Security

Security guidance for Smartsheet cleanup and review work.

CrystalSlate is built around controlled access, role-aware behavior, deliberate write actions, and careful support practices.

Security principles

1

Token access you control

Hosted CrystalSlate uses a verified CrystalSlate account and a Smartsheet personal API token that you enter in Settings. The token carries exactly the permissions of your Smartsheet account, nothing broader.

2

Review before change

The product emphasizes read-only review, exports, and owner confirmation before high-impact write workflows.

3

Activity records

CrystalSlate-initiated writes are designed to leave an activity record that can support operational review.

Smartsheet access

CrystalSlate's launch mode uses an email-and-password account with email verification. After signing in, you enter your own Smartsheet personal API token in Settings for the workspace session. There is no OAuth-style scoped authorization today; OAuth remains a future direction and should not be treated as available until explicitly announced.

  • Use a work account with the Smartsheet role needed for testing.
  • Only connect through the official CrystalSlate app at app.crystalslate.com.
  • Never email or paste Smartsheet tokens into support messages, screenshots, tickets, or documents.

What CrystalSlate stores or displays

CrystalSlate is a Smartsheet companion workspace. It may display Smartsheet metadata and review results needed for the workflow you run. Avoid using production-sensitive examples in screenshots unless they are redacted.

  • Inventory and workflow views depend on what the connected Smartsheet account can access.
  • Exports should be handled as customer data by your organization.
  • CrystalSlate activity records are meant to support accountability for write workflows.

Your responsibilities

  • Choose safe test targets before running writes.
  • Confirm business-owner approval before changing sharing, publishing, groups, automation, or webhooks.
  • Redact sensitive data before contacting support.
  • Rotate Smartsheet tokens if you suspect one was exposed.

Security reports

Email security reports to hello@crystalslate.com with “Security report” in the subject. Include the affected page or workflow, reproduction steps, browser, approximate time, and impact. Do not include secrets or exploit customer data to prove impact.