Pricing
One ladder for the whole suite.
Each product is a surface on one model, not a product beside it, so every surface is included from the first paid plan up and none is sold separately.
Starter
One team, one product, in production.
- 1 application
- 2 editors, 1 ratifier
- Production keys
- Access rules, release policies, conflict detection
- 30 days of history
Team
A platform team that wants the coverage number for their own product.
- 3 applications
- 5 editors, 3 ratifiers
- SSO / SAML
- Proposal and ratification workflow
- 90 days of history
Business
Engineering carrying a compliance obligation.
- 10 applications
- 20 editors, 10 ratifiers
- Audit export to your SIEM
- 1 year of history, SCIM provisioning
- Publish to the marketplace
Billed annually at two months free. Every plan includes the console, the Playground, the docs and the MCP tools.
Free
$0
Proving it to yourself.
- 1 application, development and staging only
- 1 editor, unlimited inspectors
- 7 days of history
- No production key
Enterprise
Custom
Federation and data residency.
- Unlimited applications and seats
- Self-host or VPC
- Rollup across organizations
- Ontology alignment, SLA, named contact
Free plans get development and staging keys, never a production key. That is not a limit we invented. The environment is read off the key itself, so it is the same boundary the platform already enforces. Build against it for free; pay when it faces your users.
Every row, side by side
Meters that mean the same thing whichever part of the suite you are using.
| Free$0forever | Starter$99per month | Team$499per month | Business$1,499per month | EnterpriseCustomquoted | |
|---|---|---|---|---|---|
| Scale | |||||
| Applications | 1, non-production | 1 | 3 | 10 | Unlimited |
| Editors — may write | 1 | 2 | 5 | 20 | Unlimited |
| Ratifiers — may put a rule in force | — | 1 | 3 | 10 | Unlimited |
| Inspectors — may read the panelNever metered, on any plan. Asking “may I do this, and why” is the habit the product exists to create. | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
| Production keys | — | ||||
| Governance | |||||
| Composable controlsFeature flags, access controls, audit logs, error logs and user analytics. Add one to one control, or all five to all of them. | Flags, access | All five | All five | All five | All five |
| Access rules and release policies | |||||
| Conflict detection | |||||
| Coverage reporting | |||||
| Build manifest publishing | |||||
| View as — ask as any seat, or as nobody | |||||
| Audit | |||||
| Occurrence history | 7 days | 30 days | 90 days | 1 year | Configurable |
| Usage and activity on every control | |||||
| Export to your SIEM or a webhook | — | — | — | ||
| API | |||||
| Read your OpenAPI documentFree and unmetered, with or without an account — the reading runs in your browser and the document never leaves it. We charge for authority, not for looking. | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
| Endpoints bound to operations | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
| x-dna in your specification | |||||
| Enforcement at your API edgeA middleware asks your model for a decision at your own edge. Nothing proxies your traffic, so there is no per-request meter to buy. | Non-production | ||||
| API operations in the audit record | |||||
| Agents | |||||
| Acting agentsAn agent that may act is an editor seat, at the same price as a person. If a human and an agent holding the same grant are interchangeable — which is the whole argument — charging differently for them would contradict it. | 1, non-production | ||||
| Read-only agents · MCPAn agent that can only ask questions is an inspector, and inspectors are never metered. Point Claude, Cursor or your own loop at your model and it costs nothing. | Unlimited | Unlimited | Unlimited | Unlimited | Unlimited |
| Policy-gated execution, human escalation | |||||
| Bring your own model key | |||||
| Authoring | |||||
| Propose and ratify separately | — | — | |||
| MCP tool surface | |||||
| Marketplace packs | Read | Read | Read | Read and publish | Read and publish |
| Administration | |||||
| SSO / SAML | — | — | |||
| SCIM provisioning | — | — | — | ||
| Rollup across organizations | — | — | — | — | |
| Self-host or VPC | — | — | — | — | |
| Support | Community | 1 business day | Shared Slack | Named contact, SLA | |
| Join the waitlist | Join the waitlist | Join the waitlist | Join the waitlist | Talk to us | |
Add-ons
So nobody has to jump a tier for one dimension.
+$149
Extra application
per month
+$59
Extra editor seat
per month
+$99
Extra year of history
per month
Model it. Govern it. Run it.
Your seats and applications carry forward.
Operations is one core and a surface for every way into your software. As each surface lands it lights up rows on the plan you already have — Agent Operations adds no meter of its own, because an agent that may act is an editor seat and one that only reads is an inspector. You will not be asked to buy a second product to keep using the first.
Model it
Meeting notes, docs and tribal knowledge, compiled into a living operating model.
Govern it
Who may use each control, what is on, and everything that has happened, inside your running product.
Govern it
Who may call each endpoint, and what it recorded, read off your own OpenAPI document.
Run it
Your agents holding the operations you granted them, under the policies you already wrote.
Pricing questions
Can I buy one surface on its own?
No, and that is deliberate. Every surface reads and writes the same model, and selling one of them apart from the graph underneath it would ship you half a product. Every paid plan includes all of them.
What counts as an application?
One deployed product with its own key: the thing a person opens. Staging and development environments of the same product do not count separately; a second product with its own users does.
Who needs to be an editor?
Anyone who writes a rule. Reading the panel, which is asking who may use a control and why, is free and unlimited on every plan, including Free. We charge for authority, not for looking.
What is the difference between an editor and a ratifier?
An editor may write a rule. A ratifier may put it in force. Being able to write something must never imply being able to make it decide, so they are separate grants in the product and separate seats on the plan.
Do you meter events, page views or monthly active users?
No. Your occurrence log grows with your own traffic, and metering it would price you for your success and give you a reason to instrument less. We meter applications and seats, figures you can predict when you sign.
What happens to my price when Design and Run ship?
Nothing. They light up rows on your existing plan, using the same seats and applications you are already paying for.
Is there a trial?
The Free plan is the trial, and it does not expire: one application on development and staging keys, one editor, unlimited inspectors. Asking for a production key is the moment it becomes a paid conversation.
See it on your own controls.
Install it, open the panel, and read what governs each button in your product. Permissions, flags, usage and audit, in one reading.