IP Address Restrictions

IP Address Restrictions — Decide Which Networks Reach Your Workspace

Allowlist specific IP addresses and CIDR ranges so only approved networks can access SmartSuite—blocking untrusted connections, enforcing VPN policy, and adding a network layer to your access controls.

What Is IP Address Restrictions?

IP Address Restrictions is a SmartSuite capability that lets a Workspace Administrator allowlist specific IP addresses and CIDR ranges, so only connections from approved networks can access the workspace. It helps enterprise security and IT teams enforce network policy at the platform level—corporate offices and VPNs in, public Wi-Fi and unknown networks out. IP Address Restrictions are available on the Enterprise plan.

Network Allowlisting

Allowlist IP Addresses and CIDR Ranges in Minutes

From the Security tab in Workspace Administration, add individual IP addresses or entire CIDR ranges—an office egress IP, a VPN concentrator's block, a data center subnet. Entries save automatically as you add and remove them.

A built-in safeguard prevents the classic mistake: your own current IP must already be on the allowlist before the restriction can be enabled, so an administrator can't lock the organization out while configuring it.

Workspace-Wide Scope

Apply IP Address Restrictions to Every Access Path

The restriction covers the workspace, not just the login page: web access, the mobile app, and even Shared Views and Shared Forms are all subject to the allowlist. There is no side door through a public link.

Third-party integrations follow the same rule—allowlist your automation platform's or integration server's IPs explicitly so governed connections keep working while everything else stays blocked.

Platform Context
How GRC Teams Use

IP Address Restrictions

Identity controls verify who is connecting; IP Address Restrictions govern where they connect from. For regulated workspaces holding registers and evidence, the two together close the perimeter.

Compliance-Sensitive Workspace Lockdown

A workspace holding regulated records is restricted to office and VPN ranges, blocking logins from public Wi-Fi and unmanaged networks—and giving auditors a demonstrable network-level control.

Remote Audit Work on Approved Networks

Allowlist the corporate VPN's egress ranges so remote compliance and audit staff reach governed registers only through the tunnel. Distributed work continues—and the network-level control holds everywhere.

Controlled External Sharing

Because Shared Views and Shared Forms honor the allowlist, a compliance team can share dashboards internally knowing the links stop working outside approved networks.

Governed Integration Traffic

Allowlist your integration servers' IPs so automation traffic through the REST API keeps flowing after restrictions go live—every other origin is refused.

Works Better Together
Related Features

Identity controls verify who is connecting; IP Address Restrictions govern where they connect from. For regulated workspaces holding registers and evidence, the two together close the perimeter.

Features FAQ’s
Frequently Asked Questions About
IP Address Restrictions
What are IP Address Restrictions in SmartSuite?

IP Address Restrictions let a Workspace Administrator allowlist specific IP addresses and CIDR ranges so only connections from those networks can access the workspace. They are configured from the Security tab in Workspace Administration.

What formats does the allowlist accept?

Both individual IP addresses (such as 192.168.1.1) and CIDR ranges (such as 192.168.1.0/24). Changes save automatically as entries are added or removed.

Can an administrator accidentally lock everyone out?

SmartSuite guards against it: the administrator's own current IP address must already be on the allowlist before the restriction can be enabled, so you cannot switch it on from a network that would be blocked.

Do IP Address Restrictions apply to the mobile app and shared links?

Yes. The restriction applies workspace-wide—regular web access, the mobile app, and Shared Views and Shared Forms are all subject to the allowlist.

What about integrations and API traffic?

Third-party integrations must be explicitly allowlisted to keep working once IP restriction is enabled. Add your integration and automation servers' IPs to the list before turning the restriction on.

Which plans include IP Address Restrictions?

IP Address Restrictions are an Enterprise plan feature, per the SmartSuite pricing page.

Close Your Workspace to Untrusted Networks

Allowlist the networks you trust, enable the restriction, and every other route to your data stops at the perimeter.