useful, but they should not automatically be treated as a complete backup and disaster recovery strategy. Firms must determine what information can be restored, how far back recovery extends, who can perform the restoration, and how long recovery will take.

A complete recovery plan should address:

  • Active Revit and BIM models
  • Published drawings and deliverables
  • Microsoft 365 email and documents
  • Contracts, specifications, and project administration files
  • On-premises servers and storage
  • Workstation data that is not stored centrally
  • Application configurations and documentation
  • Ransomware affecting synchronized or connected systems

911 IT's business continuity services include secure backup, recovery planning, cloud-based continuity, and preparation for system failures and cyber incidents.

Cloud BIM Collaboration, VPN, or Virtual Desktop?

Approach Best For Main Advantages Main Risks or Limitations
Autodesk cloud collaboration Distributed teams, multiple offices, and external project partners Centralized cloud models, project-based access, version history, and collaboration without opening a central model over a traditional VPN Requires licensing, reliable internet, disciplined account management, and clear backup and archive procedures
On-premises file server Teams working primarily from one well-connected office Fast local access, direct infrastructure control, and predictable local performance Remote access can be difficult, infrastructure requires maintenance, and recovery depends on the firm's backup and continuity design
Traditional VPN to office storage Light remote access to ordinary files and administrative systems Extends access to office resources without moving every system to the cloud Latency and connection interruptions can make direct Revit worksharing risky and frustrating
Azure Virtual Desktop or hosted workstation Remote users who need applications and data located close together Centralized control, secure access, scalable computing options, and reduced transfer of project data to remote devices Ongoing cloud cost, design complexity, graphics requirements, internet dependency, and peripheral considerations
Hybrid model Firms with a mixture of local, remote, cloud, and specialized workloads Allows each workload to use the most appropriate platform Requires clear architecture, documentation, security standards, and ownership

Do not choose a platform only because it is labeled “cloud.” Determine where the Revit application runs, where the model is stored, how users connect, how consultants are invited, how access is removed, how data is backed up, and what happens during an outage.

Why Opening Revit Central Models Across a Traditional VPN Can Be Risky

A VPN can provide secure access to an office network, but it does not remove the effects of distance, internet latency, dropped connections, or limited bandwidth. Directly opening and synchronizing a workshared Revit central model across a poorly performing VPN can create slow operations, interrupted synchronization, and an increased chance of file problems.

A VPN may still be appropriate for:

  • Accessing ordinary office documents
  • Connecting to business applications
  • Remote administration
  • Occasional access to non-workshared files
  • Reaching an office-hosted virtual workstation

For full-time remote Revit production, consider cloud worksharing or a virtual desktop architecture that keeps the application and data close together.

How to Organize Revit, BIM, and Supporting Project Documents

A secure collaboration strategy should define where every category of project information belongs.

Information Type Recommended Governance Question
Active Revit cloud models Which Autodesk hub, account, project, and folder own the model?
Published drawings Where is the approved issue set stored, and who can replace it?
Consultant models How are links received, reviewed, updated, and archived?
Specifications and contracts Are permissions restricted to employees who require access?
Project communication Should decisions be retained in email, Teams, the project platform, or another system?
Reference files and content Who approves libraries, templates, families, and shared standards?
Completed projects What is the archive format, retention period, and restore procedure?

Document these decisions in a project-technology standard. Employees should not have to invent a new folder structure or sharing process for every project.

Secure Access for Consultants and External Partners

Outside collaboration is essential to architecture, but it expands the number of identities and organizations that can interact with project information.

Use a controlled external-access process:

  1. Confirm the business need: Identify the project, company, user, and information required.
  2. Invite a named individual: Avoid shared consultant accounts.
  3. Assign the minimum necessary permissions: Do not grant administrative or company-wide access for convenience.
  4. Require multi-factor authentication: Apply it to guests wherever the platform allows.
  5. Set an expiration or review date: External access should not remain indefinitely without review.
  6. Monitor activity: Retain logs and investigate unusual downloads or access.
  7. Remove access promptly: Close access when the person's role or project participation ends.

Project managers, BIM leaders, and IT personnel should agree on who has authority to invite external users. Allowing every employee to create unrestricted sharing links can lead to uncontrolled access.

Permission Levels Architecture Firms Should Define

A practical role-based model might include:

  • Platform administrator: Manages global settings, integrations, and high-level configuration.
  • Project administrator: Creates projects, manages membership, and controls project-level permissions.
  • BIM manager: Manages models, coordination, standards, and technical project workflows.
  • Project team member: Creates and modifies information within assigned projects.
  • Reviewer: Can view, comment, or approve without changing source content.
  • External consultant: Receives access only to the specific project information required.
  • Client or owner: Receives controlled access to approved deliverables or review areas.

Limit the number of global and project administrators. Administrative access should be assigned to a small, documented group and reviewed regularly.

A Seven-Step Secure BIM Collaboration Workflow

  1. Assess the project: Identify team size, offices, consultants, model size, applications, contractual requirements, and security expectations.
  2. Select the platform: Choose cloud collaboration, local infrastructure, virtual desktops, or a documented hybrid design.
  3. Define ownership: Identify the system of record for models, drawings, specifications, communication, and archives.
  4. Configure identity and permissions: Require individual accounts, multi-factor authentication, and least-privilege access.
  5. Standardize workstations and networks: Verify that devices, internet circuits, switches, wireless systems, and security tools support the workload.
  6. Test backup and recovery: Confirm that critical information can be restored within an acceptable timeframe.
  7. Train and review: Teach employees the approved workflow and review access, performance, and recovery at defined intervals.

Performance Targets to Establish Before Deployment

Do not rely only on general statements such as “the internet is fast” or “the cloud seems slow.” Define measurable targets and record a baseline.

Useful measurements include:

  • Internet upload and download speed during business hours
  • Latency and packet loss to key cloud services
  • Time required to open a representative model
  • Time required to synchronize with the central model
  • Frequency of failed or interrupted synchronization
  • Workstation memory utilization during typical work
  • Available local storage
  • Wireless signal quality in production areas
  • Number of support incidents related to model access
  • Time required to restore a representative project file

Measure with the same representative files and workflows before and after a change. This makes it easier to determine whether an infrastructure improvement produced a meaningful result.

Common BIM Collaboration Mistakes

Emailing Revit Models

Email creates uncontrolled copies, size limitations, unclear ownership, and version confusion. Use an approved project platform with permissions and version history.

Using Personal File-Sharing Accounts

Personal cloud accounts can place business information outside company control. The firm may be unable to remove access, preserve logs, enforce security, or recover information when an employee leaves.

Synchronizing Active Models Through Ordinary Desktop Sync Tools

General-purpose file synchronization tools are not automatically appropriate for active workshared Revit central models. Use a supported collaboration method designed for the workflow.

Giving Every User Administrative Rights

Excessive permissions increase the impact of compromised accounts, accidental changes, and unauthorized sharing. Grant only what each role requires.

Treating Cloud Storage as a Complete Backup

Synchronization, retention, recycling, version history, backup, and disaster recovery are different capabilities. Document what can be recovered and test the process.

Ignoring Consultant Offboarding

External users may retain access after their work ends unless someone removes it. Include consultant access in project closeout procedures.

Buying Faster Computers Without Testing the Network

A new workstation cannot correct internet latency, overloaded Wi-Fi, slow storage, unhealthy models, or an unsuitable remote-access design.

Allowing Multiple Sources of Truth

When the same project exists in several locations, employees can unknowingly work on outdated information. Assign one authoritative location to each information category.

Cybersecurity Controls for Architecture Collaboration

Architecture firms hold information that can be valuable to criminals, competitors, and other unauthorized parties. Project data may include floor plans, access details, infrastructure information, financial records, contracts, and personally identifiable information.

A layered security standard should include:

Security Layer Recommended Controls
Identity Multi-factor authentication, individual accounts, single sign-on, Conditional Access, and administrator separation
Endpoint Endpoint detection and response, encryption, patching, device management, and restricted administrator rights
Email Anti-phishing protection, attachment and link analysis, domain protection, and employee training
Network Managed firewalls, secure DNS, segmented networks, monitored remote access, and business-grade Wi-Fi
Data Role-based access, secure sharing, retention, backup, recovery testing, and controlled deletion
People Security awareness training, phishing simulations, incident reporting, and project-access reviews

Security should be designed into collaboration from the beginning. Adding controls after a client questionnaire, insurance renewal, or suspected breach is usually more disruptive and expensive.

Backup and Recovery Questions Every Firm Should Answer

  1. Which BIM and project systems are backed up?
  2. Which systems rely only on built-in version history or retention?
  3. How frequently is protected data copied?
  4. Is a backup isolated from production credentials and ransomware?
  5. How many historical versions are retained?
  6. Who receives alerts when a backup fails?
  7. How often is restoration tested?
  8. How long would it take to recover a critical active project?
  9. Can the firm recover after an administrator account is compromised?
  10. Can Microsoft 365 email, Teams, SharePoint, and OneDrive information be restored?
  11. How are completed projects archived?
  12. Who is authorized to request or approve a restoration?

The firm should define a recovery time objective for how quickly systems must return and a recovery point objective for how much recent work can be lost. These objectives guide the technology and budget required.

Example: A 40-Person Firm With Two Offices and Remote Employees

Consider a 40-person architecture firm with 25 employees in its main office, 10 employees in a second office, and 5 remote employees. The team uses Revit, Autodesk Construction Cloud, Microsoft 365, Bluebeam, and several external engineering consultants.

A practical collaboration design could include:

  • Autodesk cloud worksharing for active Revit models
  • Individual Autodesk and Microsoft identities protected by multi-factor authentication
  • Project-based permissions for employees and consultants
  • Managed Windows workstations with encryption and endpoint detection and response
  • Business-grade wired networks and wireless coverage in both offices
  • Internet circuits sized for simultaneous BIM, cloud, video, and business traffic
  • Microsoft 365 for approved communication and supporting documents
  • Documented backup and recovery procedures for project and business information
  • Quarterly review of external access and inactive accounts
  • A project closeout process that removes guests and creates a controlled archive

The firm should test representative models from each location before committing to the final design. A successful pilot should measure opening, synchronization, navigation, consultant access, security, and recovery.

When Autodesk Cloud Collaboration May Not Be the Best Choice

Cloud collaboration is valuable, but it is not automatically the correct answer for every project or firm.

Another approach may be appropriate when:

  • Nearly every employee works from one office
  • Internet service is unreliable or has limited capacity
  • A client contract restricts cloud storage
  • The project requires a specialized application or data location
  • Cloud licensing cannot be justified for the workflow
  • The firm already has modern local infrastructure with a strong recovery plan
  • A hosted virtual workstation provides a better experience for remote employees

Make the decision project by project and document exceptions. The objective is not to move everything to one platform; it is to give employees secure, reliable access to the correct information.

A BIM Collaboration Readiness Checklist

Category Readiness Question
Platform Is there one approved location for each type of active project information?
Identity Does every user have an individual account protected by multi-factor authentication?
Permissions Are users limited to the projects and functions required for their roles?
External access Are consultant invitations, reviews, expiration, and removal documented?
Workstations Are computers managed, encrypted, patched, and appropriately specified?
Network Have internet capacity, latency, Wi-Fi, switches, and firewalls been tested?
Model health Are models, links, warnings, families, and worksets actively managed?
Backup Can the firm explain exactly what is protected and how it would be restored?
Incident response Do employees know how to report suspicious access, phishing, or data loss?
Governance Are standards, ownership, retention, and project closeout documented?

Questions to Ask an IT Provider or BIM Consultant

  1. Which collaboration model is best for our employee locations and project types?
  2. Where will active Revit models and supporting documents be stored?
  3. How will consultant access be approved, reviewed, and removed?
  4. How will multi-factor authentication be enforced?
  5. Who will manage Autodesk and Microsoft identities?
  6. What network and internet performance does the design require?
  7. How will we measure Revit opening and synchronization performance?
  8. Which workstation specifications are recommended for each user role?
  9. How will project data be protected from ransomware?
  10. What is backed up independently of the production platform?
  11. How quickly can a deleted or damaged project be restored?
  12. How will completed projects be archived?
  13. What happens when internet service or a cloud platform is unavailable?
  14. Who provides support when an employee cannot access a model?
  15. Which responsibilities belong to the architecture firm, Autodesk, and the IT provider?

Frequently Asked Questions

Can Revit files be stored in OneDrive or SharePoint?

OneDrive and SharePoint can be appropriate for many ordinary documents, but they should not automatically be used to host active workshared Revit central models. Use a collaboration method supported for the specific Revit workflow and test it before deployment.

Is Autodesk Construction Cloud secure?

Cloud-platform security depends on both the provider and the customer's configuration. Architecture firms must still secure identities, require multi-factor authentication, manage permissions, protect endpoints, review external access, and maintain appropriate recovery procedures.

Should remote Revit users connect through a VPN?

A VPN can be useful for ordinary network access, but directly working with central Revit models over a high-latency connection can produce poor performance and reliability. Cloud worksharing or a virtual desktop may be more appropriate for full-time remote production.

How much internet speed does an architecture firm need?

There is no single number that fits every firm. Requirements depend on employee count, file activity, cloud applications, video meetings, voice traffic, model size, and the number of offices. Measure upload capacity, latency, packet loss, and performance during busy hours rather than relying only on an advertised download speed.

Does cloud collaboration replace backup?

Not necessarily. Built-in retention and version history may help recover some changes, but the firm should document whether critical information is independently protected and regularly test restoration.

How often should consultant access be reviewed?

Review access when a person's role changes, at project milestones, and during project closeout. Firms with many external users should also perform a recurring review of active guest accounts.

Should every architect have access to every project?

No. Provide access based on business need. Limiting permissions reduces accidental changes and the impact of a compromised account.

What causes slow Revit synchronization?

Possible causes include internet latency, packet loss, weak Wi-Fi, insufficient workstation resources, unhealthy models, complex links, overloaded local infrastructure, security-software configuration, or an unsuitable remote-access method.

Can architecture firms use virtual desktops for Revit?

Yes, provided the platform is designed with appropriate processors, graphics resources, storage performance, profile management, network connectivity, application licensing, and cost controls. Test the complete workflow with representative models before broad deployment.

How to Improve BIM Collaboration in the Next 30 Days

  1. List every location where active project files are currently stored.
  2. Identify shared, inactive, and unprotected employee or consultant accounts.
  3. Enable multi-factor authentication for cloud collaboration systems.
  4. Review permissions for the firm's five most active projects.
  5. Test Revit opening and synchronization from every office and remote-work method.
  6. Confirm that production workstations are encrypted, patched, and protected by managed endpoint security.
  7. Document what project information is backed up and perform one test restoration.
  8. Create an external-user offboarding checklist.
  9. Assign one owner for BIM platform governance and one owner for security administration.
  10. Build a roadmap for any network, workstation, cloud, or recovery gaps discovered.

911 IT helps architecture and engineering firms design secure collaboration environments that connect Autodesk workflows, Microsoft 365, networks, workstations, cybersecurity, and business continuity. Its cloud services include cloud storage, Microsoft 365, virtual desktops, and secure remote-access solutions, while its managed IT services provide ongoing monitoring, support, technology management, and strategic planning.

Schedule a discovery call to review your firm's BIM collaboration workflow, identify security and performance gaps, and create a practical technology plan.