Workspace Secrets — Store AI Provider Keys Once, Govern Them Everywhere
Keep OpenAI, Anthropic, and other AI provider credentials in the AI Control Center—entered once by an administrator, scoped to the Solutions and features that need them, and never re-typed or exposed at the point of use.
What Is Workspace Secrets?
Workspace Secrets is SmartSuite's central, admin-controlled storage for third-party AI provider credentials, delivered through the AI Control Center—the home for every AI connection in your Workspace. Workspace Administrators enter an API key once for providers such as OpenAI, Anthropic, Google Gemini, Amazon Bedrock, Azure OpenAI, Perplexity AI, IBM watsonx, and xAI, then reuse that connection across AI features without re-entering credentials. It helps IT and security teams keep keys out of individual configurations—centralizing rotation, scoping, and shutdown in the AI Center.
Central Storage
Enter Each AI Provider Key Once in the AI Control Center
All of a Workspace's AI connections live in one central place, restricted to Workspace Administrators. Setting one up takes a single pass: pick the provider and model, paste in the API key, then name and describe the connection so its purpose is clear to every admin who reviews it later.
Supported providers span the major LLM ecosystem—OpenAI, Anthropic, Google Gemini, Amazon Bedrock, Azure OpenAI, Perplexity AI, IBM watsonx, and xAI—so bring-your-own-model strategies run through one governed door.
Scoped Connections
Scope Every Connection to the Solutions and Features That Need It
Each stored connection carries its own boundaries: make it available across all Solutions or restrict it to specific ones, and enable or disable individual AI features per connection. A premium model can serve one sensitive Solution while a general-purpose connection covers everything else.
Cost control and data governance ride on the same setting—admins decide exactly where each provider, model, and key may be used.
Point-of-Use Protection
Keep Keys Invisible Where AI Features Consume Them
Downstream consumers—AI Workflow Agent and AI Field Agent automation actions—select from a dropdown of only the connections active for that Solution and feature. The underlying key is never re-entered, pasted into a builder, or exposed at the point of use.
When a key must be rotated or a feature shut down, admins change it once centrally—every workflow that uses the connection follows, with nothing to hunt down.
Workspace Secrets
AI credentials are secrets with real spend and real data exposure behind them. Workspace Secrets keeps the keys behind AI-assisted risk, compliance, and audit workflows governed centrally--while teams keep building freely.
Scope an enterprise-grade model connection to the risk and compliance Solutions alone, so AI drafting on sensitive registers runs only through the provider your security review approved.
Point access reviewers at one admin-controlled inventory of AI provider connections—named, described, and scoped—instead of chasing keys pasted across automations and personal notes.
Configure a single OpenAI or Anthropic connection and let every AI Field Agent that drafts control narratives, summarizes assessments, or classifies findings consume it—no per-automation key handling by compliance teams.
If a provider incident or policy change demands it, disable the affected connection centrally and every dependent AI workflow stops at once. It's a resilience control you can execute in seconds—and demonstrate to reviewers afterward.
Pair Workspace Secrets with Service Accounts: governed identities for what touches SmartSuite, centrally stored credentials for the AI providers those governed workflows call.
AI credentials are secrets with real spend and real data exposure behind them. Workspace Secrets keeps the keys behind AI-assisted risk, compliance, and audit workflows governed centrally--while teams keep building freely.
Workspace Secrets is SmartSuite's central storage for third-party AI provider API keys, delivered through the AI Control Center. Administrators enter each provider's key once, and AI features across the Workspace reuse the stored connection without the key being re-entered or exposed.
Documented providers include OpenAI, Anthropic, Google Gemini, Amazon Bedrock, Azure OpenAI, Perplexity AI, Nscale, IBM watsonx, and xAI. For each connection you choose the provider and model, paste the key, and name the connection.
Only Workspace Administrators. The AI Control Center is admin-restricted, so key entry, scoping, and disabling all happen through a controlled, central surface rather than in individual builders.
Yes. Each connection can be made available across all Solutions or restricted to specific ones, and individual AI features can be enabled or disabled per connection—so a costlier or more sensitive model serves only the Solutions you designate.
No. Builders select a connection from a dropdown showing only the connections active for that Solution and feature—the underlying key is never displayed or re-entered at the point of use.
Centralizing AI credentials gives security teams one reviewable inventory of which providers are connected, what each connection is for, and where it may be used—evidence that credential handling follows policy, which helps the organization stay audit-ready.
The AI Control Center is documented as available to Workspaces with AI features, and SmartSuite's pricing page lists AI features—including Bring Your Own Model and AI Admin Controls—across all current plans. No separate gating for the credential store itself is documented.
Put Every AI Key Behind One Governed Door
Store provider credentials once, scope them to the work that needs them, and let teams build AI workflows without ever handling a key.