Specialist Project Integration

Smartsheet Solutions

Smartsheet is an Information Management solution enabling collaborative working across teams, departments, and organisations. Smartsheet scales from project to enterprise level, and provides solutions to create team efficiency, effectiveness, and scale. SPI offers bespoke deployments to provide our clients with an implementation to provide real business value.

Features

  • DASHBOARDS: bespoke deployments to present relevant information to stakeholders.
  • FORMS: build and deploy to internal and external stakeholders.
  • MOBILE: supported on iOS and Android - phone and tablet.
  • PORTALS: keep team members informed with trusted information.
  • AUTOMATION: enables simple and powerful workflows to be created.
  • CONTENT COLLABORATION: automated alerts and reminders to maintain schedule.
  • CONNECTORS: pre-built integration between many popular software tools.
  • ADMIN CENTRE: central control and management of users/licensing.
  • MULTIPLE VIEWS: information in list, grid, calendar, gantt formats.
  • INTEGRATIONS: integrate with top productivity suites and messaging applications

Benefits

  • Robust, real-time view of KPIs, critical trends, summary reports.
  • Enables collection of error-free, consistent data from targeted stakeholders.
  • Full functionality and collaboration in a secure collaborative mobile environment.
  • Easy-to-create and maintain enabling information sharing and cooperation across teams.
  • Reduce time and costs through rework and unnecessary document control.
  • Content tasks in reports and dashboards for greater management oversight.
  • Enables improved collaboration with real-time visibility into critical business systems.
  • Efficient deployment with cost control and easily managed licence requirements.
  • Trusted data to be used appropriately by multiple roles.
  • Data shared across Office365, Adobe, DocuSign, Teams, Skype, Gmail, Outlook.

Pricing

£218 a licence a year

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at accounts@thinkspi.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 13

Service ID

6 5 8 1 2 4 5 0 5 8 1 1 5 2 9

Contact

Specialist Project Integration Deirdre O'Donovan
Telephone: 01908 671933
Email: accounts@thinkspi.co.uk

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
There are no constrains
System requirements
The only requirement is access to internet

User support

Email or online ticketing support
Email or online ticketing
Support response times
Within 1 working day,
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.1 AAA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
Yes, at an extra cost
Web chat support availability
9 to 5 (UK time), Monday to Friday
Web chat support accessibility standard
WCAG 2.1 AAA
Web chat accessibility testing
None as yet as too early in the site redesign
Onsite support
Yes, at extra cost
Support levels
SPI provide on-site process capture and mapping as part of the initial configuration of Smartsheet for the customer. We then provide ongoing support, the amount of hours per month to be agreed with the customer. Support is bespoke and is built around the customer requirements but typically involves an initial training session with super-users within the customer, and telephone and email support to these users. We are introducing web-chat support as part of our website redesign. SPI will also manage product support for the customer with the OEM (Original Equipment Manufacturer).
Support available to third parties
Yes

Onboarding and offboarding

Getting started
SPI can provide all: on site customised or generic training in addition to online e-learning and on line user documentation .
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Smartsheet supports exporting to the following formats:

Microsoft Excel
PDF
Image (PNG) (Gantt Chart Only)
Google Sheets
Microsoft Project (Gantt Chart Only)

The exported sheet or report will be saved to a location on the customers IT system.
End-of-contract process
Should the customer no longer wish to continue to pay for Smartsheet licences then all data must be transferred from the platform (as per the offboarding process). There is no cost unless the customer wishes SPI to carry out this work for them.

Using the service

Web browser interface
Yes
Supported browsers
  • Internet Explorer 11
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The Smartsheet mobile apps for iOS and Android, allows users to view and take action on your work while on the go.

Capabilities including:

Enter your location in a sheet or form field
Take a photo with your device and upload it directly to a sheet
Scan a barcode or QR code to search for or update sheet data
Access your forms quickly from Home or Recents

Some sheet and user configuration settings can only be accessed from the desktop browser version of Smartsheet, including:
Service interface
Yes
User support accessibility
WCAG 2.1 AAA
Description of service interface
The only element of the solution which requires a web interface is the reporting element through dashboards.
Accessibility standards
WCAG 2.1 AA or EN 301 549
Accessibility testing
N/A
API
Yes
What users can and can't do using the API
API's can be opened and available at extra cost. The API is a powerful tool for developers that helps ensure a combination of secure data management, automation through webhooks, and the ability to scale Smartsheet throughout your company.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Open platform. Open API, fully customisable

Scaling

Independence of resources
Smartsheet has a status page. In the last 90 days it was 99.97% up time

Analytics

Service usage metrics
Yes
Metrics types
Smartsheet has a full audit trail to a call level. Automation and workflows enable administrators to track all access, changes to sheets, etc. Should particular reporting be required SPI will be happy to engage with the client.
Reporting types
Reports on request

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Smartsheet

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Up to Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
Other locations
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least every 6 months
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
  • Physical access control, complying with another standard
  • Other
Other data at rest protection approach
All data durably stored with NIST approved ciphers, proven transport layer security (TLS) technology from the most trusted providers, AES 256 at-rest encryption, Amazon’s S3 service to store and serve uploaded files.
Data sanitisation process
Yes
Data sanitisation type
Deleted data can’t be directly accessed
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v.30, CAS (Sanitisation) or ISO/IEC 27001

Data importing and exporting

Data export approach
Easily exported to Excel (one click).
Data export formats
  • CSV
  • Other
Other data export formats
.xlc
Data import formats
  • CSV
  • Other
Other data import formats
.xls

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Data Center and Security Redundancy: Smartsheets have multi-site data redundancy, hosting at Equinix and AWS facilities, and facilities are ICPA SOC 1 examined, tested as well as ISO 27001 certified. Monitoring includes biometric scanning protocols, continuous surveillance, and 24 X 7 production environment management

Data Security: Third party data assessment, multi-layer data access permissions

Encryption: all data durably stored with NIST approved ciphers, proven transport layer security (TLS) technology from the most trusted providers, AES 256 at-rest encryption, Amazon’s S3 service to store and serve uploaded files.

Operational Management: production systems and data access is limited to authorized Smartsheets Technicians.
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
There is no guarantee on the level of availability. In the past year Smartsheet always had an uptime of more than 99%.
Approach to resilience
Information is available on request
Outage reporting
Clients can subscribe to an automatic alerts updates

Identity and authentication

User authentication needed
Yes
User authentication
  • 2-factor authentication
  • Username or password
Access restrictions in management interfaces and support channels
Securing systems, applications, and data begins with identity-based access controls. The identity and access management features that are built into Smartsheet help protect your organizational and personal information from unauthorized access, while making it available to legitimate users whenever and wherever they need it. Synchronize existing enterprise directory services with Smartsheet to provision and deprovision users, and share user metadata.
Access restriction testing frequency
At least every 6 months
Management access authentication
Other
Description of management access authentication
Because every user isn’t the same, we give you the ability to grant user-based permission levels to make sure the right people have the appropriate level of access to the data and capabilities within Smartsheet. For detailed information on how to manage user permissions in Smartsheet,

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
International Organization for Standardization.
ISO/IEC 27001 accreditation date
Ongoing
What the ISO/IEC 27001 doesn’t cover
These certification audits were performed by an accredited third-party auditor and reviewed by a certification body. These certifications demonstrate Smartsheet’s compliance to industry-leading security and privacy best practices and commitment to providing customers with the best enterprise-grade security and privacy features. All covered
ISO 28000:2007 certification
No
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber essentials plus
No
Other security certifications
Yes
Any other security certifications
  • CSA CAIQ Self-assessment provided to customers within Smartsheets security packet.
  • SOC 2 Type II and SOC 2 attestation

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Reporting structure:
Ultimate responsibility for SPI's Information Security rests with the Managing Director of SPI. This includes the business Information Risk Register and recommendations of appropriate risk management measures.
Information Security Employees and HR Manager are responsible for managing and implementing the policy and related procedures.
.
The Policy is reviewed by the Information Security Management Forum annually, or more often if appropriate.
Line Managers are responsible for ensuring that their permanent, temporary staff and contractors are aware of applicability in their role, personal responsibility for information security and how to access advice on information security matters

Information Security Awareness training is included in the staff and contractors induction process and Training Plan
Users are made aware of the procedures applicable to them and refreshed regularly.
An on-going awareness programme is established and maintained in order to ensure that staff and contractors awareness is refreshed and updated as necessary.

Adequacy of SPI's Security System si tested via regular audits. All breaches of this Policy and other information security incidents or suspected weaknesses are reported to the IT Manager immediately. These are logged and investigated to establish their cause and impacts with to avoid similar events.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
Smartsheet offers a number of configuration controls that allow you to set up plans and users in a way that best supports your business objectives. Globally configure user types to designate what individuals can and can’t do with your Smartsheet account, automatically add users to an enterprise account with automated user provisioning, or adjust account settings for features and working days.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
This information is available on request. An NDA has to be signed to receive this information.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
This information is available on request. We were advised by Smarthseets that an NDA has to be signed to receive this information. Full Security Statement from Smartsheets is available from: https://www.smartsheet.com/trust/security
Incident management type
Supplier-defined controls
Incident management approach
This information is available on request. We were advised by Smartsheets that an NDA has to be signed to receive this information. Full advice on security measures taken can be found on: https://www.smartsheet.com/trust/security

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)

Public sector networks

Connection to public sector networks
No

Social Value

Fighting climate change

Fighting climate change

Smartsheet is committed to continually improving energy consumption, waste, and recycling methods. Encourage recycling of paper, glass, hard plastic, aluminum, tin cans, and cardboard in all offices and partner with vendors to address more difficult-to-dispose-of items, such as batteries. Recycle all IT equipment through 3R Technology, a certified and trusted ITAD provider and electronics recycler. Works with Amazon Web Services (AWS) as our cloud services platform partner to further reduce our carbon footprint. Provides a stipend to employees and encourage alternative modes of transportation. Offices are located near public transportation hubs and provide end-of-trip amenities including bike storage, locker rooms, and showers. Building on established efforts, we are looking to positively contribute to environmental sustainability by eliminating single-use plastic cups and utensils from all Smartsheet offices, implementing composting programs, and putting policies and best practices in place that minimize carbon-intensive travel.
Covid-19 recovery

Covid-19 recovery

Smartsheet has disaster recovery and business continuity plans that cover maintaining business operations and delivery of services to our customers to meet our promised service delivery levels
Tackling economic inequality

Tackling economic inequality

Throughout the year, the Smartsheet Cares Committee organizes large-scale volunteer opportunities where employees are invited to make an impact in our local communities. In 2019, employees from every office location came together to repack nearly 300,000 meals for hungry families, support the clean-up and conservation of local rivers, and volunteer at nonprofit organizations that serve children, families, and people in vulnerable situations.
Equal opportunity

Equal opportunity

Smartsheet is an Equal Opportunity Employer committed to fostering an inclusive environment with the best employees. We provide employment opportunities without regard to any legally protected status in accordance with applicable laws in the US, UK, Germany, and Australia.
Wellbeing

Wellbeing

Smartsheet is supporting Early Childhood Education and runs Mental Heath Awareness Programmes as well as employees are encouraged to volunteer in their communities with paid time off for projects that align with their passions.

Pricing

Price
£218 a licence a year
Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Free licence for one month with access to create and share sheets, dashboards, and reports.

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at accounts@thinkspi.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.