Manage policy overrides in EPM

Allow specific managed plans to customize select policies while keeping others centrally enforced.

Who can use this?

Plans:

  • Enterprise

Permissions:

  • System Admin

Find out if this capability is included in Smartsheet Regions or Smartsheet Gov.

By default, managed plans inherit all EPM-governed policies from the main plan and can’t change them. If a managed plan has a business need to customize a specific policy, the main plan System Admin can grant that plan override permission for eligible policies.


Which policies can be overridden?

Eligible for override

  • Publishing controls
  • External Collaborator SSO (EC-SSO)
  • External Collaborator MFA (EC-MFA)
  • Safe sharing
  • Web content widget

Centrally enforced (no override)

  • Authentication
  • Domain management
  • UAP

Safe sharingEC-SSO, and EC-MFA share the same policy sheet. When you enable override for Safe sharing, all three are overridden simultaneously. You can’t grant an override for one without the others.


Configure policy overrides for a managed plan

  1. In Admin Center, navigate to Menu > Enterprise Plan Management.
  2. Select the kebab menu Configure policy overrides.

    Brandfolder Image
    Configure policy overrides
  3. For each eligible policy, find the managed plan you want to configure and toggle whether that managed plan can override it.

    Brandfolder Image
    Edit enterprise plan family
  4. Select Save.

The managed plan's System Admin can then modify those policies in their own Admin Center. Policies that managed plans can’t override display a Main plan policy indicator. The managed plan can view but not edit them.


Safe sharing with policy overrides

Even when override is enabled for safe sharing, the main plan's safe sharing list acts as a hard boundary:

  • Any domain or email not on the main plan's safe sharing list can’t be shared to by anyone in the EPM family, even if that domain is on a managed plan's own list and override is enabled.
  • Managed plan System Admins can view the main plan's safe sharing list in read-only mode.