Subscription & enterprise

Read seat usage and edition details, and separate public CLI capabilities from optional enterprise components.

On this page

Subscription shows workspace edition and seat allocation. Owners, administrators, and billing users can read subscription information. Billing access does not grant access to agent activity or device management.

Understand seats

Allocated seats include memberships and unexpired pending invitations. Review the Members page before inviting a large group so you can account for reserved invitations as well as accepted teammates.

The subscription page shows allocated and available seats with edition details. Commercial activation, support, and invoicing terms are agreed with Beam; the current page does not collect payment or provide an automated checkout flow.

Public CLI and enterprise monitoring

The public @agent-beam/beam CLI provides local capture, Studio, offline scanning, and its implemented workspace connection/policy path. The optional proprietary beam-enterprise companion adds OS process/network observation where supported. Hook-based capture continues without that optional package.

Current enterprise source uses process and network inspection mechanisms such as ps and lsof. Installing the package is not proof of complete operating-system coverage, packet capture, or universal enforcement. Validate the target OS, package entitlement, running monitor, and observed event source before making a coverage claim.

The browser extension and MDM response channels have their own installation and authorization requirements. A subscription does not automatically enroll devices, install every integration, or include Fleet Premium.

Self-hosted licensing

The self-hosted dashboard uses an installation-bound signed license with edition, expiry, and seat count. Validation is offline using the publisher verification key baked into the image. An invalid or expired license stops new configuration, invitations, enrollment, and ingestion; history reading/export, risk review, and access revocation remain available.

Renew by following your deployment operator's license-replacement procedure. Recreate the dashboard container after replacing the license mount so it reads the intended file.

Plan a rollout

Discuss deployment boundaries, desired device coverage, retention, support, and recovery needs before activation. SAML/OIDC SSO, SCIM, MFA, automated retention jobs, SIEM push, high availability, and automated invoicing are not supplied by the current self-host bundle. Treat those requirements as separate implementation or operational decisions.

Explore the docs