Roles and access

CrystalSlate shows the work your connected account can do.

Commercial access and Smartsheet permission are separate checks. A paid seat unlocks the launch product; the connected Smartsheet role determines which workflows appear.

How access is decided

  1. CrystalSlate verifies the signed-in account and active trial or subscription.
  2. You connect a Smartsheet account through Settings.
  3. CrystalSlate identifies that account as a regular user, Group Admin, or System Admin.
  4. Start and the main navigation omit every workflow that fails either check.

These browser rules improve clarity; server-side CrystalSlate checks and Smartsheet’s own API permissions remain authoritative.

Paid role matrix

Connected Smartsheet roleLaunch areas normally shownTypical work
Regular userAssets, SettingsInventory, sheet utilities, exports, formulas, references, and supported bulk work on accessible assets
Group AdminGroups, Assets, SettingsRegular-user work plus managed-group review and membership workflows
System AdminUsers, Groups, Assets, Activity, SettingsUser lifecycle, groups, assets, and organization-level CrystalSlate write history

Every role pays the same per-authorized-user price. A role does not create a more expensive plan.

Using the tailored Start screen

Start is the default workspace. Before connection it provides one connection step. After connection it shows only accessible workflow cards, and each card opens the exact tool it names. You can still navigate freely to any available area afterward.

Trial users see only read-only Assets workflows and Settings. Paid users see the role-appropriate matrix above.

When a workflow is missing

  • Check whether the seven-day read-only trial is still active.
  • Open Settings and confirm which Smartsheet account is connected.
  • Confirm that account’s Smartsheet role and access to the target asset or managed group.
  • If the role is correct but the workflow remains absent, reconnect and send support the section name, browser, approximate time, and redacted screenshot. Never send a token.