Editions
Data-driven product tiers that grant features and limits to tenants.
What an edition is
An edition is a named product tier — a set of feature entitlements plus pricing metadata — that a tenant is assigned to. Editions are data-driven, so a host administrator can define new tiers at any time rather than depending on a code release.
| Attribute | Purpose |
|---|---|
| Name | Unique tier name (for example "free", "enterprise") |
| Display name & description | How the edition is presented |
| Pricing | Monthly price, annual price, setup fee and currency |
| Free & availability flags | Whether the tier is free and whether it is currently offered |
| Visibility | Whether the edition is visible to every tenant or an allow-list |
| Sort order | Display ordering |
Each edition owns a set of feature entitlements — one value per capability (see Features). A tenant is assigned to exactly one edition, and there are no per-tenant feature overrides: every entitlement is inherited from the edition.
Seeded editions
On a fresh install, three editions are provided out of the box:
| Edition | Shape |
|---|---|
| Free | Minimal: keys and vaults enabled, software vault, the DKE 365 app, RSA-2048; tight limits (1 key, 1 vault, 1 app, 5 users) |
| Free Trial | Every module enabled so a prospect can evaluate the full platform, with capped headline quotas (for example 20 keys, 2 vaults, 5 apps, 5 users); the tenant is downgraded to Free once the trial window expires |
| Enterprise | Everything enabled; all numeric limits unlimited |
Additional editions (for example intermediate tiers) are created by host administrators at runtime.
The platform does not model deployment (SaaS vs on-premise vs hybrid) as an edition — those are commercial and deployment choices. Self-hosted installs use the "all features" switch described in Host.
Limits
Numeric features act as quotas and are enforced as maximums. By convention:
| Value | Meaning |
|---|---|
-1 | Unlimited |
0 | No allowance (fail-closed) |
n > 0 | Maximum of n |
Typical limits cap the number of users, keys, vaults, apps, certificate authorities and PQC endpoints.
Enforcement
Resolve the edition
On each request, the platform resolves the caller tenant's edition and its feature entitlements.
Check the feature
The requested capability is checked against the edition; a disabled capability is refused. Anything not explicitly granted is treated as denied (fail-closed).
Guard edition changes
Reassigning a tenant to another edition is allowed only if the tenant's current usage already fits the target — no quota exceeded, no in-use module removed, no now-unavailable resource type present.
Soft-deleting an edition immediately stops granting its features to any tenant still assigned to it.
API reference
Editions are managed from the host tier — creating, updating and deleting editions, setting their feature values and visibility, and listing the editions a given tenant may move to — governed by host-level edition permissions.