> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Grist

> Collaborative spreadsheets — members & access

<Tabs>
  <Tab title="Overview">
    Connect Grist with an API key to sync organization members, workspaces and documents, and run access reviews. Read-only; the key is held by Nango, and DSALTA keeps only a connection reference.

    <Info>
      **Read-only access.** DSALTA only reads data from this integration. It never creates, modifies, or deletes anything in your environment, and every remediation step is performed by your team directly in the third-party product.
    </Info>

    <Info>
      **What you'll see.** The Access page lists the **members** of one Grist organization — a team site when the key can see one, otherwise the personal site — with their name, email and access level (**owners**, **editors** or **viewers**). Only people Grist marks as members of the organization are included; guests who were shared a single document or workspace are left out. Grist reports no account status, join date or MFA state, so every member is shown as **Active** with MFA **Unknown**, and each row is stamped with the date of the sync.
    </Info>

    <Note>
      DSALTA collects this integration's data when you connect it — you can refresh it at any time with **Sync from integrations** on the **Integrations** page. The compliance checks below re-run once a day at 02:00 America/New\_York.
    </Note>

    ## What DSALTA reads

    DSALTA reads the Grist organization member roster — names, emails and access levels — which appears on your **Access** page; and the organization's **workspaces**, which appear on your **Inventory** page with a count and the names of the documents inside them. Document contents are never read.

    It calls these Grist endpoints, through Nango's proxy, on `docs.getgrist.com`:

    * `/api/orgs`
    * `/api/orgs/{id}/access`
    * `/api/orgs/{id}/workspaces`

    Every request is a read. DSALTA has no code path that creates, modifies, or deletes anything in your Grist environment.

    ## Troubleshooting

    <AccordionGroup>
      <Accordion title="The Access page shows my personal site instead of the team">
        A Grist API key can see every site its owner belongs to. DSALTA prefers a team site over a personal one and, among several, takes the one with the lowest ID; there is no field to pin another. Connect with the key of a user who belongs only to the team site you want reviewed. Note that disconnecting permanently deletes the data already collected from Grist.
      </Accordion>

      <Accordion title="The connection is rejected">
        DSALTA checks the key as soon as Nango reports the connection, by listing the sites it can see. A mistyped or revoked key, or one whose owner belongs to no Grist site, is rejected there and the integration never reaches the **Connected** tab. If the card later reads **Connection issues detected** under **Manage → Status**, disconnect and connect again with a fresh key from **Account settings → Developer**.
      </Accordion>
    </AccordionGroup>

    <AccordionGroup>
      <Accordion title="How do I check whether the connection is healthy?">
        Open **Integrations** in the DSALTA sidebar, stay on the **Connected** tab, and click **Manage** on the integration's card. Open the **Status** tab: it shows either **Connected and working properly** or **Connection issues detected**.

        Use the **Status** tab, not **Overview** — Overview always reports **Connected** regardless of the real state.
      </Accordion>

      <Accordion title="A check shows Failed and nothing changed on my side">
        On an integration-powered check, **Failed** normally means DSALTA was blocked rather than that you are non-compliant. Open the test, go to **Source Data**, and read the result code: **403** is a missing permission, **428** is a setting DSALTA still needs, **500** is a failure on DSALTA's side.

        A real compliance gap shows **207** and leaves the test looking **Completed**. See [Understanding Test Results](/guides/compliance/test-results).
      </Accordion>

      <Accordion title="Data looks out of date">
        Compliance checks re-run once a day at 02:00 America/New\_York. To refresh sooner, open **Integrations → Connected** and click **Sync from integrations** at the top right — it refreshes every connected integration at once.
      </Accordion>

      <Accordion title="How do I repair a broken connection?">
        There is no Reconnect, Repair or Refresh Token button. The only repair available is to disconnect and connect again.

        <Warning>
          **Disconnecting is destructive and cannot be undone.** DSALTA removes the access records, inventory, vulnerabilities, code changes, incidents and device records collected from this integration, and deletes the test results tied to the connection. Export anything you still need as audit evidence first — see [Integration errors](/troubleshooting/integration-errors).
        </Warning>
      </Accordion>

      <Accordion title="Configure scope will not let me change anything">
        That is expected. **Configure scope** is read-only — it shows what DSALTA is permitted to read, and has no Save action. To change what DSALTA can see, change the permissions on the credential in the third-party product, then disconnect and connect again.
      </Accordion>
    </AccordionGroup>
  </Tab>

  <Tab title="How to connect">
    Connect Grist by entering your API key in a secure Nango window. The key is stored by Nango — DSALTA only keeps a connection reference.

    **Before you begin**

    * A Grist account on [getgrist.com](https://getgrist.com) that belongs to the team site you want reviewed. Grist states that an API key "is owned by a single user, and has the same permissions as that user", so use an account that is an **Owner** of the site.

    You will need:

    | Field       | Where to find it                                   | Example                                         |
    | ----------- | -------------------------------------------------- | ----------------------------------------------- |
    | **API key** | Profile picture → **Account settings → Developer** | Visible on that page; **Create** if none exists |

    <Steps>
      <Step title="Start in DSALTA">
        Open **Integrations** in the DSALTA sidebar, find **Grist**, and click **Connect** to open the connect panel. Leave it open — the steps below are listed there too.
      </Step>

      <Step title="Open your Grist account settings">
        Sign in at [getgrist.com](https://getgrist.com), click your profile picture, and choose **Account settings**. The API key lives under the **Developers** section — not under any API menu.
      </Step>

      <Step title="Copy your API key">
        In **Account settings**, open the **Developer** page and copy your API key, or click **Create** if none exists. Grist keeps one key per user: **Remove** revokes it, and creating a new one afterwards breaks any connection that used the old key.
      </Step>

      <Step title="Connect Grist">
        Return to the connect panel and click **Connect**. A secure Nango window opens — paste the API key there. The key is stored by Nango; DSALTA keeps only a connection reference and never stores the key directly.
      </Step>
    </Steps>

    <Check>
      Once Nango confirms the connection to DSALTA, DSALTA creates this integration's checks, runs them, and starts the first sync. The integration moves to the **Connected** tab, and **Manage → Status** reads **Connected and working properly** once the first sync has succeeded.
    </Check>

    <Warning>
      **If the connection is rejected.** An invalid or revoked API key, or a key whose owner belongs to no Grist site. The Nango window itself does not test the key — DSALTA validates it when Nango reports the connection, by listing the sites the key can see.

      The on-screen message is generic — see [Connection error messages](/troubleshooting/connection-error-messages).
    </Warning>
  </Tab>

  <Tab title="Automated checks">
    Each check below re-runs once a day, at 02:00 America/New\_York, while this integration is connected. Click any check for step-by-step remediation guidance.

    | Check                                                                                                                | Severity | What it verifies                                                                 |
    | -------------------------------------------------------------------------------------------------------------------- | -------- | -------------------------------------------------------------------------------- |
    | [User access to Critical System should be valid](/integrations/grist/user-access-to-critical-system-should-be-valid) | Info     | Checks that everyone with Grist access is an active employee on the People page. |
    | [Offboarded users should not have active access](/integrations/grist/offboarded-users-should-not-have-active-access) | High     | Checks that offboarded employees no longer have active Grist access.             |
  </Tab>

  <Tab title="Useful links">
    | Topic       | Link                                                                    |
    | ----------- | ----------------------------------------------------------------------- |
    | Setup       | [Grist REST API and API keys](https://support.getgrist.com/rest-api/)   |
    | Remediation | [Team sites and members](https://support.getgrist.com/teams/)           |
    | General     | [Grist](https://getgrist.com)                                           |
    | DSALTA      | [Connection error messages](/troubleshooting/connection-error-messages) |
  </Tab>
</Tabs>
