Roles and access

CrystalSlate shows the work your connected account can do.

Organization management, paid workflow access, and Smartsheet permission are separate checks. A paid license unlocks workflows; the connected Smartsheet role determines which ones appear.

How access is decided

  1. CrystalSlate verifies the signed-in account and active trial or subscription.
  2. You connect a Smartsheet account through Settings.
  3. CrystalSlate identifies that account as a regular user, Group Admin, or System Admin.
  4. Start and the main navigation omit every workflow that fails either check.

These browser rules improve clarity; server-side CrystalSlate checks and Smartsheet’s own API permissions remain authoritative.

CrystalSlate organization roles

  • Primary Owner: the one person who assigns management roles and can transfer ownership.
  • Workspace Admin: manages workspace configuration. This does not automatically grant billing visibility.
  • Account Manager: manages people and assigns available paid workflow licenses.
  • Billing Manager: is the only role that sees Billing and can open Stripe for payment, invoices, quantity, cancellation, or refund requests.

Account Managers and Billing Managers can sign in without a paid workflow license. They use only their authorized account sections and cannot enter Smartsheet workflows until a license is separately assigned.

Paid role matrix

Connected Smartsheet roleLaunch areas normally shownTypical work
Regular userAssets, SettingsInventory, sheet utilities, exports, formulas, references, and supported bulk work on accessible assets
Group AdminGroups, Assets, SettingsRegular-user work plus managed-group review and membership workflows
System AdminUsers, Groups, Assets, Activity, SettingsUser lifecycle, groups, assets, and organization-level CrystalSlate write history

Every licensed workflow user has the same per-user price. Management-only roles do not consume a license.

Using the tailored Start screen

Start is the default workspace. Before connection it provides one connection step. After connection it shows only accessible workflow cards, and each card opens the exact tool it names. You can still navigate freely to any available area afterward.

Trial users see only read-only Assets workflows and Settings. Paid users see the role-appropriate matrix above.

When a workflow is missing

  • Check whether the seven-day read-only trial is still active.
  • Open Settings and confirm which Smartsheet account is connected.
  • Confirm that account’s Smartsheet role and access to the target asset or managed group.
  • If the role is correct but the workflow remains absent, reconnect and send support the section name, browser, approximate time, and redacted screenshot. Never send a token.