Skip to main content

Limits and quotas catalog

A single page for every hard number a customer might run into. If a setting has a default value, an expiry, a ceiling, or a window, it is in one of the tables below. This page does not document workflows. For the narratives, follow the linked deep-dive on each row.

For the rules engine behind these numbers (which job runs them, what the user sees when one fires), see Business rules catalog. For per-plan capabilities, see Plan feature matrix.

No UI on this page

This is a reference index. Every number listed here is enforced by the platform, not configured per workspace, unless the row says otherwise.

Plan quotas

Every Retrievy plan caps seats and data sources. Both counters live on Billing Settings → Subscription Management.

LimitEssentialsAdvancedBuild Your OwnWhere it is setDeep dive
Monthly price$149$349from $400 (graduated per-source)Workspace planPlans and pricing
Yearly price$1,490$3,490monthly onlyWorkspace planPlans and pricing
Grandfathered Advanced pricen/a$199 / monthn/aLegacy Stripe pricePlan feature matrix
Seats (active users plus pending invitations)310up to 50 (slider)Workspace planSeats and quotas
Data sources (cloud, AD domain, or FortiGate device)24up to 50 (slider)Workspace planSeats and quotas
Concurrent scanners133Workspace planBusiness rules: scan rules
Concurrent processors133Workspace planBusiness rules: scan rules
Queue prioritybest effortstandardstandardWorkspace planBusiness rules: scan rules
Finding retention90 days180 days180 daysWorkspace planSeats and quotas

The Phantom Slot rule means a data source that has scanned in the current billing cycle keeps its slot for the rest of the cycle even if you delete it. The slot frees automatically on the next monthly invoice. See Seats and quotas for the full overflow flow.

Agent fleet windows

The agent heartbeat cycle drives the Online / Offline badge on Settings → Agents and every fleet email. Recipients are users whose role includes Create, rotate, and revoke agent tokens.

LimitValueWhere it is setDeep dive
Heartbeat send cadenceevery 10 minutesAgent processRetrievy Agent fleet
Heartbeat check cadenceevery 5 minutesPlatform schedulerBusiness rules: agent fleet
Time after last heartbeat before badge flips to Offlinemore than 20 minutes (two missed cycles)PlatformBusiness rules: agent fleet
Time after last heartbeat before the first Agent Offline emailmore than 1 hourPlatformBusiness rules: agent fleet
Daily "still offline" reminder cadenceevery 24 hours while offlinePlatformBusiness rules: agent fleet
Install token TTL (unredeemed)60 minutesPlatformAgents

Scan timeouts and limits

A scan that never finishes blocks the queue. These thresholds clean up stuck work and hold queue contention in check.

LimitValueWhere it is setDeep dive
Stuck Pending scan timeout30 minutesPlatformBusiness rules: scan rules
Stuck Running scan timeout4 hoursPlatformBusiness rules: scan rules
Reconciler deadline for orphaned scans90 minutes (5,400 seconds)PlatformBusiness rules: scan rules
Cleanup pass cadence (catches stuck scans)every 5 minutesPlatform schedulerBusiness rules: scan rules
Daily scheduled scan time23:00 in the workspace timezonePlatform scheduler, workspace timezoneBusiness rules: scan rules
Synchronous scan timeout (small data sources)up to 1 hourPlatformn/a

Drift alert windows

Drift alerts batch related cloud and on-prem changes into one email per workspace per window.

LimitValueWhere it is setDeep dive
Roll-up window (events grouped into one notification)30 minutes from the first drift eventPlatformBusiness rules: drift alerts
Dispatcher cadence (when the email actually queues)every 5 minutesPlatform schedulerBusiness rules: drift alerts
Maximum delay from first event to email35 minutesPlatformBusiness rules: drift alerts
Mutation rows per email60 (extras collapsed into a "+N more" tail)PlatformBusiness rules: drift alerts
Drift history retention7 daysPlatformBusiness rules: drift alerts
Daily drift purge timemidnight in the workspace timezonePlatform schedulerBusiness rules: drift alerts

Security exception lifecycle

Security exceptions are time-bound. The reminder, the cleanup, and the cascade rules all key off the same expiry date.

LimitValueWhere it is setDeep dive
Expiring exception remindersent when expiry is exactly 7 days awayPlatformBusiness rules: security exceptions
Reminder send time08:00 in the workspace timezonePlatform scheduler, workspace timezoneSecurity Exceptions
Cleanup pass (expired exceptions reopen findings)runs daily at midnight in the workspace timezone, plus an hourly sweepPlatform schedulerBusiness rules: security exceptions

Stale claim and assignment

When a teammate sits on a claim too long, the assignment service releases it. The timeout is editable on Settings → General Settings.

LimitDefaultWhere it is setDeep dive
Stale claim timeout (days)14 daysSettings → General Settings → Assignment & AttributionWorkspace settings
Stale claim sweep cadencehourly per workspacePlatform schedulerBusiness rules: assignment
Daily assignment digest send hour08:00 in the workspace timezoneSettings → General SettingsWorkspace settings

Authentication tokens, sessions, and 2FA

These are the timeouts and counts that control how long a sign-in artifact lasts.

LimitValueWhere it is setDeep dive
Password reset link TTL60 minutes from issuePlatform auth configProfile and 2FA
Password reset issue throttle (same user)60 seconds between requestsPlatform auth configProfile and 2FA
Password confirmation re-promptevery 1 hour for sensitive actionsPlatform auth confign/a
Session lifetime (idle)120 minutes (2 hours)Platform session confign/a
Two-factor recovery codes generated per user8 codesGenerated on Settings → Password & 2FA → View recovery codesProfile and 2FA

Rate limits

Per-IP and per-session limits applied to authentication and tenant-provisioning endpoints. A request that exceeds the limit gets HTTP 429 with a Retry-After header.

EndpointLimitScopeDeep dive
Login attempts5 per minuteper username + IPProfile and 2FA
Two-factor challenge attempts5 per minuteper login sessionProfile and 2FA
Password reset requests5 per minuteper IPProfile and 2FA
Registration submissions10 per minuteper IPPlans and pricing
OAuth callback hits20 per minuteper IPMicrosoft Entra ID SSO
Redeem-code preview and redemption10 per minute per IP, plus 30 per hour per userper IP and per userPlans and pricing
New workspace creation2 per minute per IP, plus 3 per hour per userper IP and per userCreate your workspace

Subscription and billing grace windows

When payment fails or the workspace owner cancels, Retrievy keeps data online for a set period.

StateGrace windowWhat you keepDeep dive
Past due (payment failed, in dunning)7 daysRead access to dashboards. Scans pause. Writes blocked.Plans and pricing
Unpaid (dunning exhausted)n/aRead-only data, no sign-in.Plans and pricing
Canceled30 daysRead-only data with the Reactivate Subscription banner. Falls back to Essentials after 30 days.Plans and pricing

FortiGate hygiene thresholds

These thresholds feed the FortiGate SCM module's hygiene score. None are configurable per workspace.

ThresholdValueFindings raisedDeep dive
Stale policy (no hits)90 days since last hitLow severityFortiGate
Zombie policy (zero hits since creation)0 hits, periodMedium severityFortiGate
Empty object referenced by an active rulen/a (presence check)High severityFortiGate
Shadowed policy (unreachable rule)n/a (path analysis)Medium severityFortiGate

Audit trail

The audit trail is available on Advanced and Build Your Own plans. Per-resource history is capped so the table stays performant.

LimitValueWhere it is setDeep dive
Per-resource audit entries kept200 most recentPlatformAudit trail
Audit trail availabilityAdvanced and Build Your Own onlyWorkspace planPlan feature matrix

Reports

The Executive Report and Technical Report PDFs cap the embedded findings list so the PDF stays readable.

LimitValueWhere it is setDeep dive
Technical Report PDF findings cap200 findingsPlatformPlan feature matrix
Executive Report PDF length6 pages (fixed layout)PlatformPlan feature matrix

Scoring thresholds

The grade bands the Retrievy Index projects to a letter, and the severity weights that drive the weighted failure count.

ThresholdValueWhere it is setDeep dive
Grade Ascore 90 to 100PlatformScoring rules catalog
Grade Bscore 75 to 89.9PlatformScoring rules catalog
Grade Cscore 60 to 74.9PlatformScoring rules catalog
Grade Dscore 40 to 59.9PlatformScoring rules catalog
Grade Fscore below 40PlatformScoring rules catalog
Critical severity weight100PlatformScoring rules catalog
High severity weight20PlatformScoring rules catalog
Medium severity weight5PlatformScoring rules catalog
Low severity weight1PlatformScoring rules catalog
Informational severity weight0PlatformScoring rules catalog