Overview
Smartsheet integration with Grip’s SSPM module allows Grip to assess critical security configurations in your Smartsheet Business and Enterprise.
As part of the integration, Grip provides configuration insights covering different security domains - including access control, data loss prevention, multi-factor authentication, privacy controls, and more.
This article covers the required permissions and flow to add a Smartsheet Tenant to Grip's SSPM module.
Adding Atlassian to Grip consists of two steps:
Get the “App client id” and “App secret” from Smartsheet.
Adding the Smartsheet tenant to Grip security posture management
Prerequisites
To connect Smartsheet tenants to Grip SSPM, you need Smartsheet admin permission to create an App client id and App secret.
Get the App client id & App secret
From the Smartsheet “Accounts” button, go to Developer Tools (1) >> Create New App” (2)
Note.
If you can’t see the “Developer Tools, “ you will need to register for a developer account here

Enter the required details in the “Create New App” window (3).
App Name – Mandatory
App description – Mandatory
App URL – Mandatory, Enter Grip’s URL
App contact / Support – Mandatory, Enter the app’s owner contact details.
App Redirect URL - Mandatory, Enter your Grip domain name after the:
“https://”
https://{client_domain_in_grip}.integrations.grip.security/oauth/callback (4)
(For example, from this URL, https://dev.dep.grip.security/, the {client_domain_in_grip} that you should take will be the dev.)
Click “Save”
Copy the “App client id” and “App secret” (5)

Now, go to the Grip app and create the connection
Connecting Smartsheet to Grip SaaS Security Posture Management.
From the Grip portal, go to “Posture” >> “Add Tenant”(1)
Click on “Smartsheet” (2)

Enter a “Display Name”
Paste the data copied from the previous steps into the Client ID and Client Secret fields.
Enter your Domain: it is the text between '
https://app.' and '/b/' in your URL. For example, if your URL is https://app.smartsheet.com/b/home, then your Domain is 'smartsheet.com'.Click on “Continue”
You will need to sign in with an admin account to your Smartsheet application

Sign in with your Smartsheet credentials (4)
Note
As mentioned in the message above, if you are not the Smartsheet administrator, copy the URL above and send it to the administrator to finish the registration.
Note that the URL will expire after 1 hour.
Allow the requested scopes (5)

Once connected, the Tenant will be added to the “Connected Tenants” on the “Posture” page. (you might need to refresh the page).

Click a policy to view its details and start fixing it if needed.
