Skip to main content

Entitlements

An entitlement is permission to use part of the CyberOptix CTEM Platform. Your plan grants a set of them; add-ons grant more.

This is worth understanding as a concept rather than a billing detail, because it explains something you will otherwise hit as a surprise: a section that is visible but refuses to open is not broken, it is not included.

Gates​

Entitlements are expressed as gates, each naming one thing you can be entitled to:

GateCovers
Application exposureApplications, repositories, code and dependency scanning
Cloud exposureCloud accounts and posture assessment
Identity exposureBreach records and identity inventory
Detection and responseSIEM, detection, alerts and incidents
Internal validationInternal scanning and assessment
IntegrationsThird-party connections

Two more are derived rather than granted directly:

  • Paid plan - anything other than the free tier.
  • Pro plus - a tier threshold, for capability that sits above the entry paid plans.

A gate is all-or-nothing. You either have cloud exposure or you do not; there is no partial version of a gate.

Plans and add-ons​

A plan grants a set of gates. An add-on grants more, or raises a limit.

Add-ons are priced three ways, and the difference matters when you are estimating cost:

ModelBills
FlatOne price. A feature unlock, quantity always one
Per unitA fixed rate per unit you purchase
Tiered consumptionMeasured usage, against a tier ladder

The first two are predictable. Tiered consumption is the one to watch, because the bill follows what you actually used rather than what you bought - which is the right model for something like log ingestion, and the one that surprises people.

When you hit a gate​

The platform tells you what you were trying to reach and how to unlock it - either by moving to a plan that includes it, or by adding an add-on. Denials name the thing rather than failing vaguely, so "this is not included" is distinguishable from "this is broken".

Usage and limits​

Where a plan includes a quantity, usage is metered against it and visible under Billing.

Check usage before you need to. Consumption-based entitlements accumulate quietly, and the point at which you notice is usually the point at which something has already changed - a section stopped accepting new work, or an invoice arrived larger than expected.

Consumption you control is worth controlling early

The largest consumption dial in the platform is which log sources are evaluated by detection rules. Sources set to search rather than detect stay fully searchable without paying detection cost on every event. Setting that deliberately before enabling detection is much easier than reducing it afterwards. See Detection engineering.

Credits​

Some arrangements include service credits - prepaid amounts drawn down as work is performed. Balances and their ledger are visible under Billing, so what remains and what consumed it are both answerable.

Why a section might be empty rather than gated​

Not everything missing is an entitlement problem. A section you are entitled to will be empty until something feeds it: cloud exposure needs a connected account, application exposure needs source control, identity exposure needs a verified domain.

Gated and empty look similar at a glance and have completely different fixes. A gate says it is not included; an empty section is included and has nothing in it yet.

Next​