How access is decided
- CrystalSlate verifies the signed-in account and active trial or subscription.
- You connect a Smartsheet account through Settings.
- CrystalSlate identifies that account as a regular user, Group Admin, or System Admin.
- Start and the main navigation omit every workflow that fails either check.
These browser rules improve clarity; server-side CrystalSlate checks and Smartsheet’s own API permissions remain authoritative.
CrystalSlate organization roles
- Primary Owner: the one person who assigns management roles and can transfer ownership.
- Workspace Admin: manages workspace configuration. This does not automatically grant billing visibility.
- Account Manager: manages people and assigns available paid workflow licenses.
- Billing Manager: is the only role that sees Billing and can open Stripe for payment, invoices, quantity, cancellation, or refund requests.
Account Managers and Billing Managers can sign in without a paid workflow license. They use only their authorized account sections and cannot enter Smartsheet workflows until a license is separately assigned.
Paid role matrix
| Connected Smartsheet role | Launch areas normally shown | Typical work |
| Regular user | Assets, Settings | Inventory, sheet utilities, exports, formulas, references, and supported bulk work on accessible assets |
| Group Admin | Groups, Assets, Settings | Regular-user work plus managed-group review and membership workflows |
| System Admin | Users, Groups, Assets, Activity, Settings | User lifecycle, groups, assets, and organization-level CrystalSlate write history |
Every licensed workflow user has the same per-user price. Management-only roles do not consume a license.
Using the tailored Start screen
Start is the default workspace. Before connection it provides one connection step. After connection it shows only accessible workflow cards, and each card opens the exact tool it names. You can still navigate freely to any available area afterward.
Trial users see only read-only Assets workflows and Settings. Paid users see the role-appropriate matrix above.
When a workflow is missing
- Check whether the seven-day read-only trial is still active.
- Open Settings and confirm which Smartsheet account is connected.
- Confirm that account’s Smartsheet role and access to the target asset or managed group.
- If the role is correct but the workflow remains absent, reconnect and send support the section name, browser, approximate time, and redacted screenshot. Never send a token.