Smart Admin STUDIO
Get started
← All posts

audit

The Easy Smartsheet Audit Checklist: the lightweight first pass for a new admin

Most advice about auditing a Smartsheet environment assumes you already have a Center of Excellence, a steering committee, and a quarter to spend. If you’re the person who just inherited the admin seat, that advice is useless. You need a first pass — something small enough to finish, honest enough to be worth reading, and specific enough that you can hand it to someone and say “here’s what we’re actually running.”

This is that first pass. Five simple questions. You can get through it without a governance program, without a policy document, and without asking anyone’s permission.

Do the easy version first, on purpose

The instinct is to design the complete audit before starting it — every dimension, every edge case, a scoring rubric. That audit never ships. The lightweight version does, and a rough baseline you finish beats a rigorous one you abandon at 40%.

Guiding principles:

  • Answer environment-wide, not sheet by sheet. If a question can only be answered by opening sheets one at a time, you’ll stop before you learn anything. Every question below is answerable from metadata — ownership, structure, activity — without reading a single cell.
  • Don’t decide anything yet. This pass produces a picture, not a cleanup plan. Deleting, reassigning, and consolidating are separate conversations, and they go much better once you have the picture.

The five questions

1. How many sheets are there, and who owns them?

Start here because it’s the question everyone asks and almost no one can answer. You want a count, and you want it broken down by owner (which leads to org chart mapping). What you’re looking for isn’t the total — it’s the shape of the distribution. A few owners holding a large share of the environment is the single most common finding in a first audit, and it’s the one with the most immediate consequences.

2. Where does ownership concentrate dangerously?

Now look at the top of that owner list and ask what happens if any of those people leave. Ownership concentration isn’t a problem in itself — it usually reflects someone who’s genuinely good at this. It becomes a problem when nobody else knows how the work is built. Note the top handful of owners and whether anyone else could pick up their sheets. That’s your institutional-knowledge risk, and you can write it down in ten minutes.

3. What hasn’t been touched in months?

Sort by last activity. In environments we’ve looked at, the large majority of sheets haven’t been touched in months — expect a big number here and don’t panic at it. Dormant doesn’t mean deletable; a quarterly process legitimately sits still for eleven weeks. What you’re building is the review pool: the set of sheets where someone should ask “is this still doing work, and if not, where should its data actually live?” Old data stranded in an unused sheet instead of properly archived somewhere is a retention gap, not just clutter.

4. Which sheets are actually complex?

Some sheets are lists. Others are applications — forms feeding them, automations firing off them, cross-sheet formulas holding them together, documents generating out of them. Those deserve the same support discipline as any other business application, and right now they probably have none. Flag them. Smart Admin Studio’s complex-sheet detection feature surfaces them by structural signals rather than by asking you to guess, which matters when the list is long.

5. Where might sensitive data be sitting?

Last, and the one people put off: which sheets look like they hold personal or sensitive information? You are not doing a compliance review in your first pass. You’re answering the narrower question of whether “we don’t know” is your current answer — because that’s the answer that becomes a problem the first time someone from risk or legal asks. Smart Admin Studio’s PII flagging narrows a whole environment down to the sheets and attachments worth a human look.

What to do with the result

Write it up in a page. Not a deck — a page, five headings, one paragraph each, and the actual numbers you found. Then share it with exactly the people who will have opinions about it.

The reason this works better than a bigger audit is that it changes the conversation from abstract to concrete. “We should govern Smartsheet better” gets nodded at and dropped. A page saying one person owns a quarter of the sheets, most of the environment is dormant, and nobody can say where PII lives — that gets a follow-up meeting.

Then run it again

The one thing to get right on the first pass is repeatability. Do it in a way you can redo in six months — same questions, same definitions — because the interesting information isn’t the snapshot, it’s the delta. Which direction is ownership concentration moving? Is the dormant share growing faster than the environment? A first audit you can’t repeat is a curiosity. One you can is the start of a governance practice, and it took you a week rather than a quarter.

Smartsheet’s native Admin Center reports will get you partway — Sheet Access and Event Reporting answer sharing and last-modified questions well. They weren’t built to answer ownership, purpose, and risk across a whole environment, which is the layer this checklist needs and the reason Smart Admin Studio exists.

Want the answers to all five questions without the spreadsheet work? Scan your environment today — no credit card, no sales call.


Smart Admin Studio is an independent product and is not affiliated with, endorsed by, or sponsored by Smartsheet Inc.

Stefan Quartemont

Co-Founder, Smart Admin Studio · President, QREW Tech

Stefan is Co-Founder of Smart Admin Studio and President of QREW Tech, which he founded in 2018 to advance the citizen-developer movement through no-code and low-code training, tooling, and consulting. He has spent years helping non-technical builders ship real business systems on platforms like Google AppSheet — and helping the organizations around them govern what gets built. He writes here about bringing visibility, ownership, and lifecycle discipline to sprawling low-code and Smartsheet environments without smothering the people doing the building.