Smartsheet Architect — Transferable Policy Registry for a Nonprofit GRC Program
Only freelancers located in the U.S. may apply.U.S. located freelancers only
We are a boutique strategic advisory firm, serving as GRC implementation partner to a national nonprofit organization midway through a policy remediation program. We need a Smartsheet architect to finish the registry that program runs on. Roughly 450 documents across 15 domains. Business plan, 6 paid seats. This is not a permanent enterprise GRC platform, and pricing it as one is the fastest way to a no from us. The build has a defined life and a known successor: it carries the remediation program through publication, then the registry transfers to the client, who will choose their own long-term platform. That decision is theirs and we are not pre-empting it. The governing constraint is therefore export fidelity, not application polish. The data — keyed, flat, documented, provably exportable — is the asset that has to survive. Anything built to make Smartsheet a better destination is written off at transfer. We need a plain registry that exports cleanly and documents its own data model than a richer application that strands its content. What the Smartsheet consultant builds: • Central register keyed on a permanent auto-number ID, with the readable reference number kept as a human label only • Explicit Parent ID on companion-document relationships, because row hierarchy does not survive a flat export • Document type and authority reach as separate fields, required approval level derived by lookup, and a hard flag on two statutory policies that cannot be routed around • One operating approval path with the statutory exception enforced and a recorded manual override, native approval capture with identity and timestamp, and a rework loop that returns to Stage 3 on the same record • Intake forms, required on-record evidence fields, and an append-only stage-events log • A ten-metric layer and five audience dashboards — audit committee, executive leadership, policy steering committee, internal audit (read-only, no edit rights anywhere), and our internal team — every one of them reading from that single shared layer • A proven export, demonstrated at the foundation gate rather than promised at the end, plus a transfer package: platform-neutral data dictionary keyed to the permanent ID, field lineage, automation and calculation inventory, and migration mapping notes Outside of scope: No confidential whistleblower or conflict-of-interest channel — wrong tool for it, and it should not live in a workspace that changes hands. No paid add-ons, no Dynamic View, no Enterprise-tier dependency. No operational lifecycle stages after publication. Inherited automations are retired and replaced with the lean set the workflow actually needs, not diagnosed and repaired — archaeology on 23 automations you didn't write costs more than clean replacement and documents worse. Our firm will handle taxonomy reconciliation, the import-ready source file, the data load itself, acceptance testing, and run-guide authoring. You build the structure and validation and return the exception report. The load is clerical; the structure is the expertise we're buying. Our delivery dates are committed in writing and the schedule risk on them is ours. Firm deadline: October 5 is fixed by a client audit committee meeting and cannot move. Award is immediate and kickoff is within three business days. That leaves a genuinely tight build window, and we would rather hear that from you now than in late September. If the full scope above does not fit the window, say so and tell us what does. The register with its permanent-ID key, a clean round-tripping export, and the audit-committee approval path are what must be live and trustworthy on October 5. The rest can follow in the weeks after, and we will structure the milestones accordingly. REQUIRED: Deep Smartsheet architecture — cross-sheet references, auto-number keys, index/match lookup patterns, native approval workflows, forms, update requests, current-user reports. Multi-audience dashboards off a single shared metrics layer. Working knowledge of the Smartsheet API including attachment retrieval and Business-plan rate and row limits. Documentation discipline: data dictionaries and ERDs are graded deliverables here, not afterthoughts. Experience taking a Smartsheet solution off Smartsheet is the strongest signal you can send. Policy governance, internal audit, risk and compliance background in nonprofit is preferred, although not a requirement.
- Less than 30 hrs/weekHourly
- 1-3 monthsDuration
- ExpertExperience Level
- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:5 to 10
- Last viewed by client:last week
- Interviewing:4
- Invites sent:5
- Unanswered invites:2
About the client
- USABrooklyn11:58 AM
- $500 total spent1 hire, 0 active
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by