Entitlements
An entitlement is permission to use part of the CyberOptix CTEM Platform. Your plan grants a set of them; add-ons grant more.
This is worth understanding as a concept rather than a billing detail, because it explains something you will otherwise hit as a surprise: a section that is visible but refuses to open is not broken, it is not included.
Gates
Entitlements are expressed as gates, each naming one thing you can be entitled to:
| Gate | Covers |
|---|---|
| Application exposure | Applications, repositories, code and dependency scanning |
| Cloud exposure | Cloud accounts and posture assessment |
| Identity exposure | Breach records and identity inventory |
| Detection and response | SIEM, detection, alerts and incidents |
| Internal validation | Internal scanning and assessment |
| Integrations | Third-party connections |
Two more are derived rather than granted directly:
- Paid plan - anything other than the free tier.
- Pro plus - a tier threshold, for capability that sits above the entry paid plans.
A gate is all-or-nothing. You either have cloud exposure or you do not; there is no partial version of a gate.
Plans and add-ons
A plan grants a set of gates. An add-on grants more, or raises a limit.
Add-ons are priced three ways, and the difference matters when you are estimating cost:
| Model | Bills |
|---|---|
| Flat | One price. A feature unlock, quantity always one |
| Per unit | A fixed rate per unit you purchase |
| Tiered consumption | Measured usage, against a tier ladder |
The first two are predictable. Tiered consumption is the one to watch, because the bill follows what you actually used rather than what you bought - which is the right model for something like log ingestion, and the one that surprises people.
When you hit a gate
The platform tells you what you were trying to reach and how to unlock it - either by moving to a plan that includes it, or by adding an add-on. Denials name the thing rather than failing vaguely, so "this is not included" is distinguishable from "this is broken".
Usage and limits
Where a plan includes a quantity, usage is metered against it and visible under Billing.
Check usage before you need to. Consumption-based entitlements accumulate quietly, and the point at which you notice is usually the point at which something has already changed - a section stopped accepting new work, or an invoice arrived larger than expected.
The largest consumption dial in the platform is which log sources are evaluated by detection rules. Sources set to search rather than detect stay fully searchable without paying detection cost on every event. Setting that deliberately before enabling detection is much easier than reducing it afterwards. See Detection engineering.
Credits
Some arrangements include service credits - prepaid amounts drawn down as work is performed. Balances and their ledger are visible under Billing, so what remains and what consumed it are both answerable.
Why a section might be empty rather than gated
Not everything missing is an entitlement problem. A section you are entitled to will be empty until something feeds it: cloud exposure needs a connected account, application exposure needs source control, identity exposure needs a verified domain.
Gated and empty look similar at a glance and have completely different fixes. A gate says it is not included; an empty section is included and has nothing in it yet.
Next
- Billing - plan, usage and invoices
- Integrations - connecting what feeds each section