User Types and Entitlements

Current SaaS and on-prem user types, plan entitlements, quotas, and the exceptions that change effective access.

This page is the current PacketSafari knowledge-base source of truth for who can do what.

Your effective access is shaped by six different layers:

LayerWhat it controlsNotes
Deployment modeWhether the workspace is running in SaaS or on-prem modeOn-prem unlocks the SaaS AI paywall layer, but deployment-specific runtime controls still matter.
Organization entitlementEnterprise Shared or Dedicated pooled capacityAn active organization entitlement takes precedence over a member's individual SaaS quota template.
Plan entitlementAnalyzer Free, Copilot Pro, Agent Pro, or legacy paid aliasesThis controls AI entitlement and the user-record quota template while the subscription end date is still active.
On-prem licenseDeployment identity, named users, Agent access, and weighted Agent unitsA valid signed token is authoritative even though the SaaS paywall is bypassed.
Admin roleAccess to the admin workspace and operator controlsAdmin is a permission boundary, not just a billing label.
Sharing rolesWhich users or role groups can read or write a captureRoles control capture access, not billing or AI plan access.

Legend

MarkerMeaning
Included / full access
👀Preview / limited access
🔒Blocked or upgrade required
🛠️Admin only
🏢On-prem only
⚙️Depends on deployment flags, capture state, or admin override

Current user types

User typeWhere it existsHow it is assignedWhat it mainly changes
Analyzer FreeSaaSNo active paid subscriptionPreview Copilot/security/connection access, lower quota template, no Agent or paid download entitlement
Copilot ProSaaSActive Copilot subscription or legacy Copilot-equivalent paid planFull Copilot, security, advanced connections, and OT analysis; Agent still locked
Agent ProSaaSActive Agent subscriptionFull AI access, 50 weighted Agent units/month template, default 1 active session
AdminSaaS or on-premMembership in the admin roleAdmin workspace access, paywall bypass, operator controls
On-prem userOn-premNormal signed-in user in an on-prem deploymentSaaS paywall is bypassed for feature entitlements
On-prem adminOn-premAdmin-role user in an on-prem deploymentOn-prem feature entitlements plus admin workspace and deployment controls

Capability matrix

CapabilitySaaS Analyzer FreeSaaS Copilot ProSaaS Agent ProSaaS AdminOn-prem userOn-prem adminNotes
Manual packet analysisCore analyzer access is not paywalled.
Upload PCAPsDeployment-wide upload flags can still disable uploads for everyone.
Share captures with users and rolesSharing roles control capture ACLs, not plan entitlements.
Copilot chat👀Free SaaS stays in preview mode.
Agent runs🔒🔒⚙️⚙️SaaS users need Agent Pro or an active Enterprise organization entitlement for autonomous Agent runs. On-prem Agent access bypasses the SaaS paywall, but can still be blocked by an invalid license, disabled Agent entitlement, or exhausted deployment units.
Security insights👀Free preview keeps only limited/redacted security detail.
Advanced connections👀Free preview keeps only limited correlated connection detail.
OT analysis🔒OT analysis is blocked for free SaaS users.
Download owned PCAPs🔒SaaS downloads require premium access; on-prem bypasses the SaaS subscription gate.
Signed anonymous viewer links for private captures🔒🔒Owner-only, read-only, time-limited share links without making the capture public. Legacy paid full-access SaaS plans also retain this entitlement while active.
Admin workspace🔒🔒🔒🛠️🔒🛠️Admin access is role-based.
User directory and security management🔒🔒🔒🛠️🔒🛠️Includes user/session/security operations.
On-prem deployment and updates pagesn/an/an/an/a🔒🛠️These pages are only meaningful in on-prem deployments.
SAML / OIDC browser SSOn/an/an/an/a🏢🏢Available in on-prem mode only.
SCIM provisioningn/an/an/an/a🏢🏢Available in on-prem mode only.
Local / on-prem AI provider configurationn/an/an/an/a🔒🛠️On-prem admins can configure local AI endpoints and egress approvals.

Current plan-to-feature entitlement mapping

FeatureAnalyzer FreeCopilot ProAgent ProAdminOn-prem
Copilot👀
Agent🔒🔒⚙️
Security👀
Advanced connections👀
OT analysis🔒

User-record quota templates

These are the current quota values attached to user records and shown in account/admin quota views.

LimitAnalyzer FreeCopilot ProAgent ProAdminNotes
Max storage total5 MB3,000 MB20,480 MBStorage shown in the profile/admin quota cards.
Max files total101,0001,000Total captures owned by the user.
Max files per month10500200Upload count quota template.
Max downloads per month100500500Download count quota template.
Max indexing per month101,0001,000Indexing job quota template.
Max weighted Agent units per month0050Focused standard-model runs use 1 unit; Fast + verification and focused strongest-model runs use 2; deep strongest-model runs use 4.
User-record max upload file size1 MB200 MB200 MBHosted launch quota for SaaS upload admission.

Enterprise organization entitlements

Enterprise usage is pooled across active members and replaces the individual user quota template while the organization entitlement is active. An organization entitlement is active only while the organization and membership are active and the organization's entitlement expiration has not passed. Expired organizations are excluded from capture and shared-resource authorization as well as new upload selection.

LimitShared Enterprise SaaSDedicated Enterprise SaaS
Named users55
Capture upload10 GiB10 GiB
Active storage100 GiB250 GiB
Processed capture data/month250 GiB1 TiB
Weighted Agent units/month5002,000
Copilot messages/month2,50010,000
Automatic capture retentionOpt-in; suggested 30 daysOpt-in; suggested 90 days
Analysis capacityShared priority Agent and indexing queuesOne reserved Agent slot and one reserved indexing slot

An accepted full-processing ingest meters retained capture bytes once toward processed capture data; store-only ingestion meters zero. Each accepted explicit post-index, infrastructure-scan, or deferred-materialization operation meters one retained capture size. Failed queue admission does not count. Organization reprocessing requires an idempotency key; a committed replay does not count again and a pending replay is rejected. Contracted add-ons extend these pooled limits.

Runtime ceilings and exceptions

These rules are important because they affect real behavior now, even when older plan copy or legacy quota templates say something else.

RuleCurrent behaviorWhy it matters
Individual SaaS PCAP upload ceiling200 MB for Copilot Pro and Agent ProEnterprise organization upload limits come from the contracted organization entitlement instead of the individual-plan clamp.
Enterprise organization precedenceAn active Shared or Dedicated organization entitlement supplies the member's pooled upload, storage, processed-data, Agent, and Copilot limitsEnterprise members do not fall back to the smaller individual SaaS quota while the organization entitlement is active. The current Shared and Dedicated organization templates use a 10 GiB retained-capture upload limit, while the Flask and nginx outer request envelopes carry 12 GiB headroom so endpoint admission can enforce the contracted limit.
Paid-plan active datePaid SaaS feature access requires the user subscription code and deactivation/end date to still be activeDemo, trial, and migrated paid users can show a visible expiration date; after it passes, paid-plan feature access falls back instead of relying on the stored plan code alone.
On-prem PCAP upload ceilingValidated per deployment profileContract/SOW and support docs should state the tested profile envelope instead of relying on a generic public size claim.
Accepted capture upload types.pcap, .pcapng, .capUnsupported extensions are rejected before storage.
TLS key upload ceiling2 MB hard capTLS key uploads stay intentionally small even if PCAP uploads can be larger.
Agent Pro concurrent-session default1 active SaaS sessionOnly Agent Pro gets the default plan-enforced session limit.
Concurrent-session admin overrideAdmin can raise a SaaS user's limit to a specific numberThis override is stored per user.
Concurrent sessions on-premNot enforcedOn-prem deployments bypass the SaaS concurrent-session rule entirely.
On-prem Agent license exceptionAgent can be blocked even on-prem when the license token is invalid, unavailable, explicitly has Agent disabled, or has exhausted its weighted unitsThe SaaS subscription paywall is bypassed on-prem, but the deployment license is still authoritative. The standard Enterprise token includes 25 named users and 5,000 weighted Agent units per licensed deployment.
SaaS download entitlementRequires premium accessAnalyzer Free users do not get the paid download entitlement.
SaaS public-download exceptionPublic captures can still only be downloaded by the owner or adminsRead access to a public capture does not automatically allow download.
noAI capture tag exceptionNon-owners cannot download a capture tagged noAIThe owner can still download it.
noAI AI exceptionAI-assisted analysis and AI-derived packet insights are disabled for captures tagged noAIThis blocks Copilot/Agent/Quick Summary style AI paths and suppresses AI-derived packet insight polling in shared analyzer views. Manual packet analysis remains available according to the capture ACL.
Signed viewer-link scopeOnly the capture owner can create or revoke these links, and the shared session stays read-only for that captureRoles and public visibility do not grant signed-link management.
Background starter brief preferenceOff by default per user for private capturesPublic SaaS captures can auto-preview automatically; private captures require profile opt-in. This is separate from prompt-driven Agent uploads.
On-prem AI anonymizationNon-anonymized AI is blocked by defaultOn-prem admins can explicitly allow non-anonymized AI.

Upload-time AI behavior

Upload-time AI features are not one combined job:

FeatureWhat controls itNotes
Agent Starter BriefCapture AI eligibility, overview-context readiness, user background-starter preference for private captures, and deployment AI/anonymization policyGenerates in-app starter context and suggested Agent prompts. It is separate from Quick Summary and does not spend an Agent unit by itself.
Quick SummaryPremium/manual access for signed-in users, or anonymous email-summary opt-in with valid consent and remaining free-summary allowanceGenerates a lightweight structured capture summary. It does not automatically run for every authenticated upload.
Ask AI Agent runAgent entitlement, weighted Agent-unit availability, and the user's Ask AI upload selectionStarts the selected Agent workflow. Focused standard-model runs use 1 unit; Fast + verification and focused strongest-model runs use 2; deep strongest-model runs use 4.

When report email delivery is requested from the upload flow, PacketSafari stores the deferred launch and email delivery state with the capture. The visible status can move through waiting for the report, queueing, queued, sending, sent, failed, or skipped depending on whether the Agent report is saved and the mail provider accepts the message.

Deployment-wide switches that override user entitlements or access paths

Even a paid or admin user can be blocked or rerouted by deployment policy when one of these runtime switches is changed.

Runtime switchEffect
ENABLE_LOGINTurns the local username/password sign-in flow on or off
ENABLE_REGISTRATIONIn on-prem mode, allows or blocks direct self-registration
ENABLE_SOCIAL_LOGIN_OAUTHAllows or blocks GitHub and Google OAuth sign-in flows
ENABLE_SAAS_PAYWALLTurns the SaaS entitlement gate on or off for hosted deployments
ENABLE_UPLOADTurns authenticated uploads on or off for the deployment
ENABLE_ANON_UPLOADTurns anonymous upload intake on or off
ENABLE_BYO_OPENAI_API_KEYIn on-prem mode, allows admins to use their own OpenAI API key for AI access
ENABLE_CODEX_CHATGPT_LOGINIn on-prem mode, allows browser-based ChatGPT / Codex login for PacketSafari's native Codex runtime
ENABLE_CAPTURE_PROBESIn on-prem mode, enables capture probe enrollment and probe-driven collection workflows
CAPTURE_PROBES_REQUIRE_APPROVALKeeps newly enrolled probes pending until an admin approves them
DISABLE_ALL_AIHard-disables Copilot, Agent, Quick Insights, and background starter briefs
ENABLE_UPLOAD_INDEXING_SETTINGSEnables or disables advanced upload indexing controls
ENABLE_ANON_AGENT_REPORT_EMAILAllows anonymous/free Agent report delivery to an entered email address when mail delivery is configured
ON_PREM_ALLOW_NON_ANON_AIIn on-prem mode, allows AI on non-anonymized captures

Legacy plan-code notes

Current product behavior collapses several older internal subscription codes into the same entitlement buckets:

Entitlement bucketCurrent labelInternal codes currently mapped here
Analyzer FreeAnalyzer Freeunsubscribed_user
Copilot ProCopilot Procopilotmonthly2026, lowtiermonthly, lowtieryearly, lowtieryearlybundle
Agent ProAgent Proagentplusmonthly, agentplusyearly, agentproyearly2026
Legacy paid full accessLegacy paidlowtier, mediumtier, hightier, lowtierdaily
AdminAdmin (Unlimited)admin

Legacy paid plans are important operationally because they keep full feature access while active, but they do not all inherit the same quota template as current Copilot Pro or Agent Pro:

Legacy codeEffective feature accessStored quota nuance
lowtierdailyFull paid accessKeeps 4 monthly agent invocations and 1,000 monthly downloads
lowtierFull paid accessKeeps 4 monthly agent invocations and 1,000 monthly downloads
mediumtierFull paid accessKeeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads
hightierFull paid accessKeeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads

Treat those legacy codes as a feature-entitlement alias, not as a quota alias for Copilot Pro or Agent Pro.

Practical summary

  • If you are trying to explain AI access, use the entitlement tables above.
  • If you are trying to explain admin/operator permissions, use the admin-role rows.
  • If you are trying to explain who can open or modify a capture, use sharing roles and capture ACLs.
  • If a user says “my plan should allow this” but the feature is still unavailable, check deployment-wide runtime flags next.

Maintenance note

  • Changed in this pass: updated Shared and Dedicated Enterprise SaaS upload entitlement copy from 5 GiB to the code-backed 10 GiB, and documented the 12 GiB Flask/nginx outer envelope that lets endpoint admission enforce that contracted organization limit. Kept the recent upload wizard, Security-review full IDS behavior, progressive Agent email milestone, and Suricata ATT&CK wording because it already matched current code-backed behavior.
  • Verified against code: entitlement and concurrent-session policy in backend/packetsafari/entitlements.py, quota templates in backend/packetsafari/common/rate_limits.py, upload/download gates, organization upload-limit precedence, raw/free upload exception, deferred upload Agent launch normalization, and Security-review full IDS request handling in backend/packetsafari/resources/upload_combined.py, backend/packetsafari/resources/common.py, backend/packetsafari/captures/runtime_ingest.py, backend/packetsafari/common/config.py, and backend/config/render_nginx_site.sh; signed-share enforcement in backend/packetsafari/resources/captures.py and backend/packetsafari/common/signed_capture_viewer.py; starter-prompt auto-run policy in backend/packetsafari/ai/agent_starter_brief.py; runtime flag defaults in backend/packetsafari/common/admin_feature_flags.py; AI auth toggles in backend/packetsafari/resources/ai_auth.py; auth-entry/runtime login behavior in backend/packetsafari/resources/user.py; Agent report email and lane-cost gating in backend/packetsafari/resources/aichat.py; deferred report email state and SES bounds in backend/packetsafari/tasks/aichat_tasks.py and backend/packetsafari/email_delivery.py; active subscription/deactivation-date profile behavior in backend/packetsafari/storage/sql/services/users.py and frontend/app/utils/permissions.ts; lane display metadata in backend/packetsafari/ai/display_metadata.py and frontend/app/utils/ai-lanes.ts; extracted-object preview/download handling in backend/packetsafari/resources/sharkdmisc.py and frontend/app/components/analyze/FilesDashboard.vue; shared noAI UI handling in frontend/app/utils/no-ai.ts, frontend/app/components/analyze/UploadInsightsPanel.vue, frontend/app/components/analyze/PacketStats.vue, and frontend/app/components/analyze/PacketList.vue; Suricata ATT&CK and full IDS lifecycle behavior in backend/packetsafari/common/sharkd_ids_security.py, backend/packetsafari/resources/captures.py, and frontend/app/components/analyze/SecurityDashboard.vue; Citrix post-index detection in backend/packetsafari/common/protocol_postindex.py; and TCP incomplete-handshake fan-in detection in backend/packetsafari/tasks/packet_stats_tasks.py.
  • Remaining mismatch: non-KB pricing/strategy docs still contain mixed historical 5 GiB, 10 GiB, and qualified-capacity language. These four KB pages are now aligned to the current runtime templates and upload admission behavior.