-
Keeping the API token secure on a shared hosting website. Using PHP
I have a website on shared hosting. I know that I should keep api tokens out of public_html folders on said website. I would like to use a <domain>/config/config.php file to hold those api tokens for Smartsheets. This approach is working for another application that I integrate with from this website. However, when I put…
-
Advise on Workgroups and access for Groups
I have Workspaces that have sheets containing sensitive information. The Workspaces have Individual access to a few people. With in the Workspace, I created Dashboards, with Dynamic Views. Each is set with specific Groups to access specific information. The users in the groups can not see or access the Dashboards, unless I…
-
PIN and Touch ID for Smartsheet App
Hi It should be a standard expectation that all apps holding significant IP data and financial information have minimal protection in place. Imagine a bank app that didn't ask for your PIN or Touch ID? It should be self-evident that the Smartsheet app MUST have a security feature. Please make this an obvious high priority.…
-
Does Gov Smartsheet contain FIPS Moderate or higher rating for data and information stored?
My question is surrounding the FIPS for security rating of this application/software for government users. I would like to know if it is rated atleast FIPS Moderate?
-
Desktop App to use system default browser for Authentication
The Smartsheet desktop app currently uses an embedded browser (WebView/WebView2) for authentication and does not support using the system browser for OIDC sign-in. This is why it fails Conditional Access policies that require device compliance or trusted client conditions. Please add support for launching authentication in…
-
Security Question
Hi, I'm relatively new to SmartSheet so I was hoping I could get some input from the experts. I have a consulting business and use SmartSheet for various things from project plan mgmt to status reporting. I am trying to understand the security model better. I have reviewed different articles from the knowledge base but I'm…
-
Merged: Folder sharing while limiting workplace sharing
This discussion has been merged.
-
Deactivate and Reactivate API enhancements now generally available!
April 1st, 2025 SysAdmins using the Deactivate and Reactivate API can now leverage enhanced API functionality to align with the updated Smartsheet governance framework. These updates ensure that deactivation and reactivation of users adhere to plan-level security controls, reducing administrative complexity and improving…
-
Security Score, now generally available!
March 26th, 2025 The Security Score helps SysAdmins assess and strengthen their Smartsheet security posture by providing a data-driven score based on implemented security capabilities. Rooted in industry best practices, the score includes a categorized policy breakdown and an intuitive metric to track security strength and…
-
Setting Up Azure SSO
Hi, my company is on the Business subscription, and we are looking at setting up SSO through Azure. We've tried contacting the Smartsheets helpdesk, but aren't really getting anywhere. Is this something we are able to set up, and is anybody able to tell us how?
-
Preparing for a Password-Free Future in Smartsheet: Share Your Feedback!
As part of our ongoing commitment to security and authentication best practices, we are preparing to deprecate password-based login for Smartsheet accounts. Our goal is to transition to more secure authentication methods, such as email-based Time-Based One-Time Passwords (TOTP) and eventually full two-factor authentication…
-
System Admin or another role for Ability to View/Report on All Workspaces
Smartsheet needs a critical feature enhancement to align with industry-standard SaaS practices: grant System Administrators inherent visibility into and access to all workspaces within the organization. Currently, admins are severely limited in their ability to oversee and manage workspaces, relying entirely on individual…
-
WorkApp and Sheet Visibility for non-Owner/Admin
I would like the ability to prevent having a WorkApp or a sheet that I created from showing on other peoples folders and home screens when they are given permission to view. All of my WorkApps are to be accessed through a link on a 'master' dashboard. The main idea behind this is so I can have groups of people that will…
-
Major Security Risk: Please require users "Accept" invitation to shared Workspaces + Group Removal
Please upvote this recommendation if you agree with the urgency of a fix for this. Imagine the following scenario. in 5 minutes an anonymous Scammer creates a free Smartsheet trial account with a fake email address, and: They create a Workspace entitled "_Please Confirm Account and Remove this Workspace" They create a…
-
How to adjust Gmail Add on?
I have installed Smartsheet add on for Gmail and I would like to know how to set it up to show only certain columns for one of the sheets based on the access or on how to set it up as currently it shows all the columns when you select a sheet. Screen shots attached.
-
Prevent files with Social Security Numbers from being shared?
Is there no built-in way to prevent Smartsheet from allowing users from sharing data outside of Smartsheet automatically, if the data includes a Social Security number? (Enterprise Version) The only information I've found about this topic is…
-
Sheet Access Report Size Limitations
Hello Community Friends - Does anyone have a creative solution for managing the Sheet Access Report? Ours has exceeded the max row limitations of both Excel and Google Sheets. We need the ability to look up who is Sheet Owner and/or Admin of various sheets that we might not have access to, but we can no longer load all of…
-
Block request from outside the organization for requesting access to certain sheets
We have had an issue with users id themselves as executives and request access to financial sheets. Its happened a few times where they have gotten access. The emails are not from our organization they are usually fake gmail accounts or something similar. I want to be able to block these from even accessing these sheets.…
-
Smartsheet for Business Continuity Planning?
Hello, I'm a certified BC professional trying to connect with anyone who uses Smartsheet for their BC planning and execution. I will be attending Smartsheet Engage in a couple of weeks and would appreciate meeting up with anyone who is using the software in this manner to share ideas. I know there are templates available…
-
Large Corporation Log In Restrictions
For a large enterprise, how do you restrict who has access when someone leaves the company. If they log in using a password, will they be able to access after they are no longer a company if they don't get removed from the sharing? Looking for best practices or lessons learned. We have been growing quickly and do not have…