Enterprise licensing built for
autonomous workforces.
One annual enterprise agreement provides IntentGrant, IntentGate, Built-in Proof, enterprise support and production capacity. Human participation is included, with no per-seat licensing. As your autonomous workforce grows, capacity scales predictably across two measures: Governed Agents and MAPA. No per-call, token, bandwidth or transaction-volume fees.
- ✓ IntentGrant & IntentGate: Full production platforms, included.
- ✓ Built-in Proof: Signed execution evidence, standard.
- ✓ Unlimited human participation: Owners, approvers, reviewers and delegators, with no per-seat licensing.
- ✓ Production capacity included: Governance and runtime capacity from day one.
- ✓ Enterprise support and SLA: Updates and security patches included.
- ✓ Counts only when governed: One agent counts only when all three are active: a defined purpose, an accountable owner and an active authority bundle.
- ✓ Not governed = not counted: Discovered, unassigned, draft, suspended and retired agents do not consume capacity.
- ✓ Humans are never metered: Owners, approvers and delegators are included and never consume agent capacity.
- ✓ Capacity, not named licences: When an agent leaves active governance, that capacity becomes available for another agent.
- ✓ Presence, not volume: One decision or millions still count as one MAPA for that stable agent.
- ✓ No API or token tax: No per-call, token, bandwidth or transaction-volume fees.
- ✓ Stable identities only: Ephemeral pods and retries never multiply the count.
- ✓ Built-in Proof on every decision: Signed Ed25519 evidence, natively.
Enterprise Licensing Principles
Governed Agents + MAPA. Measured locally. Cryptographically verifiable. No customer runtime data required.
🔍 Active Governance, Not Discovery
IntentGrant counts an agent only while three governance conditions are active: a defined purpose, an accountable owner and an active authority bundle. Discovery, draft configuration, suspension or retirement does not consume Governed Agent capacity. Human owners, approvers and delegators are included with no per-seat charge.
⚖️ Stable Workload Identities
IntentGate measures Monthly Active Protected Agents (MAPA) based on stable identities (like a SPIFFE ID or service account). Twenty ephemeral Kubernetes pods representing the same governed agent count as exactly one MAPA. 1 decision or 5 million decisions = 1 MAPA.
🛡️ Security Never Fails Open
Commercial limits never disable security enforcement. If usage exceeds the contracted commitment, IntentGate continues protecting every agent. Overage is recorded locally and reconciled through commercial true-up, never by failing open or disabling authorization.
📄 Zero-Telemetry Billing
Licensing is verifiable without sending us your data. The meter runs locally in your VPC. At the agreed reporting interval, it produces a tamper-evident, Ed25519-signed statement containing only aggregate commercial counters (Governed Agents and MAPA). Prompts, payloads, policies, audit events and transaction values remain inside your environment.
Verifiable billing. Zero customer telemetry.
The licence meter runs locally in your environment. It measures only the commercial units required for the agreement and produces a signed, tamper-evident aggregate statement. Runtime content never needs to leave your network.
Frequently Asked Questions
Do I pay per API request or authorization call?
No. IntentGate is licensed by Monthly Active Protected Agents (MAPA). If an agent passes through IntentGate during the month, it counts as one protected agent. Whether that agent makes 100 or 1,000,000 authorization decisions, there is no additional per-call fee. You are not taxed on transaction volume.
How do you measure usage if IntentGate is 100% VPC-Native?
We use a privacy-preserving local license counter. The meter runs entirely inside your VPC. IntentGate never receives your prompts, payloads, or audit logs. At true-up intervals, the system generates an aggregate statement (e.g., "IntentGrant governed agents: 4,721. Human owners & approvers: Included. IntentGate MAPA: 638. Runtime data: Not reported.").
What is the difference between an IntentGrant and IntentGate license?
IntentGrant licenses authority under governance. An agent counts as one Governed Agent only while it has all three: a defined purpose, an accountable owner and an active authority bundle. Discovery alone does not count, and suspended or retired agents release that capacity. Human owners and approvers are included. IntentGate licenses authority exercised at runtime: stable autonomous identities that receive at least one enforced runtime decision during the month. You can govern 3,000 agents in IntentGrant while only 800 are active under IntentGate runtime protection.
Do I need to buy Built-in Proof separately?
No. Built-in Proof is natively included with any IntentGate data plane license. Every decision the proxy makes automatically generates cryptographically signed (Ed25519) evidence that you can route to your own SIEM or data lake.