Skip to content

Licence and plan

Admin, Licence (/admin/billing), gated by the billing.manage permission.

Shows your plan, what it includes against what you use, and lets you enter or remove a licence key.

From 0.18.1 there is one Plugboard plan. It includes:

  • every base module
  • 2 Technical seats
  • 2,000 managed devices
  • on managed hosting, 5,000 hosted AI calls a month

On top of that, a licence can include extra Technical seats, Business seats, 1,000-device blocks and the campus operations add-on, which covers Facilities, Administration, Other departments and School operations. Prices are on plans.

Admin, Licence shows:

  • Technical and Business seats used against seats included
  • managed devices against the devices included, and on the plan, the device blocks included and how many your fleet needs now
  • whether campus operations is included
  • hosted AI calls this month against the monthly allowance. Self-hosted deployments have no hosted allowance; their own model and keys are never metered

Every active staff account is one of three seat types. Nobody picks a seat by hand: it follows from the permissions the account’s roles grant, so it cannot be under-declared. The Users page shows each account’s seat, and the role step says when a role you are granting would raise it, for example “This makes Sam a Technical seat, 3 of 2 included”. It never stops the grant.

An account is Technical if any of its permissions is a Technical one, otherwise Business if any is a Business one, otherwise a free Participant. A role holding * makes a Technical seat.

Technical covers service delivery, devices, identity, connections and administration:

Area Permissions
Service desk ticket.update, ticket.close, ticket.transfer, ticket.internal, repair.update, repair.close, loan.issue, loan.return, loan.manage
Devices and remote device.manage, device.laps.read, device.wipe.request, remote.start, remote.manage
Identity identity.account.enable, identity.account.manage, identity.license.manage, identity.mailbox.delegate, identity.mailbox.fullaccess, identity.mfa.reset, identity.password.reset, identity.session.revoke, directory.manage
Connections and monitoring connector.manage, integration.manage, network.manage, monitor.manage
Desk setup induction.manage, client.manage, workflow.manage, departments.manage, visitor.configure
Administration role.manage, user.manage, site.manage, feature.manage, branding.manage, backup.manage

Business covers money, purchasing, reporting, content and projects, with no device, identity or technical control:

Area Permissions
Money charge.raise, charge.approve, cost.manage, cost.export, billing.manage
Purchasing and contracts stock.manage, software.manage
Projects operations.manage
Reporting report.manage, dashboard.manage
Content docs.edit, docs.manage, kb.manage
Approvals approvals.manage

Participant is free, and covers everything else:

Area Permissions
Viewing Every *.view permission, and docs.viewRestricted
Raising and commenting ticket.create, ticket.comment, repair.create
Deciding approvals approvals.decide, operations.approve, device.wipe.approve
Other assistant.agentforce.use, ticket.ingest, audit.view
Front office visitor.view, visitor.manage

So a head of department who reads reports and approves requests costs nothing, a business manager who approves charges is a Business seat, and anyone who updates tickets or manages devices is a Technical seat. Students, parents and other requesters never hold staff seats.

See roles and permissions and the permissions reference.

Nothing is blocked. Using more seats or devices than the licence includes shows a warning on this page, is reported with your usage, and is settled at renewal as a single line, so finance does not process a small invoice every month against a fresh purchase order. Enrolling a class set of iPads or hiring a technician never locks the desk. You can also ask for seats or device blocks to be added to the licence.

A school without a licence is on a 30-day trial, on managed hosting and self-hosted alike. The trial includes every base module and no add-ons.

The trial clock starts the first time the desk checks its entitlement on 0.18.1 or later, and it is never restarted. A school that was already unlicensed before 0.18.1 gets the full 30 days from its upgrade. In the trial’s last week a banner at the top of every page says how many days are left.

The desk becomes read-only when:

  • the trial has ended and no licence has been added
  • a licence has expired and its grace days have passed (14 unless your licence says otherwise)
  • a licence has been cancelled

While it is read-only:

  • Staff can sign in and read everything. Modules stay on and their records stay visible.
  • Staff can add or renew the licence here, run, verify and restore backups, export data, and look after their own account, password, MFA and passkeys.
  • Admins can still take access away: remove a user, sign someone out, force MFA to be set up again, or remove someone’s passkeys. A billing lapse should never stop you off-boarding a leaver.
  • Every other change is refused with a message saying how to fix it. That includes changes through API keys, the REST actions and MCP; tools that only read keep answering.
  • The student portal, kiosk, parent portal, inbound email and webhooks keep accepting requests, so nothing is lost.
  • Work that reaches other systems pauses: connector and SIS sync, MDM fleet sync, vendor repair and external ticket status sync, remote wipes, automation actions, network and printer sweeps, and scheduled report emails. Backups, service levels, service monitors and recurring tickets keep running.
  • A banner tells everyone, and people who can manage billing get a link here.

Adding or renewing a licence ends read-only straight away. Nothing is deleted.

Before 0.18.1, an expired or cancelled licence switched modules off, which hid their records. They now stay readable.

The public demo is never read-only.

Paste the key you were issued and save. The instance verifies it locally and the plan takes effect immediately.

On a managed deployment there is usually nothing to paste. Provisioning puts the licence in the environment and the instance activates it once at first boot. It acts only when there is no active licence, so it cannot overrule an activation you made yourself.

Licence keys are signed tokens. The instance holds only the public key and verifies the signature offline, so:

  • There is no call home at sign-in.
  • A network outage cannot disable your service desk.
  • The vendor cannot silently change what you are entitled to.

If the plan changes, the plan.changed message is sent to staff who can manage billing, because modules appearing or disappearing without explanation is confusing enough to warrant an email. That message cannot be switched off.

You can remove a licence key from this screen. The school goes back to what is left of its 30-day trial, or, if the trial has been used, becomes read-only straight away. Add-ons such as campus operations stop at once either way. The confirm step says which applies. Paste the key back to undo it.

Before 0.18.1, removing a key unlocked every module with no expiry.

Licences issued on the earlier Core, Standard, Advanced and Enterprise tiers keep working with the modules and limits they were sold with, and this page says which plan a licence is on. They are no longer offered for new licences. On a tier licence, Business seats are counted and shown but never flagged as over, because those licences never included any.

Plan The one plan, or an earlier tier
Included devices The managed device count the price covers, in 1,000-device blocks on the plan
Included seats Technical seats, and Business seats
Add-ons Campus operations, when bought
Hosted AI calls The monthly allowance, on managed hosting
Included tenants Usually 1; more is agreed in a quote
Expiry and grace When it needs renewing, and the days allowed after
Deployment binding Optionally, which install it is for
Telemetry endpoint Where usage counts are reported

Your deployment reports count-only usage every few hours.

What is sent:

  • Number of Technical seats and Business seats
  • Number of managed devices
  • Which modules are enabled
  • The version and channel
  • The deployment id
  • A monthly count of vendor-hosted AI completions, where your plan includes AI. A count, never content, and only for inference we pay for. Your own key and the bundled model are not counted

What is not sent: any name, any record, any ticket, any device serial, any connector credential, any content of any kind.

The endpoint normally comes from the licence itself.

Self-hosted deployments can turn it off:

Terminal window
USAGE_REPORTER_DISABLED=1

With it off, snapshots are still kept locally and can be exported from this screen, which is how a self-hosted customer reports usage for billing without phoning home at all.

Managed deployments report as part of the service.

The licence key is the credential used to report. We check the signature, the issuer, the audience, expiry, that the licence is not revoked, that the timestamp is within a replay window, and that the reporting deployment matches any binding on the licence.

A licence reporting from more than one install is surfaced as an alert rather than blocked, because a legitimate rebuild also produces a new install id. It wants a human glance, not an outage.

Entitlement lives in the signed licence your deployment already holds, not in the billing system. A school’s service desk keeps working through a billing outage, an expired card or a failed webhook. A licence that lapses makes the desk read-only after its grace days; it never deletes or hides your records.

A failed payment starts a conversation. Cancelling a licence remains a deliberate act.

Contracts are annual and invoiced annually by default, with automatic collection off, because most schools pay by transfer against a purchase order. A hosted payment page is available for anyone who would rather use a card or direct debit.

A This deployment card shows the version you are running, its build date, the channel, and whether an update is available. It is what support will ask for first.

Self-hosted deployments see the same in the status panel, which works when the service does not.

A self-hosted deployment needs LICENSE_PUBLIC_KEY set in its environment so it can verify keys. This is the vendor’s public key and is the same value for every customer.

Key rotation is supported through a keyed map:

Terminal window
LICENSE_PUBLIC_KEYS='{"k_ab12cd34":"LS0tLS1CRUdJTiBQVUJM..."}'

And specific licences can be refused locally:

Terminal window
LICENSE_REVOKED_JTIS="..."

Full detail in environment variables.