Limits and quotas catalog
A single page for every hard number a customer might run into. If a setting has a default value, an expiry, a ceiling, or a window, it is in one of the tables below. This page does not document workflows. For the narratives, follow the linked deep-dive on each row.
For the rules engine behind these numbers (which job runs them, what the user sees when one fires), see Business rules catalog. For per-plan capabilities, see Plan feature matrix.
This is a reference index. Every number listed here is enforced by the platform, not configured per workspace, unless the row says otherwise.
Plan quotas
Every Retrievy plan caps seats and data sources. Both counters live on Billing Settings → Subscription Management.
| Limit | Essentials | Advanced | Build Your Own | Where it is set | Deep dive |
|---|---|---|---|---|---|
| Monthly price | $149 | $349 | from $400 (graduated per-source) | Workspace plan | Plans and pricing |
| Yearly price | $1,490 | $3,490 | monthly only | Workspace plan | Plans and pricing |
| Grandfathered Advanced price | n/a | $199 / month | n/a | Legacy Stripe price | Plan feature matrix |
| Seats (active users plus pending invitations) | 3 | 10 | up to 50 (slider) | Workspace plan | Seats and quotas |
| Data sources (cloud, AD domain, or FortiGate device) | 2 | 4 | up to 50 (slider) | Workspace plan | Seats and quotas |
| Concurrent scanners | 1 | 3 | 3 | Workspace plan | Business rules: scan rules |
| Concurrent processors | 1 | 3 | 3 | Workspace plan | Business rules: scan rules |
| Queue priority | best effort | standard | standard | Workspace plan | Business rules: scan rules |
| Finding retention | 90 days | 180 days | 180 days | Workspace plan | Seats and quotas |
The Phantom Slot rule means a data source that has scanned in the current billing cycle keeps its slot for the rest of the cycle even if you delete it. The slot frees automatically on the next monthly invoice. See Seats and quotas for the full overflow flow.
Agent fleet windows
The agent heartbeat cycle drives the Online / Offline badge on Settings → Agents and every fleet email. Recipients are users whose role includes Create, rotate, and revoke agent tokens.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Heartbeat send cadence | every 10 minutes | Agent process | Retrievy Agent fleet |
| Heartbeat check cadence | every 5 minutes | Platform scheduler | Business rules: agent fleet |
| Time after last heartbeat before badge flips to Offline | more than 20 minutes (two missed cycles) | Platform | Business rules: agent fleet |
| Time after last heartbeat before the first Agent Offline email | more than 1 hour | Platform | Business rules: agent fleet |
| Daily "still offline" reminder cadence | every 24 hours while offline | Platform | Business rules: agent fleet |
| Install token TTL (unredeemed) | 60 minutes | Platform | Agents |
Scan timeouts and limits
A scan that never finishes blocks the queue. These thresholds clean up stuck work and hold queue contention in check.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Stuck Pending scan timeout | 30 minutes | Platform | Business rules: scan rules |
| Stuck Running scan timeout | 4 hours | Platform | Business rules: scan rules |
| Reconciler deadline for orphaned scans | 90 minutes (5,400 seconds) | Platform | Business rules: scan rules |
| Cleanup pass cadence (catches stuck scans) | every 5 minutes | Platform scheduler | Business rules: scan rules |
| Daily scheduled scan time | 23:00 in the workspace timezone | Platform scheduler, workspace timezone | Business rules: scan rules |
| Synchronous scan timeout (small data sources) | up to 1 hour | Platform | n/a |
Drift alert windows
Drift alerts batch related cloud and on-prem changes into one email per workspace per window.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Roll-up window (events grouped into one notification) | 30 minutes from the first drift event | Platform | Business rules: drift alerts |
| Dispatcher cadence (when the email actually queues) | every 5 minutes | Platform scheduler | Business rules: drift alerts |
| Maximum delay from first event to email | 35 minutes | Platform | Business rules: drift alerts |
| Mutation rows per email | 60 (extras collapsed into a "+N more" tail) | Platform | Business rules: drift alerts |
| Drift history retention | 7 days | Platform | Business rules: drift alerts |
| Daily drift purge time | midnight in the workspace timezone | Platform scheduler | Business rules: drift alerts |
Security exception lifecycle
Security exceptions are time-bound. The reminder, the cleanup, and the cascade rules all key off the same expiry date.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Expiring exception reminder | sent when expiry is exactly 7 days away | Platform | Business rules: security exceptions |
| Reminder send time | 08:00 in the workspace timezone | Platform scheduler, workspace timezone | Security Exceptions |
| Cleanup pass (expired exceptions reopen findings) | runs daily at midnight in the workspace timezone, plus an hourly sweep | Platform scheduler | Business rules: security exceptions |
Stale claim and assignment
When a teammate sits on a claim too long, the assignment service releases it. The timeout is editable on Settings → General Settings.
| Limit | Default | Where it is set | Deep dive |
|---|---|---|---|
| Stale claim timeout (days) | 14 days | Settings → General Settings → Assignment & Attribution | Workspace settings |
| Stale claim sweep cadence | hourly per workspace | Platform scheduler | Business rules: assignment |
| Daily assignment digest send hour | 08:00 in the workspace timezone | Settings → General Settings | Workspace settings |
Authentication tokens, sessions, and 2FA
These are the timeouts and counts that control how long a sign-in artifact lasts.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Password reset link TTL | 60 minutes from issue | Platform auth config | Profile and 2FA |
| Password reset issue throttle (same user) | 60 seconds between requests | Platform auth config | Profile and 2FA |
| Password confirmation re-prompt | every 1 hour for sensitive actions | Platform auth config | n/a |
| Session lifetime (idle) | 120 minutes (2 hours) | Platform session config | n/a |
| Two-factor recovery codes generated per user | 8 codes | Generated on Settings → Password & 2FA → View recovery codes | Profile and 2FA |
Rate limits
Per-IP and per-session limits applied to authentication and tenant-provisioning endpoints. A request that exceeds the limit gets HTTP 429 with a Retry-After header.
| Endpoint | Limit | Scope | Deep dive |
|---|---|---|---|
| Login attempts | 5 per minute | per username + IP | Profile and 2FA |
| Two-factor challenge attempts | 5 per minute | per login session | Profile and 2FA |
| Password reset requests | 5 per minute | per IP | Profile and 2FA |
| Registration submissions | 10 per minute | per IP | Plans and pricing |
| OAuth callback hits | 20 per minute | per IP | Microsoft Entra ID SSO |
| Redeem-code preview and redemption | 10 per minute per IP, plus 30 per hour per user | per IP and per user | Plans and pricing |
| New workspace creation | 2 per minute per IP, plus 3 per hour per user | per IP and per user | Create your workspace |
Subscription and billing grace windows
When payment fails or the workspace owner cancels, Retrievy keeps data online for a set period.
| State | Grace window | What you keep | Deep dive |
|---|---|---|---|
| Past due (payment failed, in dunning) | 7 days | Read access to dashboards. Scans pause. Writes blocked. | Plans and pricing |
| Unpaid (dunning exhausted) | n/a | Read-only data, no sign-in. | Plans and pricing |
| Canceled | 30 days | Read-only data with the Reactivate Subscription banner. Falls back to Essentials after 30 days. | Plans and pricing |
FortiGate hygiene thresholds
These thresholds feed the FortiGate SCM module's hygiene score. None are configurable per workspace.
| Threshold | Value | Findings raised | Deep dive |
|---|---|---|---|
| Stale policy (no hits) | 90 days since last hit | Low severity | FortiGate |
| Zombie policy (zero hits since creation) | 0 hits, period | Medium severity | FortiGate |
| Empty object referenced by an active rule | n/a (presence check) | High severity | FortiGate |
| Shadowed policy (unreachable rule) | n/a (path analysis) | Medium severity | FortiGate |
Audit trail
The audit trail is available on Advanced and Build Your Own plans. Per-resource history is capped so the table stays performant.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Per-resource audit entries kept | 200 most recent | Platform | Audit trail |
| Audit trail availability | Advanced and Build Your Own only | Workspace plan | Plan feature matrix |
Reports
The Executive Report and Technical Report PDFs cap the embedded findings list so the PDF stays readable.
| Limit | Value | Where it is set | Deep dive |
|---|---|---|---|
| Technical Report PDF findings cap | 200 findings | Platform | Plan feature matrix |
| Executive Report PDF length | 6 pages (fixed layout) | Platform | Plan feature matrix |
Scoring thresholds
The grade bands the Retrievy Index projects to a letter, and the severity weights that drive the weighted failure count.
| Threshold | Value | Where it is set | Deep dive |
|---|---|---|---|
| Grade A | score 90 to 100 | Platform | Scoring rules catalog |
| Grade B | score 75 to 89.9 | Platform | Scoring rules catalog |
| Grade C | score 60 to 74.9 | Platform | Scoring rules catalog |
| Grade D | score 40 to 59.9 | Platform | Scoring rules catalog |
| Grade F | score below 40 | Platform | Scoring rules catalog |
| Critical severity weight | 100 | Platform | Scoring rules catalog |
| High severity weight | 20 | Platform | Scoring rules catalog |
| Medium severity weight | 5 | Platform | Scoring rules catalog |
| Low severity weight | 1 | Platform | Scoring rules catalog |
| Informational severity weight | 0 | Platform | Scoring rules catalog |