We have had instances of team members sharing entire Workspaces in lieu of Sheets to external parties. This poses a risk of non-company personnel viewing aspects of a Workspace that they shouldn't.
We typically grant all company team-members Admin rights due to the limitations of Editors (not being able to create new sheets for instance is very limiting); this opens up the possibility of Sharing Workspaces erroneously.
Security & Controls has a number of Publishing Functions nominated.
I should think that the inclusion of Workspace Publishing/Sharing is a good option for Company Admins to manage.
I completely agree with this. I want my users to be able to share the individual sheets - but they are erroneously sharing the entire workspace. We have clients who have very sensitive data that CANNOT be shared.... if I could set this permission at a group level - that would be IDEAL!
Smartsheet needs to have a power user that is in between admin and editor. We should be able to add users/groups to workspaces that gives them admin access to sheets they own and viewer level access to the workspace security settings, while still being able to move sheets in and out of the workspace. As mentioned in the original post, the security model for Smartsheet is very light. This should be one of the most robust parts of any application. We should also be able to set workspace permissions at the workspace level. Such as, a selection that says only groups or Account Admins can be added to workspace level vs individual users. Something similar to this should exist at the sheet level. As the admin, I create the project template with pre-determined formulas. A power user should be able to administer everything in the sheet except those columns/rows specifically locked by an admin in the sheet and summary areas.