User Types and Entitlements
This page is the current PacketSafari knowledge-base source of truth for who can do what.
Your effective access is shaped by six different layers:
| Layer | What it controls | Notes |
|---|---|---|
| Deployment mode | Whether the workspace is running in SaaS or on-prem mode | On-prem unlocks the SaaS AI paywall layer, but deployment-specific runtime controls still matter. |
| Organization entitlement | Enterprise Shared or Dedicated pooled capacity | An active organization entitlement takes precedence over a member's individual SaaS quota template. |
| Plan entitlement | Analyzer Free, Copilot Pro, Agent Pro, or legacy paid aliases | This controls AI entitlement and the user-record quota template while the subscription end date is still active. |
| On-prem license | Deployment identity, named users, Agent access, and weighted Agent units | A valid signed token is authoritative even though the SaaS paywall is bypassed. |
| Admin role | Access to the admin workspace and operator controls | Admin is a permission boundary, not just a billing label. |
| Sharing roles | Which users or role groups can read or write a capture | Roles control capture access, not billing or AI plan access. |
Legend
| Marker | Meaning |
|---|---|
| ✅ | Included / full access |
| 👀 | Preview / limited access |
| 🔒 | Blocked or upgrade required |
| 🛠️ | Admin only |
| 🏢 | On-prem only |
| ⚙️ | Depends on deployment flags, capture state, or admin override |
Current user types
| User type | Where it exists | How it is assigned | What it mainly changes |
|---|---|---|---|
| Analyzer Free | SaaS | No active paid subscription | Preview Copilot/security/connection access, lower quota template, no Agent or paid download entitlement |
| Copilot Pro | SaaS | Active Copilot subscription or legacy Copilot-equivalent paid plan | Full Copilot, security, advanced connections, and OT analysis; Agent still locked |
| Agent Pro | SaaS | Active Agent subscription | Full AI access, 50 weighted Agent units/month template, default 1 active session |
| Admin | SaaS or on-prem | Membership in the admin role | Admin workspace access, paywall bypass, operator controls |
| On-prem user | On-prem | Normal signed-in user in an on-prem deployment | SaaS paywall is bypassed for feature entitlements |
| On-prem admin | On-prem | Admin-role user in an on-prem deployment | On-prem feature entitlements plus admin workspace and deployment controls |
Capability matrix
| Capability | SaaS Analyzer Free | SaaS Copilot Pro | SaaS Agent Pro | SaaS Admin | On-prem user | On-prem admin | Notes |
|---|---|---|---|---|---|---|---|
| Manual packet analysis | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | Core analyzer access is not paywalled. |
| Upload PCAPs | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | Deployment-wide upload flags can still disable uploads for everyone. |
| Share captures with users and roles | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ | Sharing roles control capture ACLs, not plan entitlements. |
| Copilot chat | 👀 | ✅ | ✅ | ✅ | ✅ | ✅ | Free SaaS stays in preview mode. |
| Agent runs | 🔒 | 🔒 | ✅ | ✅ | ⚙️ | ⚙️ | SaaS users need Agent Pro or an active Enterprise organization entitlement for autonomous Agent runs. On-prem Agent access bypasses the SaaS paywall, but can still be blocked by an invalid license, disabled Agent entitlement, or exhausted deployment units. |
| Security insights | 👀 | ✅ | ✅ | ✅ | ✅ | ✅ | Free preview keeps only limited/redacted security detail. |
| Advanced connections | 👀 | ✅ | ✅ | ✅ | ✅ | ✅ | Free preview keeps only limited correlated connection detail. |
| OT analysis | 🔒 | ✅ | ✅ | ✅ | ✅ | ✅ | OT analysis is blocked for free SaaS users. |
| Download owned PCAPs | 🔒 | ✅ | ✅ | ✅ | ✅ | ✅ | SaaS downloads require premium access; on-prem bypasses the SaaS subscription gate. |
| Signed anonymous viewer links for private captures | 🔒 | 🔒 | ✅ | ✅ | ✅ | ✅ | Owner-only, read-only, time-limited share links without making the capture public. Legacy paid full-access SaaS plans also retain this entitlement while active. |
| Admin workspace | 🔒 | 🔒 | 🔒 | 🛠️ | 🔒 | 🛠️ | Admin access is role-based. |
| User directory and security management | 🔒 | 🔒 | 🔒 | 🛠️ | 🔒 | 🛠️ | Includes user/session/security operations. |
| On-prem deployment and updates pages | n/a | n/a | n/a | n/a | 🔒 | 🛠️ | These pages are only meaningful in on-prem deployments. |
| SAML / OIDC browser SSO | n/a | n/a | n/a | n/a | 🏢 | 🏢 | Available in on-prem mode only. |
| SCIM provisioning | n/a | n/a | n/a | n/a | 🏢 | 🏢 | Available in on-prem mode only. |
| Local / on-prem AI provider configuration | n/a | n/a | n/a | n/a | 🔒 | 🛠️ | On-prem admins can configure local AI endpoints and egress approvals. |
Current plan-to-feature entitlement mapping
| Feature | Analyzer Free | Copilot Pro | Agent Pro | Admin | On-prem |
|---|---|---|---|---|---|
| Copilot | 👀 | ✅ | ✅ | ✅ | ✅ |
| Agent | 🔒 | 🔒 | ✅ | ✅ | ⚙️ |
| Security | 👀 | ✅ | ✅ | ✅ | ✅ |
| Advanced connections | 👀 | ✅ | ✅ | ✅ | ✅ |
| OT analysis | 🔒 | ✅ | ✅ | ✅ | ✅ |
User-record quota templates
These are the current quota values attached to user records and shown in account/admin quota views.
| Limit | Analyzer Free | Copilot Pro | Agent Pro | Admin | Notes |
|---|---|---|---|---|---|
| Max storage total | 5 MB | 3,000 MB | 20,480 MB | ∞ | Storage shown in the profile/admin quota cards. |
| Max files total | 10 | 1,000 | 1,000 | ∞ | Total captures owned by the user. |
| Max files per month | 10 | 500 | 200 | ∞ | Upload count quota template. |
| Max downloads per month | 100 | 500 | 500 | ∞ | Download count quota template. |
| Max indexing per month | 10 | 1,000 | 1,000 | ∞ | Indexing job quota template. |
| Max weighted Agent units per month | 0 | 0 | 50 | ∞ | Focused standard-model runs use 1 unit; Fast + verification and focused strongest-model runs use 2; deep strongest-model runs use 4. |
| User-record max upload file size | 1 MB | 200 MB | 200 MB | ∞ | Hosted launch quota for SaaS upload admission. |
Enterprise organization entitlements
Enterprise usage is pooled across active members and replaces the individual user quota template while the organization entitlement is active. An organization entitlement is active only while the organization and membership are active and the organization's entitlement expiration has not passed. Expired organizations are excluded from capture and shared-resource authorization as well as new upload selection.
| Limit | Shared Enterprise SaaS | Dedicated Enterprise SaaS |
|---|---|---|
| Named users | 5 | 5 |
| Capture upload | 10 GiB | 10 GiB |
| Active storage | 100 GiB | 250 GiB |
| Processed capture data/month | 250 GiB | 1 TiB |
| Weighted Agent units/month | 500 | 2,000 |
| Copilot messages/month | 2,500 | 10,000 |
| Automatic capture retention | Opt-in; suggested 30 days | Opt-in; suggested 90 days |
| Analysis capacity | Shared priority Agent and indexing queues | One reserved Agent slot and one reserved indexing slot |
An accepted full-processing ingest meters retained capture bytes once toward processed capture data; store-only ingestion meters zero. Each accepted explicit post-index, infrastructure-scan, or deferred-materialization operation meters one retained capture size. Failed queue admission does not count. Organization reprocessing requires an idempotency key; a committed replay does not count again and a pending replay is rejected. Contracted add-ons extend these pooled limits.
Runtime ceilings and exceptions
These rules are important because they affect real behavior now, even when older plan copy or legacy quota templates say something else.
| Rule | Current behavior | Why it matters |
|---|---|---|
| Individual SaaS PCAP upload ceiling | 200 MB for Copilot Pro and Agent Pro | Enterprise organization upload limits come from the contracted organization entitlement instead of the individual-plan clamp. |
| Enterprise organization precedence | An active Shared or Dedicated organization entitlement supplies the member's pooled upload, storage, processed-data, Agent, and Copilot limits | Enterprise members do not fall back to the smaller individual SaaS quota while the organization entitlement is active. The current Shared and Dedicated organization templates use a 10 GiB retained-capture upload limit, while the Flask and nginx outer request envelopes carry 12 GiB headroom so endpoint admission can enforce the contracted limit. |
| Paid-plan active date | Paid SaaS feature access requires the user subscription code and deactivation/end date to still be active | Demo, trial, and migrated paid users can show a visible expiration date; after it passes, paid-plan feature access falls back instead of relying on the stored plan code alone. |
| On-prem PCAP upload ceiling | Validated per deployment profile | Contract/SOW and support docs should state the tested profile envelope instead of relying on a generic public size claim. |
| Accepted capture upload types | .pcap, .pcapng, .cap | Unsupported extensions are rejected before storage. |
| TLS key upload ceiling | 2 MB hard cap | TLS key uploads stay intentionally small even if PCAP uploads can be larger. |
| Agent Pro concurrent-session default | 1 active SaaS session | Only Agent Pro gets the default plan-enforced session limit. |
| Concurrent-session admin override | Admin can raise a SaaS user's limit to a specific number | This override is stored per user. |
| Concurrent sessions on-prem | Not enforced | On-prem deployments bypass the SaaS concurrent-session rule entirely. |
| On-prem Agent license exception | Agent can be blocked even on-prem when the license token is invalid, unavailable, explicitly has Agent disabled, or has exhausted its weighted units | The SaaS subscription paywall is bypassed on-prem, but the deployment license is still authoritative. The standard Enterprise token includes 25 named users and 5,000 weighted Agent units per licensed deployment. |
| SaaS download entitlement | Requires premium access | Analyzer Free users do not get the paid download entitlement. |
| SaaS public-download exception | Public captures can still only be downloaded by the owner or admins | Read access to a public capture does not automatically allow download. |
noAI capture tag exception | Non-owners cannot download a capture tagged noAI | The owner can still download it. |
noAI AI exception | AI-assisted analysis and AI-derived packet insights are disabled for captures tagged noAI | This blocks Copilot/Agent/Quick Summary style AI paths and suppresses AI-derived packet insight polling in shared analyzer views. Manual packet analysis remains available according to the capture ACL. |
| Signed viewer-link scope | Only the capture owner can create or revoke these links, and the shared session stays read-only for that capture | Roles and public visibility do not grant signed-link management. |
| Background starter brief preference | Off by default per user for private captures | Public SaaS captures can auto-preview automatically; private captures require profile opt-in. This is separate from prompt-driven Agent uploads. |
| On-prem AI anonymization | Non-anonymized AI is blocked by default | On-prem admins can explicitly allow non-anonymized AI. |
Upload-time AI behavior
Upload-time AI features are not one combined job:
| Feature | What controls it | Notes |
|---|---|---|
| Agent Starter Brief | Capture AI eligibility, overview-context readiness, user background-starter preference for private captures, and deployment AI/anonymization policy | Generates in-app starter context and suggested Agent prompts. It is separate from Quick Summary and does not spend an Agent unit by itself. |
| Quick Summary | Premium/manual access for signed-in users, or anonymous email-summary opt-in with valid consent and remaining free-summary allowance | Generates a lightweight structured capture summary. It does not automatically run for every authenticated upload. |
| Ask AI Agent run | Agent entitlement, weighted Agent-unit availability, and the user's Ask AI upload selection | Starts the selected Agent workflow. Focused standard-model runs use 1 unit; Fast + verification and focused strongest-model runs use 2; deep strongest-model runs use 4. |
When report email delivery is requested from the upload flow, PacketSafari stores the deferred launch and email delivery state with the capture. The visible status can move through waiting for the report, queueing, queued, sending, sent, failed, or skipped depending on whether the Agent report is saved and the mail provider accepts the message.
Deployment-wide switches that override user entitlements or access paths
Even a paid or admin user can be blocked or rerouted by deployment policy when one of these runtime switches is changed.
| Runtime switch | Effect |
|---|---|
ENABLE_LOGIN | Turns the local username/password sign-in flow on or off |
ENABLE_REGISTRATION | In on-prem mode, allows or blocks direct self-registration |
ENABLE_SOCIAL_LOGIN_OAUTH | Allows or blocks GitHub and Google OAuth sign-in flows |
ENABLE_SAAS_PAYWALL | Turns the SaaS entitlement gate on or off for hosted deployments |
ENABLE_UPLOAD | Turns authenticated uploads on or off for the deployment |
ENABLE_ANON_UPLOAD | Turns anonymous upload intake on or off |
ENABLE_BYO_OPENAI_API_KEY | In on-prem mode, allows admins to use their own OpenAI API key for AI access |
ENABLE_CODEX_CHATGPT_LOGIN | In on-prem mode, allows browser-based ChatGPT / Codex login for PacketSafari's native Codex runtime |
ENABLE_CAPTURE_PROBES | In on-prem mode, enables capture probe enrollment and probe-driven collection workflows |
CAPTURE_PROBES_REQUIRE_APPROVAL | Keeps newly enrolled probes pending until an admin approves them |
DISABLE_ALL_AI | Hard-disables Copilot, Agent, Quick Insights, and background starter briefs |
ENABLE_UPLOAD_INDEXING_SETTINGS | Enables or disables advanced upload indexing controls |
ENABLE_ANON_AGENT_REPORT_EMAIL | Allows anonymous/free Agent report delivery to an entered email address when mail delivery is configured |
ON_PREM_ALLOW_NON_ANON_AI | In on-prem mode, allows AI on non-anonymized captures |
Legacy plan-code notes
Current product behavior collapses several older internal subscription codes into the same entitlement buckets:
| Entitlement bucket | Current label | Internal codes currently mapped here |
|---|---|---|
| Analyzer Free | Analyzer Free | unsubscribed_user |
| Copilot Pro | Copilot Pro | copilotmonthly2026, lowtiermonthly, lowtieryearly, lowtieryearlybundle |
| Agent Pro | Agent Pro | agentplusmonthly, agentplusyearly, agentproyearly2026 |
| Legacy paid full access | Legacy paid | lowtier, mediumtier, hightier, lowtierdaily |
| Admin | Admin (Unlimited) | admin |
Legacy paid plans are important operationally because they keep full feature access while active, but they do not all inherit the same quota template as current Copilot Pro or Agent Pro:
| Legacy code | Effective feature access | Stored quota nuance |
|---|---|---|
lowtierdaily | Full paid access | Keeps 4 monthly agent invocations and 1,000 monthly downloads |
lowtier | Full paid access | Keeps 4 monthly agent invocations and 1,000 monthly downloads |
mediumtier | Full paid access | Keeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads |
hightier | Full paid access | Keeps unlimited (-1) monthly agent invocations and 1,000 monthly downloads |
Treat those legacy codes as a feature-entitlement alias, not as a quota alias for Copilot Pro or Agent Pro.
Practical summary
- If you are trying to explain AI access, use the entitlement tables above.
- If you are trying to explain admin/operator permissions, use the admin-role rows.
- If you are trying to explain who can open or modify a capture, use sharing roles and capture ACLs.
- If a user says “my plan should allow this” but the feature is still unavailable, check deployment-wide runtime flags next.
Maintenance note
- Changed in this pass: updated Shared and Dedicated Enterprise SaaS upload entitlement copy from
5 GiBto the code-backed10 GiB, and documented the12 GiBFlask/nginx outer envelope that lets endpoint admission enforce that contracted organization limit. Kept the recent upload wizard, Security-review full IDS behavior, progressive Agent email milestone, and Suricata ATT&CK wording because it already matched current code-backed behavior. - Verified against code: entitlement and concurrent-session policy in
backend/packetsafari/entitlements.py, quota templates inbackend/packetsafari/common/rate_limits.py, upload/download gates, organization upload-limit precedence, raw/free upload exception, deferred upload Agent launch normalization, and Security-review full IDS request handling inbackend/packetsafari/resources/upload_combined.py,backend/packetsafari/resources/common.py,backend/packetsafari/captures/runtime_ingest.py,backend/packetsafari/common/config.py, andbackend/config/render_nginx_site.sh; signed-share enforcement inbackend/packetsafari/resources/captures.pyandbackend/packetsafari/common/signed_capture_viewer.py; starter-prompt auto-run policy inbackend/packetsafari/ai/agent_starter_brief.py; runtime flag defaults inbackend/packetsafari/common/admin_feature_flags.py; AI auth toggles inbackend/packetsafari/resources/ai_auth.py; auth-entry/runtime login behavior inbackend/packetsafari/resources/user.py; Agent report email and lane-cost gating inbackend/packetsafari/resources/aichat.py; deferred report email state and SES bounds inbackend/packetsafari/tasks/aichat_tasks.pyandbackend/packetsafari/email_delivery.py; active subscription/deactivation-date profile behavior inbackend/packetsafari/storage/sql/services/users.pyandfrontend/app/utils/permissions.ts; lane display metadata inbackend/packetsafari/ai/display_metadata.pyandfrontend/app/utils/ai-lanes.ts; extracted-object preview/download handling inbackend/packetsafari/resources/sharkdmisc.pyandfrontend/app/components/analyze/FilesDashboard.vue; sharednoAIUI handling infrontend/app/utils/no-ai.ts,frontend/app/components/analyze/UploadInsightsPanel.vue,frontend/app/components/analyze/PacketStats.vue, andfrontend/app/components/analyze/PacketList.vue; Suricata ATT&CK and full IDS lifecycle behavior inbackend/packetsafari/common/sharkd_ids_security.py,backend/packetsafari/resources/captures.py, andfrontend/app/components/analyze/SecurityDashboard.vue; Citrix post-index detection inbackend/packetsafari/common/protocol_postindex.py; and TCP incomplete-handshake fan-in detection inbackend/packetsafari/tasks/packet_stats_tasks.py. - Remaining mismatch: non-KB pricing/strategy docs still contain mixed historical
5 GiB,10 GiB, and qualified-capacity language. These four KB pages are now aligned to the current runtime templates and upload admission behavior.
