To configure Smartsheet for the Next Generation API Data Protection, follow the instructions below.
Prerequisite
Before configuring Smartsheet for the Next Generation API Data Protection, review the prerequisites.
-
Smartsheet with Enterprise or Advanced Work Management plan.
In addition, the Event Reporting add-on is required for the above plans. -
A user account with the system admin role. This role is required to generate access token on the Smartsheet admin center.
Generate New API Access Token for Smartsheet
This section describes the steps to create a new API access token for Smartsheet. This access token will be required when you set up the Smartsheet instance on the Netskope tenant UI.
To set the maximum expiry period, see Smartsheet help center article.
-
Log in to app.smartsheet.com as a system admin.
-
On the bottom-left, click Account > Personal Settings….

-
On the Personal Settings window, click API Access, then Generate new access token.

-
Enter a name for the access token. Click OK.
-
Copy the access token.
The access token is only visible once, so be sure to copy it securely. The access token will be required when you set up the Smartsheet instance on the Netskope tenant.
Configure Netskope to Access your Smartsheet Account
To authorize Netskope to access your Smartsheet account, follow the steps below:
-
Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > CASB API.
-
Under Apps, select Smartsheet and click Setup CASB API Instance.
The Setup Instance window opens.
-
Under Administrator Email, enter the email address of the user who will receive an email notification when a policy violation or event triggers. This step is optional.
-
Under Plan ID, enter the plan ID of your Smartsheet account.
To find the plan ID, log in to admin.smartsheet.com as a system admin. Click the user icon on the top-right and copy the plan ID.

-
Under API Token, enter the API access token that was previously created (step 5).
-
Under Instance Name, enter a name of the SaaS app instance. This step is optional and if left blank, Netskope will determine the name of the app instance post grant.
-
Click Grant Access.
Refresh your browser, and you should see a green check icon next to the instance name.
Next, you can view the Next Generation API Data Protection Inventory page to get deep insights on various entities on your Smartsheet instance. For more information on the Inventory page, see Next Generation API Data Protection Inventory.
Next, you should configure a Next Generation API Data Protection policy. To do so, see Next Generation API Data Protection Policy Wizard.

