PacketSafari

User Types and Entitlements

Current SaaS and on-prem user types, plan entitlements, quotas, and the exceptions that change effective access.

This page is the current PacketSafari knowledge-base source of truth for who can do what.

Your effective access is shaped by six different layers:

LayerWhat it controlsNotes
Deployment modeWhether the workspace is running in SaaS or on-prem modeOn-prem unlocks the SaaS AI paywall layer, but deployment-specific runtime controls still matter.
Organization entitlementEnterprise Shared or Dedicated pooled capacityAn active organization entitlement takes precedence over a member's individual SaaS quota template.
Plan entitlementAnalyzer Free, Copilot Pro, Agent Pro, or legacy paid aliasesThe active end date gates paid access. Expiry preserves the stored paid quota template so reactivation does not require entitlement repair, but does not preserve paid feature access.
On-prem licenseDeployment identity, named users, Agent access, and all three AI usage categoriesA valid signed token is authoritative even though the SaaS paywall is bypassed.
Admin roleAccess to the admin workspace and operator controlsAdmin is a permission boundary, not just a billing label.
Sharing rolesWhich users or role groups can read or write a captureRoles control capture access, not billing or AI plan access.

Legend

MarkerMeaning
βœ…Included / full access
πŸ‘€Preview / limited access
πŸ”’Blocked or upgrade required
πŸ› οΈAdmin only
🏒On-prem only
βš™οΈDepends on deployment flags, capture state, or admin override

Current user types

User typeWhere it existsHow it is assignedWhat it mainly changes
Analyzer FreeSaaSNo active paid subscriptionPreview Copilot/security/connection access, lower quota template, no Agent or paid download entitlement
Copilot ProSaaSActive Copilot subscription or legacy Copilot-equivalent paid planFull Copilot, security, advanced connections, and OT analysis; Agent still locked
Agent ProSaaSActive Agent subscriptionFull AI access, a plan-controlled Analysis-run allowance, default 1 active session
AdminSaaS or on-premMembership in the admin roleAdmin workspace access, paywall bypass, operator controls
On-prem userOn-premNormal signed-in user in an on-prem deploymentSaaS paywall is bypassed for feature entitlements
On-prem adminOn-premAdmin-role user in an on-prem deploymentOn-prem feature entitlements plus admin workspace and deployment controls

Capability matrix

CapabilitySaaS Analyzer FreeSaaS Copilot ProSaaS Agent ProSaaS AdminOn-prem userOn-prem adminNotes
Manual packet analysisβœ…βœ…βœ…βœ…βœ…βœ…Core analyzer access is not paywalled.
Upload PCAPsβœ…βœ…βœ…βœ…βœ…βœ…Deployment-wide upload flags can still disable uploads for everyone.
Share captures with users and rolesβœ…βœ…βœ…βœ…βœ…βœ…Sharing roles control capture ACLs, not plan entitlements.
Copilot chatπŸ‘€βœ…βœ…βœ…βœ…βœ…Free SaaS stays in preview mode.
Agent runsπŸ”’πŸ”’βœ…βœ…βš™οΈβš™οΈSaaS users need Agent Pro or an active Enterprise organization entitlement for autonomous Agent runs. On-prem Agent access bypasses the SaaS paywall, but can still be blocked by an invalid license, disabled Agent entitlement, or exhausted deployment runs.
Security insightsπŸ‘€βœ…βœ…βœ…βœ…βœ…Free preview keeps only limited/redacted security detail.
Advanced connectionsπŸ‘€βœ…βœ…βœ…βœ…βœ…Free preview keeps only limited correlated connection detail.
OT analysisπŸ”’βœ…βœ…βœ…βœ…βœ…OT analysis is blocked for free SaaS users.
Anoncap private profile and custom privacy policyπŸ‘€βœ…βœ…βœ…βœ…βœ…Free SaaS can use the public/basic anonymization profile. Active premium, enterprise, admin, and on-prem access adds PacketSafari's private rules plus configurable privacy classes and identity groups.
Download owned PCAPsπŸ”’βœ…βœ…βœ…βœ…βœ…SaaS downloads require premium access; on-prem bypasses the SaaS subscription gate.
Signed anonymous viewer links for private capturesπŸ”’πŸ”’βœ…βœ…βœ…βœ…Owner-only, read-only, time-limited share links without making the capture public. Legacy paid full-access SaaS plans also retain this entitlement while active.
Admin workspaceπŸ”’πŸ”’πŸ”’πŸ› οΈπŸ”’πŸ› οΈAdmin access is role-based.
User directory and security managementπŸ”’πŸ”’πŸ”’πŸ› οΈπŸ”’πŸ› οΈIncludes user/session/security operations.
On-prem deployment and updates pagesn/an/an/an/aπŸ”’πŸ› οΈThese pages are only meaningful in on-prem deployments.
SAML / OIDC browser SSOn/an/an/an/a🏒🏒Available in on-prem mode only.
SCIM provisioningn/an/an/an/a🏒🏒Available in on-prem mode only.
Local / on-prem AI provider configurationn/an/an/an/aπŸ”’πŸ› οΈOn-prem admins can configure local AI endpoints and egress approvals.

Current plan-to-feature entitlement mapping

FeatureAnalyzer FreeCopilot ProAgent ProAdminOn-prem
CopilotπŸ‘€βœ…βœ…βœ…βœ…
AgentπŸ”’πŸ”’βœ…βœ…βš™οΈ
SecurityπŸ‘€βœ…βœ…βœ…βœ…
Advanced connectionsπŸ‘€βœ…βœ…βœ…βœ…
OT analysisπŸ”’βœ…βœ…βœ…βœ…
Anoncap private profile and custom privacy policyπŸ‘€βœ…βœ…βœ…βœ…

User-record quota templates

These are the current quota values attached to user records and shown in account/admin quota views. A paid plan's stored values are retained after its end date passes, even though runtime paid access is disabled until reactivation.

LimitAnalyzer FreeCopilot ProAgent ProAdminNotes
Max storage total5 MB3,000 MB20,480 MB∞Storage shown in the profile/admin quota cards.
Max files total101,0001,000∞Total captures owned by the user.
Max files per month10500200∞Upload count quota template.
Max downloads per month100500500∞Download count quota template.
Max indexing per month101,0001,000∞Indexing job quota template.
Max Analysis runs per month00Plan setting∞A user-initiated guided full investigation counts once only when its workflow completes. Inconclusive or later-corrected conclusions still count; failed uploads, rejected submissions, service failures, interruptions, and automatic retries do not. Report milestones, resumes, and same-investigation follow-ups remain included.
Max Quick questions per month100100100∞One submitted Copilot question or lightweight standalone Agent-tab question counts once.
Max Prompt Coach requests per month500500500∞One explicit Prompt Coach submission counts once.
User-record max upload file size1 MB200 MB200 MB∞Hosted launch quota for SaaS upload admission.

Opening or reading an AI surface, typing without submitting, automatic retries, and internal tool/model calls consume none of these categories. The profile shows used, limit, remaining, and reset date for all three.

Enterprise organization entitlements

Enterprise usage is pooled across active members and replaces the individual user quota template while the organization entitlement is active. An organization entitlement is active only while the organization and membership are active and the organization's entitlement expiration has not passed. Expired organizations are excluded from capture and shared-resource authorization as well as new upload selection.

LimitShared Enterprise SaaSDedicated Enterprise SaaS
Named users55
Capture upload1 GB1 GB
Active storage100 GiB250 GiB
Processed capture data/month250 GiB1 TiB
Analysis runs/monthContract settingContract setting
Shared Quick questions/month100100
Shared Prompt Coach requests/month500500
Automatic capture retentionOpt-in; suggested 30 daysOpt-in; suggested 90 days
Analysis capacityShared priority Agent and indexing queuesOne reserved Agent slot and one reserved indexing slot

An accepted full-processing ingest meters retained capture bytes once toward processed capture data; store-only ingestion meters zero. Each accepted explicit post-index, infrastructure-scan, or deferred-materialization operation meters one retained capture size. Failed queue admission does not count. Organization reprocessing requires an idempotency key; a committed replay does not count again and a pending replay is rejected. Contracted add-ons extend these pooled limits.

The Quick-question and Prompt-Coach values above are one pool for the entire organization, not a per-member grant. Every member sees used, remaining, limit, reset date, and shared scope. Owners/admins additionally see the per-member breakdown and total so an approaching limit is visible before it blocks work.

Runtime ceilings and exceptions

These rules are important because they affect real behavior now, even when older plan copy or legacy quota templates say something else.

RuleCurrent behaviorWhy it matters
Individual SaaS PCAP upload ceiling200 MB for Copilot Pro and Agent ProEnterprise organization upload limits come from the contracted organization entitlement instead of the individual-plan clamp.
Enterprise organization precedenceAn active Shared or Dedicated organization entitlement supplies the member's pooled upload, storage, processed-data, Analysis-run, Quick-question, and Prompt-Coach limitsEnterprise members do not fall back to the individual SaaS quota while the organization entitlement is active. The customer-facing qualified capture profile is 1 GB; the outer request envelope does not expand that commercial limit.
Paid-plan active datePaid SaaS feature access requires the user subscription code and deactivation/end date to still be activeDemo, trial, and migrated paid users can show a visible expiration date. After it passes, paid feature access falls back, but PacketSafari preserves the stored paid quota values so extending the date restores the account without rewriting its plan.
On-prem PCAP upload ceilingValidated per deployment profileContract/SOW and support docs should state the tested profile envelope instead of relying on a generic public size claim.
Accepted capture upload types.pcap, .pcapng, .capUnsupported extensions are rejected before storage.
TLS key upload ceiling2 MB hard capTLS key uploads stay intentionally small even if PCAP uploads can be larger.
Agent Pro concurrent-session default1 active SaaS sessionOnly Agent Pro gets the default plan-enforced session limit.
Concurrent-session admin overrideAdmin can raise a SaaS user's limit to a specific numberThis override is stored per user.
Concurrent sessions on-premNot enforcedOn-prem deployments bypass the SaaS concurrent-session rule entirely.
On-prem AI license exceptionAI can be blocked even on-prem when the license token is invalid or unavailable, Agent is disabled, or the applicable category is exhaustedThe SaaS subscription paywall is bypassed on-prem, but the deployment license is still authoritative. Analysis runs, Quick questions, and Prompt Coach are independently contract-configurable; -1 means unlimited only for that category.
SaaS download entitlementRequires premium accessAnalyzer Free users do not get the paid download entitlement.
SaaS public-download exceptionPublic captures can still only be downloaded by the owner or adminsRead access to a public capture does not automatically allow download.
noAI capture tag exceptionNon-owners cannot download a capture tagged noAIThe owner can still download it.
noAI AI exceptionAI-assisted analysis is disabled for captures tagged noAIThis blocks Copilot and Agent while preserving manual packet analysis according to the capture ACL.
Signed viewer-link scopeOnly the capture owner can create or revoke these links, and the shared session stays read-only for that captureRoles and public visibility do not grant signed-link management.
On-prem AI anonymizationNon-anonymized AI is blocked by defaultOn-prem admins can explicitly allow non-anonymized AI.

Upload-time AI behavior

Upload-time AI choices remain explicit and separate:

FeatureWhat controls itNotes
Copilot / Ask AICopilot entitlement and Quick-question availabilityEach submitted question consumes one Quick question.
Agent quick questionAgent/Copilot entitlement and Quick-question availabilityA lightweight standalone Agent-tab submission consumes one Quick question from the same allowance as Copilot.
Agent investigationAgent entitlement, shared analysis-run availability, and the guided investigation setupStarts the selected Agent workflow. The full analysis counts once only if its workflow completes; its selected model, depth, report milestones, retries, resumes, and normal follow-ups remain included.
Prompt CoachPrompt-Coach availabilityEach explicit coaching request consumes one Prompt Coach request; it never consumes an Analysis run or Quick question.

When report email delivery is requested from the upload flow, PacketSafari stores the deferred launch and email delivery state with the capture. The visible status can move through waiting for the report, queueing, queued, sending, sent, failed, or skipped depending on whether the Agent report is saved and the mail provider accepts the message.

Deployment-wide switches that override user entitlements or access paths

Even a paid or admin user can be blocked or rerouted by deployment policy when one of these runtime switches is changed.

Runtime switchEffect
ENABLE_LOGINTurns the local username/password sign-in flow on or off
ENABLE_REGISTRATIONIn on-prem mode, allows or blocks direct self-registration
ENABLE_SOCIAL_LOGIN_OAUTHAllows or blocks GitHub and Google OAuth sign-in flows
ENABLE_SAAS_PAYWALLTurns the SaaS entitlement gate on or off for hosted deployments
ENABLE_UPLOADTurns authenticated uploads on or off for the deployment
ENABLE_ANON_UPLOADTurns anonymous upload intake on or off
ENABLE_BYO_OPENAI_API_KEYIn on-prem mode, allows admins to use their own OpenAI API key for AI access
ENABLE_CODEX_CHATGPT_LOGINIn on-prem mode, allows browser-based ChatGPT / Codex login for PacketSafari's native Codex runtime
ENABLE_CAPTURE_PROBESIn on-prem mode, enables capture probe enrollment and probe-driven collection workflows
CAPTURE_PROBES_REQUIRE_APPROVALKeeps newly enrolled probes pending until an admin approves them
DISABLE_ALL_AIHard-disables Copilot and Agent model-backed work
ENABLE_UPLOAD_INDEXING_SETTINGSEnables or disables advanced upload indexing controls
ENABLE_ANON_AGENT_REPORT_EMAILAllows anonymous/free Agent report delivery to an entered email address when mail delivery is configured
ON_PREM_ALLOW_NON_ANON_AIIn on-prem mode, allows AI on non-anonymized captures

Legacy plan-code notes

Current product behavior collapses several older internal subscription codes into the same entitlement buckets:

Entitlement bucketCurrent labelInternal codes currently mapped here
Analyzer FreeAnalyzer Freeunsubscribed_user
Copilot ProCopilot Procopilotmonthly2026, lowtiermonthly, lowtieryearly, lowtieryearlybundle
Agent ProAgent Proagentplusmonthly, agentplusyearly, agentproyearly2026
Legacy paid full accessLegacy paidlowtier, mediumtier, hightier, lowtierdaily
AdminAdmin (Unlimited)admin

Legacy paid plans are important operationally because they keep full feature access while active, but they do not all inherit the same quota template as current Copilot Pro or Agent Pro:

Legacy codeEffective feature accessStored quota nuance
lowtierdailyFull paid accessKeeps 4 monthly agent invocations and 1,000 monthly downloads
lowtierFull paid accessKeeps 4 monthly agent invocations and 1,000 monthly downloads
mediumtierFull paid accessKeeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads
hightierFull paid accessKeeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads

Treat those legacy codes as a feature-entitlement alias, not as a quota alias for Copilot Pro or Agent Pro.

Practical summary

  • If you are trying to explain AI access, use the entitlement tables above.
  • If you are trying to explain admin/operator permissions, use the admin-role rows.
  • If you are trying to explain who can open or modify a capture, use sharing roles and capture ACLs.
  • If a user says β€œmy plan should allow this” but the feature is still unavailable, check deployment-wide runtime flags next.

Maintenance note

  • Changed in this pass: no plan, quota, admin-boundary, upload/download, concurrent-session, license, or runtime-flag contract changed. Public KB pages now consistently describe Upload Insights as deterministic first-open evidence, exclude it from AI authentication and AI history, use the current Preliminary Report / Verification / Final Report labels, and describe report milestones as persisted automatically rather than generated later. The roles page required no entitlement changes.
  • Verified against code: entitlement and concurrent-session policy in backend/packetsafari/entitlements.py; quota templates in backend/packetsafari/common/rate_limits.py; upload/download gates and organization precedence in backend/packetsafari/resources/upload_combined.py, backend/packetsafari/resources/common.py, and backend/packetsafari/resources/captures.py; runtime switches in backend/packetsafari/common/admin_feature_flags.py; current upload workflow admission and recommendations in frontend/app/utils/agent-investigation-policy.ts; activity deletion authorization in backend/packetsafari/resources/aichat.py; plan-expiry preservation in backend/packetsafari/storage/sql/services/users.py; and canonical milestone labels in frontend/app/constants/investigationMilestones.ts. Recent durable Agent-session, report-lifecycle, TCP-evidence, provider-model, and Codex runtime fixes did not change commercial access contracts.
  • Customer-facing enterprise upload capacity is 1 GB. Internal runtime headroom is not a commercial entitlement and is not customer-facing copy.