Skip to main content

Seats and data-source quotas

Every Retrievy plan caps two things: how many people can sign in to your workspace, and how many data sources you can scan. This page explains how each counter works, what happens when you cross either limit, and how to clean up after a downgrade.

For the per-plan numbers, see the plan feature matrix. For the subscription flow, see Manage your subscription.

Before you start

  • You need to be the workspace owner to upgrade or resize the plan. Adding seats or sources at the limit always routes through billing, and only the owner can act on billing.
  • A workspace admin with the Users permission can invite users and remove them, but cannot change the plan tier.
  • The seat and source counters live inside the tenant workspace, so you must be signed in to the workspace (not the central account dashboard) to see them.

What counts as a seat or data source

A seat is one invited user. Both active users (anyone who has accepted their invite and can sign in) and pending invitations (people you have invited who have not accepted yet) count against the seat limit. The counter goes up the moment you send the invite, not when the recipient clicks the link. Invitations that expire stop counting automatically.

A data source is one connected target. A data source is whichever of these the workspace owns:

  • One cloud account (AWS, Azure, GCP, OCI, Microsoft 365, Cloudflare, or Kubernetes). One cloud account is one slot, regardless of how many regions or services it covers.
  • One Active Directory domain. Each domain is one slot. The agents you install on domain controllers do not consume slots; they all funnel into the same domain.
  • One FortiGate device. Each device is one slot.

The counter is built on what Retrievy calls the Phantom Slot rule: once a source has run a scan in the current billing cycle, it holds its slot for the rest of that cycle even if you delete it. The slot frees up automatically when the cycle rolls over (when Stripe issues the next monthly invoice). This stops the workspace from churning through slots inside a single billing month.

Quotas per plan

PlanSeatsData sources
Essentials ($149 / month)32
Advanced ($349 / month)104
Build Your Own (from $400 / month)up to 50 (slider)up to 50 (slider)

Build Your Own uses two sliders on the Subscription Management page: one for Data Sources, one for User Seats. The new totals take effect the moment Stripe confirms the change.

Owner is always preserved

The workspace owner counts toward the seat limit but is never locked out by a downgrade. If a plan change would push the owner over the cap, every other user gets locked first.

Adding seats or sources

You add seats by inviting users. Open Settings > Team Members and click Invite User. The seat meter at the top of the page reads <used> / <max> seats used and shows how many seats remain underneath:

<remaining> seats available. Includes active users and pending invitations.

You add a data source by connecting it from the relevant integration page (for example Connect an AWS account or Connect FortiGate). The data-source counter is enforced inside each connection wizard; you do not see a single combined meter.

To raise either limit, open Billing in the workspace menu and either switch to a higher tier or drag the Build Your Own sliders on the Subscription Management page. See Manage your subscription for the full flow, including the prorated charge preview.

Hitting the limit

Seat ceiling

When the seat counter reaches the cap, the Invite User button on Team Members disables itself. Its label changes to read Seat Limit Reached: Upgrade, and clicking it routes to the billing page. The seat meter turns red and the inline message reads:

Seat limit reached on the <plan name> plan. Upgrade your plan to invite more team members.

The seat counter goes up at invite time, not acceptance. If you have one slot left and invite two people in quick succession, the second invite is rejected with the same message. Cancel a pending invitation from the Team Members list to free its slot.

Data-source ceiling

The data-source ceiling is enforced inside each integration wizard. When you try to add a cloud account at the limit, the second step of the wizard is replaced by a Slot Limit Reached panel:

Your current plan has no remaining data source slots.

The FortiGate setup page shows the same panel with a <used> / <max> used counter and a one-line reminder:

Deleting a previously scanned device will not free the slot until your billing cycle resets.

That reminder is the Phantom Slot rule in action. To free a slot inside the current cycle, either upgrade the plan or contact support to force a recompute.

Resolving overflow after a downgrade

When you switch to a smaller plan (or shrink Build Your Own), Retrievy does not delete anything. It locks the surplus. The locked items stay on disk with their full configuration and findings, ready to be restored the moment you free space.

The lock rule is most recent first. Retrievy sorts your seats and your data sources by creation date and locks whichever was added latest, until the active count fits the new plan. The workspace owner is always excluded.

Right after the downgrade processes, you see an amber banner at the top of every page:

You're over your plan limits

<N> data source(s) paused and <M> user seat(s) suspended due to plan downgrade. Choose which to keep active or upgrade your plan to restore them all.

The banner carries a Manage button. Click it to open the overflow workspace, which has two sections:

  • Locked Data Sources with a <active> / <max> active counter on the right. Each row lists the source name, its type, and how long it has been paused. Two actions: Unlock (only available when there is headroom under the cap) and Remove.
  • Suspended Seats with the same <active> / <max> active counter. Each user row shows the name, email, and how long ago the seat was suspended. The action is Restore Seat.

You have three ways to clear the overflow:

  1. Upgrade the plan so the cap fits everything. Retrievy auto-rebalances: the oldest-locked items get restored first, in the order they were locked, until the cap is hit again.
  2. Pick what to keep. Open the overflow workspace. Remove items you no longer need; that frees a slot, which immediately becomes available for Unlock on a different locked item. Use this when you want to keep an older source but drop a newer one.
  3. Do nothing. Locked items stay locked. Findings on them age out per the new plan's retention window (Essentials at 90 days, Advanced and Build Your Own at 180 days).

How the auto-rebalance works

Whenever an item is removed or the plan resizes, Retrievy re-runs the lock pass. The pass works in two directions:

  • If the active count now exceeds the new cap, lock the most recently added items until it fits.
  • If the cap now exceeds the active count, unlock the oldest-locked items until the cap is full.

This is what makes upgrades reversible. Upgrade back to the plan you came from and the same items unlock in the same order they were locked.

Locked vs deleted

The distinction matters. Locked is not deleted.

StateData on diskScans runFindings visibleScore still counted
Active data sourceYesYesYesYes
Locked (paused) data sourceYesNoYes (frozen at last scan)Yes (but stops moving)
Removed data sourceNo (soft-deleted; the slot frees on the next billing cycle)NoNoNo
Active seatYesn/an/an/a
Suspended seatYes (account, assignments, comments)n/an/an/a
Removed seatAccount membership revoked; central account survivesn/an/an/a

A suspended user keeps their account, their assignments, their comments, and any audit history. They can't sign in until you restore the seat. A removed user is detached from the workspace, but their central Retrievy account is not deleted.

A locked data source keeps every finding it has ever produced. It just stops scanning. The next time you unlock it, scans resume on the normal schedule.

Removal is reversible only by re-adding

Remove soft-deletes the data source. You can reconnect it later from the same integration wizard. The slot frees on the next billing cycle, not immediately.

How this affects your Retrievy Index

Locked data sources stop producing findings. That has two visible effects on your Retrievy Index:

  • Per-module score freezes. The module that owns the locked source (CSPM for cloud, ISPM for IAM workloads, SCM for Active Directory and FortiGate) keeps the score from the last successful scan. It will not move until you unlock the source or remove it.
  • Global score stays weighted. The locked source still contributes its frozen value to the global Retrievy Index until you remove it. If you remove it, the module re-aggregates over the remaining sources at the next scoring pass.

Suspended seats have no effect on the score. The score reflects security posture, not how many people can sign in.

If a locked source carried Critical or High findings, those still count toward the weighted-failure portion of the formula until they age out per the new plan's retention window. The exact weights are in the scoring rules catalog; the math is in How the Retrievy Index is calculated.

Troubleshooting

Symptom: I removed a pending invitation but the seat counter has not gone down.

  • Fix: The counter recomputes on the next page load. Reload Team Members. If the seat is still held, the invite was probably accepted in the meantime; check the active users list.

Symptom: I deleted a cloud account but the Slot Limit Reached panel still appears when I try to add a new one.

  • Fix: That is the Phantom Slot rule. A source that scanned this billing cycle holds its slot until the cycle rolls over. Wait for the next monthly invoice, upgrade the plan to free headroom now, or contact support to force a recompute.

Symptom: I downgraded from Advanced to Essentials and the dashboard hides everything except a banner.

  • Fix: The downgrade locked the surplus data sources and suspended the surplus seats. Click Manage on the banner to open the overflow workspace. Either upgrade back, or pick which items to keep.

Symptom: I just upgraded back to Advanced but several sources are still showing Locked.

  • Fix: The auto-rebalance only unlocks up to the new cap. If you locked five sources on Essentials and upgraded to Advanced (4 slots), only three are restored. Either upgrade further or remove the items you no longer need.

Symptom: A user I suspended still appears in the Team Members list.

  • Fix: Suspended users stay listed so you can restore them. They cannot sign in. To remove the account from the workspace, use Remove on the user row.

Symptom: I clicked Unlock on a locked source and got No headroom. Remove or unlock another source first.

  • Fix: Your active count is already at the cap. Remove or lock another source, or upgrade the plan.