IP Address Restrictions — Decide Which Networks Reach Your Workspace
Allowlist specific IP addresses and CIDR ranges so only approved networks can access SmartSuite—blocking untrusted connections, enforcing VPN policy, and adding a network layer to your access controls.
What Is IP Address Restrictions?
IP Address Restrictions is a SmartSuite capability that lets a Workspace Administrator allowlist specific IP addresses and CIDR ranges, so only connections from approved networks can access the workspace. It helps enterprise security and IT teams enforce network policy at the platform level—corporate offices and VPNs in, public Wi-Fi and unknown networks out. IP Address Restrictions are available on the Enterprise plan.
Network Allowlisting
Allowlist IP Addresses and CIDR Ranges in Minutes
From the Security tab in Workspace Administration, add individual IP addresses or entire CIDR ranges—an office egress IP, a VPN concentrator's block, a data center subnet. Entries save automatically as you add and remove them.
A built-in safeguard prevents the classic mistake: your own current IP must already be on the allowlist before the restriction can be enabled, so an administrator can't lock the organization out while configuring it.
Workspace-Wide Scope
Apply IP Address Restrictions to Every Access Path
The restriction covers the workspace, not just the login page: web access, the mobile app, and even Shared Views and Shared Forms are all subject to the allowlist. There is no side door through a public link.
Third-party integrations follow the same rule—allowlist your automation platform's or integration server's IPs explicitly so governed connections keep working while everything else stays blocked.
IP Address Restrictions
Identity controls verify who is connecting; IP Address Restrictions govern where they connect from. For regulated workspaces holding registers and evidence, the two together close the perimeter.
A workspace holding regulated records is restricted to office and VPN ranges, blocking logins from public Wi-Fi and unmanaged networks—and giving auditors a demonstrable network-level control.
Allowlist the corporate VPN's egress ranges so remote compliance and audit staff reach governed registers only through the tunnel. Distributed work continues—and the network-level control holds everywhere.
Because Shared Views and Shared Forms honor the allowlist, a compliance team can share dashboards internally knowing the links stop working outside approved networks.
Allowlist your integration servers' IPs so automation traffic through the REST API keeps flowing after restrictions go live—every other origin is refused.
Identity controls verify who is connecting; IP Address Restrictions govern where they connect from. For regulated workspaces holding registers and evidence, the two together close the perimeter.
IP Address Restrictions let a Workspace Administrator allowlist specific IP addresses and CIDR ranges so only connections from those networks can access the workspace. They are configured from the Security tab in Workspace Administration.
Both individual IP addresses (such as 192.168.1.1) and CIDR ranges (such as 192.168.1.0/24). Changes save automatically as entries are added or removed.
SmartSuite guards against it: the administrator's own current IP address must already be on the allowlist before the restriction can be enabled, so you cannot switch it on from a network that would be blocked.
Yes. The restriction applies workspace-wide—regular web access, the mobile app, and Shared Views and Shared Forms are all subject to the allowlist.
Third-party integrations must be explicitly allowlisted to keep working once IP restriction is enabled. Add your integration and automation servers' IPs to the list before turning the restriction on.
IP Address Restrictions are an Enterprise plan feature, per the SmartSuite pricing page.
Close Your Workspace to Untrusted Networks
Allowlist the networks you trust, enable the restriction, and every other route to your data stops at the perimeter.