Hello All!
We are encountering an unexpected behavior when provisioning projects through the Control Center in Smartsheet. Upon setting up a new project with the intended permission level of "Editor - can share" for the Project Manager (Mario), we've noticed that Control Center is unintentionally granting Admin privileges on individual assets within the project.
This behavior violates our principle of least privilege, which is concerning. In the example provided (referencing an image attached), Mario should only have Editor access to the asset in question, but they currently has Admin-level permissions, which is not intended.
My hypothesis is that this may stem from a hidden requirement within the Control Center blueprint—specifically, it might be related to WorkApp functionality where the owner of the WorkApp needs Admin privileges to add Dashboards or other functionalities. This seems to override our defined permission settings.
We are seeking guidance or insights from the Smartsheet community on how to prevent this unintended behavior. Is there a known workaround or setting within Control Center that can ensure that asset-level permissions align with the workspace-level permissions? Any advice would be greatly appreciated!
Thank you in advance for your expertise.