Use Enterprise Plan Manager (EPM) to establish security and governance policies for all plans across your organization’s validated domains.
USM Content
EPM v2 setup is self-service once your account team activates it on your main plan. Before setup begins, your account team has to work with you to scope and align on EPM, then submit an internal request to activate EPM v2 on the identified main plan.
EPM v2 is off by default. Contact your account team to begin the scoping and alignment process. Once activated, the Enterprise Plan Management page becomes available in your Admin Center, and you can proceed with the steps below.
Before you begin
Before your account team requests activation, confirm the following with all relevant System Admins. These items should be aligned on during the scoping process, not after EPM is enabled.
Authentication
Authentication is set on the main plan and applies to all managed plans automatically when they join the family. Misalignment can lock users out.
- Confirm the main plan's authentication method (ideally SAML/SSO) with managed plan System Admins before activation.
- Confirm that managed plan users' primary email addresses match their SSO email addresses before disabling email/password sign-in.
- If users have mismatched email addresses, managed plan System Admins may need to run a user merge after the change.
- Managed plans can't override authentication.
See Admin Center: Manage authentication options for more.
The main plan's authentication policy automatically overrides any managed plan's existing authentication settings when it joins the family. Confirm authentication alignment with managed plan System Admins before activation to avoid locking users out.
User Auto-Provisioning (UAP)
UAP automatically adds any user signing in with a validated domain to the main plan. Decide whether to enable it and how to configure it before activation.
Optionally, plan a user movement policy to automatically route users to the right managed plan based on their SAML attributes.
Learn more in Admin Center: Automatically add users with UAP.
Step 1: Validate your domains
- Go to Admin Center.
- Select the Menu icon in the upper-left corner and navigate to Domain Management.
Select Add Domain and follow the instructions to set up a public DNS record.
If you're unsure how, copy the instructions and send them to your DNS administrator.
- Select Verify.
Once you verify your domains, any plans opened under that domain appear on the Manage Plans screen. Learn more about domain management.
Step 2: Create your EPM family
In Admin Center homepage, select Go to Enterprise Plan Manager in the Create an Enterprise Plan Family card. Alternatively, open the Menu on the left and navigate to Enterprise Plan Management.
Brandfolder Image
Enter a name for your EPM family to continue the guided setup. Your plan is designated as the main plan.
Brandfolder Image
Step 3: Configure policy overrides (optional)
- Select Configure policy overrides in the bottom right.
For each eligible policy, toggle whether managed plans can override it.
Brandfolder Image
Select Create Enterprise plan family.
Your new EPM family displays.
If certain managed plans need to customize specific policies, you can grant them override permissions. See Manage policy overrides in EPM.
Step 4: Discover and invite managed plans
Select Discover plans.
Brandfolder Image
The Plan discovery page displays. It shows all Smartsheet plans that share your validated domains or whose System Admin email matches your validated domains. Non-Enterprise plans appear with upgrade guidance, as they can’t join until upgraded.
Brandfolder Image
Select Send invite next to any eligible Enterprise plan.
Brandfolder Image
- The invited plan's System Admin receives an email and an in-app Admin Center notification. They can accept or decline the invitation.
Once a managed plan accepts, it automatically inherits all EPM-governed policies from the main plan.
LCM Content
EPM creates a plan hierarchy with two levels:
- Main plan: This plan sets the policies and adds plans to the family.
- Managed plan: These plans inherit security and governance policies from the main plan.
Contact your Smartsheet Customer Success Manager or Technical Account Manager to designate your main plan for EPM. Once you set the main plan, follow the steps below.
Validate your domains
- Go to Admin Center.
- Select the Menu icon in the upper-left corner and navigate to Domain Management.
Select Add Domain and follow the instructions on the right panel. To verify your domains, you must set up a public DNS record.
If you're unsure how to do this, copy the instructions in the wizard to notify your public DNS admin and ask them to do it for you.
- After you've entered all your information, select Verify.
Once you verify your domains, any plans opened under that domain appear on the Manage Plans screen. Learn more about domain management.
Configure your authentication settings
This process ensures everyone in your organization uses the same sign-on method. Follow the instructions in the wizard; you might need to contact your Identity Provider (IdP) to obtain the information you need.
- It's recommended that you use single-sign-on (SSO) for authentication and deactivate email/password. Before you apply this best practice, confirm your team’s SSO readiness.
- Give your team a heads-up that you're implementing centralized plan management and inform everyone that they're being added to the EPM family.
- Ask each plan Admin to confirm whether people in their plan use SSO email addresses as their primary email addresses. The main plan Admin must leave the email/password on at the main plan level until all managed plan admins have confirmed their SSO readiness.
- If the managed plan admins don't respond, the main plan admin may need to contact them to discuss that individual managed plan admins might have to run a User Merge to update primary email addresses so they match the SSO email addresses of any remaining users.
Need more on configuring your authentication settings? Check out Admin Center: Manage authentication options.
Add managed plans to your family
- On the Manage Plans screen, select the plans you want to work with.
- Select add. This converts any independent plans to managed plans. They automatically inherit the authentication and domain validation settings you created in the main plan.
A message identifies any ineligible plans. Contact the plan owner to find out if they'd like to merge their plan into an existing managed plan or upgrade to an Enterprise plan.
Set a timeframe for enforcement (for example, activation of UAP) and communicate that to your team. After that, they can still use their plan, but they can't add new users.
Set User Auto-Provisioning (UAP) behavior
This setting applies to all users on your validated domains by default. Once you've added specific domains, you can toggle UAP on and off for them.
Non-Enterprise plans must upgrade or merge before you activate UAP. After you activate UAP, non-compliant plans can't add new users. Learn more about User Auto-Provisioning.
- From the Admin Center menu, navigate to Settings and select User Auto-Provisioning.
- From the Auto-Provisioning Behavior dropdown, select one of the following options:
- Off: The user doesn't receive automatic provisioning.
- On: Add as free user: The user gets automatically added as an unlicensed user.
- On: Add as licensed user: The user automatically receives a license.
Once you set up UAP, managed plans can add unlicensed users from the main plan or invite people who don't have Smartsheet accounts to join their plans. If you use SAML for authentication, you can also set a user movement policy. Learn how to set a user movement policy.
Inherited permissions
If you have multiple plans and one plan is the main plan under Enterprise Plan Manager, you can set publishing controls for reports, sheets, and dashboards in the main plan. All managed plans inherit those controls.
You can also set safe sharing controls in the same way. You can change these settings on the managed plan if you're an administrator on the main plan.