Skip to main content
Applies to:
Cockpit v2Feature flags & entitlementsProduct catalog

The feature model​

A feature is a named entitlement that turns a platform capability on or off (or sets a numeric limit). Each feature has a value type and belongs to a category:

AspectDetail
Value typeBoolean · Numeric · Text
Numeric convention-1 = unlimited · 0 = none (fail-closed) · n = maximum
ResolutionA tenant\'s value comes from its edition; anything not explicitly granted resolves to a safe, fail-closed default
Coming-soonCapabilities marked coming-soon appear for visibility but cannot be selected or enabled

Feature values live on editions (there are no per-tenant overrides), so changing what a tenant can do means changing its edition.

Catalog by category​

CategoryWhat it entitles
Key managementWhether key management is enabled, how many keys are allowed, and which key algorithms may be used (RSA, elliptic-curve, AES, HMAC, post-quantum)
Vault managementWhether vaults are enabled, how many, and which vault providers are available (software, DuoKey HSM, Securosys, the major cloud KMS providers, HashiCorp and more)
PKIWhether PKI is enabled, how many certificate authorities are allowed, external-CA support, and enrolment protocols (EST, SCEP, ACME, CMP, OCSP)
PQCPost-quantum readiness and the number of PQC endpoints
ApplicationsWhether apps are enabled, how many, and which product integrations are available
Identity / SSOWhether SSO is enabled and which identity providers (Azure AD, Okta, Keycloak, UAE Pass, Ping Identity, RSA SecurID Access, ForgeRock)
Access controlAttribute-based access policies
SSH Certificate AuthorityWhether the SSH Certificate Authority module is enabled, how many CAs and active certificates are allowed, and whether the live PKCS#11 signing bridge may be enrolled
MCPWhether the MCP interface is enabled, which capability packs it exposes, and its usage limits
PlatformCross-cutting capabilities such as webhooks, KMIP and the maximum number of users

How features gate capabilities​

Whether a capability exists for a tenant is decided by its edition. Before an operation runs, the platform checks the corresponding entitlement centrally, so a capability the edition does not grant is simply unavailable.

Core administrative surfaces (sign-in, users, roles, settings, tenants, editions, billing, dashboards, audit and activity logs, notifications, organizational units and features) are always available and never feature-gated.

Permissions vs features

Features decide whether a capability exists for the tenant's edition; permissions (see Administration) decide whether this user may use it. A call must pass both.

Coming-soon features​

A set of features is marked coming-soon: they appear in the catalog for visibility but cannot be selected or enabled. Treat them as roadmap, not available capability.

Product catalog​

The platform ships a broad catalog of products and integrations a tenant can deploy. Each app is scoped to a tenant and, optionally, to an organizational unit.

GroupProducts
Microsoft 365 / DKEDKE 365, ADFS, SharePoint, Exchange, Purview DLP
Database TDEOracle TDE, MySQL TDE, Percona PostgreSQL, MongoDB CSFLE, SQL EKM
Cloud KMS / BYOKAzure EKM, AWS XKS, OCI EKMS, Google CSE, Snowflake tri-secret
SaaS BYOKSalesforce, ServiceNow, Slack, Zoom, Box, GitHub, Atlassian, Zendesk, Workday, ADP, SAP Data Custodian, Genesys
Data security postureVaronis, Cyera, Wiz, Netwrix
Network / SSLCloudflare keyless, F5 BIG-IP, Imperva WAF, Skyhigh SWG
SigningPDF signing, code signing (Git, GitLab, SignTool, Docker, kernel, JAR, Office macro), key attestation
InterfacesKMIP, REST API, custom SDK, HashiCorp / OpenBao, vault sync, customer key, KMS client

Each product integrates over standard interfaces (such as REST and KMIP) and common authentication methods (such as API keys, OAuth2, mutual TLS and identity-provider sign-in), and exercises only the cryptographic operations it needs (for example encrypt, decrypt, sign, verify, wrap and unwrap).

How the major products fit

DKE 365 and Oracle TDE are examples of apps from the catalog above. PKI and PQC are core platform modules rather than apps. KMIP is available both as a platform gateway and as an interface an app can use.

API reference​

Feature definitions are read-only; their values are managed on editions, where each edition sets what its tenants are entitled to.

API reference
Detailed API endpoints are documented separately in the Developer Docs → Platform Administration API.