User Types and Entitlements
This page is the current PacketSafari knowledge-base source of truth for who can do what.
Your effective access is shaped by six different layers:
| Layer | What it controls | Notes |
|---|---|---|
| Deployment mode | Whether the workspace is running in SaaS or on-prem mode | On-prem unlocks the SaaS AI paywall layer, but deployment-specific runtime controls still matter. |
| Organization entitlement | Enterprise Shared or Dedicated pooled capacity | An active organization entitlement takes precedence over a member's individual SaaS quota template. |
| Plan entitlement | Analyzer Free, Copilot Pro, Agent Pro, or legacy paid aliases | The active end date gates paid access. Expiry preserves the stored paid quota template so reactivation does not require entitlement repair, but does not preserve paid feature access. |
| On-prem license | Deployment identity, named users, Agent access, and all three AI usage categories | A valid signed token is authoritative even though the SaaS paywall is bypassed. |
| Admin role | Access to the admin workspace and operator controls | Admin is a permission boundary, not just a billing label. |
| Sharing roles | Which users or role groups can read or write a capture | Roles control capture access, not billing or AI plan access. |
Legend
| Marker | Meaning |
|---|---|
| β | Included / full access |
| π | Preview / limited access |
| π | Blocked or upgrade required |
| π οΈ | Admin only |
| π’ | On-prem only |
| βοΈ | Depends on deployment flags, capture state, or admin override |
Current user types
| User type | Where it exists | How it is assigned | What it mainly changes |
|---|---|---|---|
| Analyzer Free | SaaS | No active paid subscription | Preview Copilot/security/connection access, lower quota template, no Agent or paid download entitlement |
| Copilot Pro | SaaS | Active Copilot subscription or legacy Copilot-equivalent paid plan | Full Copilot, security, advanced connections, and OT analysis; Agent still locked |
| Agent Pro | SaaS | Active Agent subscription | Full AI access, a plan-controlled Analysis-run allowance, default 1 active session |
| Admin | SaaS or on-prem | Membership in the admin role | Admin workspace access, paywall bypass, operator controls |
| On-prem user | On-prem | Normal signed-in user in an on-prem deployment | SaaS paywall is bypassed for feature entitlements |
| On-prem admin | On-prem | Admin-role user in an on-prem deployment | On-prem feature entitlements plus admin workspace and deployment controls |
Capability matrix
| Capability | SaaS Analyzer Free | SaaS Copilot Pro | SaaS Agent Pro | SaaS Admin | On-prem user | On-prem admin | Notes |
|---|---|---|---|---|---|---|---|
| Manual packet analysis | β | β | β | β | β | β | Core analyzer access is not paywalled. |
| Upload PCAPs | β | β | β | β | β | β | Deployment-wide upload flags can still disable uploads for everyone. |
| Share captures with users and roles | β | β | β | β | β | β | Sharing roles control capture ACLs, not plan entitlements. |
| Copilot chat | π | β | β | β | β | β | Free SaaS stays in preview mode. |
| Agent runs | π | π | β | β | βοΈ | βοΈ | SaaS users need Agent Pro or an active Enterprise organization entitlement for autonomous Agent runs. On-prem Agent access bypasses the SaaS paywall, but can still be blocked by an invalid license, disabled Agent entitlement, or exhausted deployment runs. |
| Security insights | π | β | β | β | β | β | Free preview keeps only limited/redacted security detail. |
| Advanced connections | π | β | β | β | β | β | Free preview keeps only limited correlated connection detail. |
| OT analysis | π | β | β | β | β | β | OT analysis is blocked for free SaaS users. |
| Anoncap private profile and custom privacy policy | π | β | β | β | β | β | Free SaaS can use the public/basic anonymization profile. Active premium, enterprise, admin, and on-prem access adds PacketSafari's private rules plus configurable privacy classes and identity groups. |
| Download owned PCAPs | π | β | β | β | β | β | SaaS downloads require premium access; on-prem bypasses the SaaS subscription gate. |
| Signed anonymous viewer links for private captures | π | π | β | β | β | β | Owner-only, read-only, time-limited share links without making the capture public. Legacy paid full-access SaaS plans also retain this entitlement while active. |
| Admin workspace | π | π | π | π οΈ | π | π οΈ | Admin access is role-based. |
| User directory and security management | π | π | π | π οΈ | π | π οΈ | Includes user/session/security operations. |
| On-prem deployment and updates pages | n/a | n/a | n/a | n/a | π | π οΈ | These pages are only meaningful in on-prem deployments. |
| SAML / OIDC browser SSO | n/a | n/a | n/a | n/a | π’ | π’ | Available in on-prem mode only. |
| SCIM provisioning | n/a | n/a | n/a | n/a | π’ | π’ | Available in on-prem mode only. |
| Local / on-prem AI provider configuration | n/a | n/a | n/a | n/a | π | π οΈ | On-prem admins can configure local AI endpoints and egress approvals. |
Current plan-to-feature entitlement mapping
| Feature | Analyzer Free | Copilot Pro | Agent Pro | Admin | On-prem |
|---|---|---|---|---|---|
| Copilot | π | β | β | β | β |
| Agent | π | π | β | β | βοΈ |
| Security | π | β | β | β | β |
| Advanced connections | π | β | β | β | β |
| OT analysis | π | β | β | β | β |
| Anoncap private profile and custom privacy policy | π | β | β | β | β |
User-record quota templates
These are the current quota values attached to user records and shown in account/admin quota views. A paid plan's stored values are retained after its end date passes, even though runtime paid access is disabled until reactivation.
| Limit | Analyzer Free | Copilot Pro | Agent Pro | Admin | Notes |
|---|---|---|---|---|---|
| Max storage total | 5 MB | 3,000 MB | 20,480 MB | β | Storage shown in the profile/admin quota cards. |
| Max files total | 10 | 1,000 | 1,000 | β | Total captures owned by the user. |
| Max files per month | 10 | 500 | 200 | β | Upload count quota template. |
| Max downloads per month | 100 | 500 | 500 | β | Download count quota template. |
| Max indexing per month | 10 | 1,000 | 1,000 | β | Indexing job quota template. |
| Max Analysis runs per month | 0 | 0 | Plan setting | β | A user-initiated guided full investigation counts once only when its workflow completes. Inconclusive or later-corrected conclusions still count; failed uploads, rejected submissions, service failures, interruptions, and automatic retries do not. Report milestones, resumes, and same-investigation follow-ups remain included. |
| Max Quick questions per month | 100 | 100 | 100 | β | One submitted Copilot question or lightweight standalone Agent-tab question counts once. |
| Max Prompt Coach requests per month | 500 | 500 | 500 | β | One explicit Prompt Coach submission counts once. |
| User-record max upload file size | 1 MB | 200 MB | 200 MB | β | Hosted launch quota for SaaS upload admission. |
Opening or reading an AI surface, typing without submitting, automatic retries, and internal tool/model calls consume none of these categories. The profile shows used, limit, remaining, and reset date for all three.
Enterprise organization entitlements
Enterprise usage is pooled across active members and replaces the individual user quota template while the organization entitlement is active. An organization entitlement is active only while the organization and membership are active and the organization's entitlement expiration has not passed. Expired organizations are excluded from capture and shared-resource authorization as well as new upload selection.
| Limit | Shared Enterprise SaaS | Dedicated Enterprise SaaS |
|---|---|---|
| Named users | 5 | 5 |
| Capture upload | 1 GB | 1 GB |
| Active storage | 100 GiB | 250 GiB |
| Processed capture data/month | 250 GiB | 1 TiB |
| Analysis runs/month | Contract setting | Contract setting |
| Shared Quick questions/month | 100 | 100 |
| Shared Prompt Coach requests/month | 500 | 500 |
| Automatic capture retention | Opt-in; suggested 30 days | Opt-in; suggested 90 days |
| Analysis capacity | Shared priority Agent and indexing queues | One reserved Agent slot and one reserved indexing slot |
An accepted full-processing ingest meters retained capture bytes once toward processed capture data; store-only ingestion meters zero. Each accepted explicit post-index, infrastructure-scan, or deferred-materialization operation meters one retained capture size. Failed queue admission does not count. Organization reprocessing requires an idempotency key; a committed replay does not count again and a pending replay is rejected. Contracted add-ons extend these pooled limits.
The Quick-question and Prompt-Coach values above are one pool for the entire organization, not a per-member grant. Every member sees used, remaining, limit, reset date, and shared scope. Owners/admins additionally see the per-member breakdown and total so an approaching limit is visible before it blocks work.
Runtime ceilings and exceptions
These rules are important because they affect real behavior now, even when older plan copy or legacy quota templates say something else.
| Rule | Current behavior | Why it matters |
|---|---|---|
| Individual SaaS PCAP upload ceiling | 200 MB for Copilot Pro and Agent Pro | Enterprise organization upload limits come from the contracted organization entitlement instead of the individual-plan clamp. |
| Enterprise organization precedence | An active Shared or Dedicated organization entitlement supplies the member's pooled upload, storage, processed-data, Analysis-run, Quick-question, and Prompt-Coach limits | Enterprise members do not fall back to the individual SaaS quota while the organization entitlement is active. The customer-facing qualified capture profile is 1 GB; the outer request envelope does not expand that commercial limit. |
| Paid-plan active date | Paid SaaS feature access requires the user subscription code and deactivation/end date to still be active | Demo, trial, and migrated paid users can show a visible expiration date. After it passes, paid feature access falls back, but PacketSafari preserves the stored paid quota values so extending the date restores the account without rewriting its plan. |
| On-prem PCAP upload ceiling | Validated per deployment profile | Contract/SOW and support docs should state the tested profile envelope instead of relying on a generic public size claim. |
| Accepted capture upload types | .pcap, .pcapng, .cap | Unsupported extensions are rejected before storage. |
| TLS key upload ceiling | 2 MB hard cap | TLS key uploads stay intentionally small even if PCAP uploads can be larger. |
| Agent Pro concurrent-session default | 1 active SaaS session | Only Agent Pro gets the default plan-enforced session limit. |
| Concurrent-session admin override | Admin can raise a SaaS user's limit to a specific number | This override is stored per user. |
| Concurrent sessions on-prem | Not enforced | On-prem deployments bypass the SaaS concurrent-session rule entirely. |
| On-prem AI license exception | AI can be blocked even on-prem when the license token is invalid or unavailable, Agent is disabled, or the applicable category is exhausted | The SaaS subscription paywall is bypassed on-prem, but the deployment license is still authoritative. Analysis runs, Quick questions, and Prompt Coach are independently contract-configurable; -1 means unlimited only for that category. |
| SaaS download entitlement | Requires premium access | Analyzer Free users do not get the paid download entitlement. |
| SaaS public-download exception | Public captures can still only be downloaded by the owner or admins | Read access to a public capture does not automatically allow download. |
noAI capture tag exception | Non-owners cannot download a capture tagged noAI | The owner can still download it. |
noAI AI exception | AI-assisted analysis is disabled for captures tagged noAI | This blocks Copilot and Agent while preserving manual packet analysis according to the capture ACL. |
| Signed viewer-link scope | Only the capture owner can create or revoke these links, and the shared session stays read-only for that capture | Roles and public visibility do not grant signed-link management. |
| On-prem AI anonymization | Non-anonymized AI is blocked by default | On-prem admins can explicitly allow non-anonymized AI. |
Upload-time AI behavior
Upload-time AI choices remain explicit and separate:
| Feature | What controls it | Notes |
|---|---|---|
| Copilot / Ask AI | Copilot entitlement and Quick-question availability | Each submitted question consumes one Quick question. |
| Agent quick question | Agent/Copilot entitlement and Quick-question availability | A lightweight standalone Agent-tab submission consumes one Quick question from the same allowance as Copilot. |
| Agent investigation | Agent entitlement, shared analysis-run availability, and the guided investigation setup | Starts the selected Agent workflow. The full analysis counts once only if its workflow completes; its selected model, depth, report milestones, retries, resumes, and normal follow-ups remain included. |
| Prompt Coach | Prompt-Coach availability | Each explicit coaching request consumes one Prompt Coach request; it never consumes an Analysis run or Quick question. |
When report email delivery is requested from the upload flow, PacketSafari stores the deferred launch and email delivery state with the capture. The visible status can move through waiting for the report, queueing, queued, sending, sent, failed, or skipped depending on whether the Agent report is saved and the mail provider accepts the message.
Deployment-wide switches that override user entitlements or access paths
Even a paid or admin user can be blocked or rerouted by deployment policy when one of these runtime switches is changed.
| Runtime switch | Effect |
|---|---|
ENABLE_LOGIN | Turns the local username/password sign-in flow on or off |
ENABLE_REGISTRATION | In on-prem mode, allows or blocks direct self-registration |
ENABLE_SOCIAL_LOGIN_OAUTH | Allows or blocks GitHub and Google OAuth sign-in flows |
ENABLE_SAAS_PAYWALL | Turns the SaaS entitlement gate on or off for hosted deployments |
ENABLE_UPLOAD | Turns authenticated uploads on or off for the deployment |
ENABLE_ANON_UPLOAD | Turns anonymous upload intake on or off |
ENABLE_BYO_OPENAI_API_KEY | In on-prem mode, allows admins to use their own OpenAI API key for AI access |
ENABLE_CODEX_CHATGPT_LOGIN | In on-prem mode, allows browser-based ChatGPT / Codex login for PacketSafari's native Codex runtime |
ENABLE_CAPTURE_PROBES | In on-prem mode, enables capture probe enrollment and probe-driven collection workflows |
CAPTURE_PROBES_REQUIRE_APPROVAL | Keeps newly enrolled probes pending until an admin approves them |
DISABLE_ALL_AI | Hard-disables Copilot and Agent model-backed work |
ENABLE_UPLOAD_INDEXING_SETTINGS | Enables or disables advanced upload indexing controls |
ENABLE_ANON_AGENT_REPORT_EMAIL | Allows anonymous/free Agent report delivery to an entered email address when mail delivery is configured |
ON_PREM_ALLOW_NON_ANON_AI | In on-prem mode, allows AI on non-anonymized captures |
Legacy plan-code notes
Current product behavior collapses several older internal subscription codes into the same entitlement buckets:
| Entitlement bucket | Current label | Internal codes currently mapped here |
|---|---|---|
| Analyzer Free | Analyzer Free | unsubscribed_user |
| Copilot Pro | Copilot Pro | copilotmonthly2026, lowtiermonthly, lowtieryearly, lowtieryearlybundle |
| Agent Pro | Agent Pro | agentplusmonthly, agentplusyearly, agentproyearly2026 |
| Legacy paid full access | Legacy paid | lowtier, mediumtier, hightier, lowtierdaily |
| Admin | Admin (Unlimited) | admin |
Legacy paid plans are important operationally because they keep full feature access while active, but they do not all inherit the same quota template as current Copilot Pro or Agent Pro:
| Legacy code | Effective feature access | Stored quota nuance |
|---|---|---|
lowtierdaily | Full paid access | Keeps 4 monthly agent invocations and 1,000 monthly downloads |
lowtier | Full paid access | Keeps 4 monthly agent invocations and 1,000 monthly downloads |
mediumtier | Full paid access | Keeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads |
hightier | Full paid access | Keeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads |
Treat those legacy codes as a feature-entitlement alias, not as a quota alias for Copilot Pro or Agent Pro.
Practical summary
- If you are trying to explain AI access, use the entitlement tables above.
- If you are trying to explain admin/operator permissions, use the admin-role rows.
- If you are trying to explain who can open or modify a capture, use sharing roles and capture ACLs.
- If a user says βmy plan should allow thisβ but the feature is still unavailable, check deployment-wide runtime flags next.
Maintenance note
- Changed in this pass: no plan, quota, admin-boundary, upload/download, concurrent-session, license, or runtime-flag contract changed. Public KB pages now consistently describe Upload Insights as deterministic first-open evidence, exclude it from AI authentication and AI history, use the current Preliminary Report / Verification / Final Report labels, and describe report milestones as persisted automatically rather than generated later. The roles page required no entitlement changes.
- Verified against code: entitlement and concurrent-session policy in
backend/packetsafari/entitlements.py; quota templates inbackend/packetsafari/common/rate_limits.py; upload/download gates and organization precedence inbackend/packetsafari/resources/upload_combined.py,backend/packetsafari/resources/common.py, andbackend/packetsafari/resources/captures.py; runtime switches inbackend/packetsafari/common/admin_feature_flags.py; current upload workflow admission and recommendations infrontend/app/utils/agent-investigation-policy.ts; activity deletion authorization inbackend/packetsafari/resources/aichat.py; plan-expiry preservation inbackend/packetsafari/storage/sql/services/users.py; and canonical milestone labels infrontend/app/constants/investigationMilestones.ts. Recent durable Agent-session, report-lifecycle, TCP-evidence, provider-model, and Codex runtime fixes did not change commercial access contracts. - Customer-facing enterprise upload capacity is
1 GB. Internal runtime headroom is not a commercial entitlement and is not customer-facing copy.
