Skip to main content

About Smartsheet

Iru reads users with their license types, sheets with their sharing permissions, workspaces with member access, and groups from the Smartsheet API. Authentication uses an API access token generated under AccountPersonal SettingsAPI Access. Requests target https://api.smartsheet.com/2.0; there is no subdomain to configure. Iru reads sharing and access configuration, not sheet contents. It collects who each sheet is shared with, not the cell data inside.

How It Works

Smartsheet authenticates with a Bearer token. Tokens are generated per user and carry that user’s effective access, with no separate per-endpoint scopes. Sheets and workspaces are shared individually, so a token from a user who is not a member of a workspace returns nothing for it. Iru cannot tell that apart from a workspace that has no sharing to report. Generate the token from a System Admin account for the most complete user and license inventory. Official references: API overview, Authentication and access tokens.

Prerequisites

  • An account that can generate an API access token. Prefer System Admin so user and license inventory is complete.
  • Access to every workspace you expect evidence from. Smartsheet access is per object.
  • Decide which workspaces are in scope. Excluded workspaces produce no evidence.

Connect Smartsheet to Iru

Complete this tab before you connect the source in Compliance.
1

Sign in to Smartsheet

Sign in to Smartsheet with the account whose access the integration should inherit, ideally a System Admin.
2

Open Personal Settings

Select Account (your avatar, lower left), then Personal Settings.
3

Open API Access

Select API Access.
4

Generate a new access token

Select Generate new access token.
5

Name and copy the token

Enter a name such as Iru Compliance so you can identify this token later. Copy the token value once while Smartsheet displays it. It cannot be retrieved afterward. If you lose it, generate a replacement.
Continue on the Iru Compliance tab.

Troubleshooting

Check pop-up blocker settings for the Iru site and try again.
Regenerate the token and paste the full string. Smartsheet does not let you view an existing token, so a partial copy cannot be checked after the fact.
The token’s owner is not shared into it. Regenerate the token from a System Admin account, or share the in-scope workspaces with the account you used.
A non-admin token returns only the users it can see. Use a System Admin token for complete user and license inventory.
This is expected. Iru collects sharing and access configuration, not cell data.

Sources Management

Browse and manage every Compliance source.

Getting Started With Compliance

Frameworks, actions, and Artifacts.

Iru Overview

How Endpoint, Compliance, and Identity fit together.

Artifacts Management

Upload, review, and organize evidence from sources and actions.