Organization plans
An organization’s plan sets the ceiling on how much infrastructure it can
run, how many people can work in it, and which platform capabilities are
switched on. There are four tiers: Starter, Professional,
Business, and Enterprise. Any Owner or Admin can view and change
the plan from Settings → Subscription (/gravity/settings/subscription).
For exact prices, see sencai.space/pricing - this page covers what each tier gives you, not what it costs.
What counts as a managed resource
Section titled “What counts as a managed resource”Plans limit the number of managed resources - one compute instance, managed database, storage bucket, or DNS zone that Sencai is actively managing for you counts as one. Resources you’re only tracking in inventory without managing don’t count against the limit.
Comparison
Section titled “Comparison”| Starter | Professional | Business | Enterprise | |
|---|---|---|---|---|
| Users | 5 | 20 | 50 | Unlimited |
| Cloud environments | 3 | 15 | 50 | Unlimited |
| Managed resources | 150 | 750 | 3,000 | Unlimited |
| Private registry | 20 GB | 100 GB | 1 TB | Custom |
| Security scanning | CIS basics | CIS + Lynis + container signing | CIS + Lynis + container signing | Custom scope |
| FinOps | Basic | Full + AI anomaly detection | Forecasting + multi-cloud comparison | Everything + custom reporting |
| Browser SSH terminal + JIT elevation | - | Included | Included | Included |
| SSO (Entra ID, Google Workspace) + SCIM | - | - | Included | Included |
| On-premise deployment option | - | - | - | Included |
| Support | Email, 3 business days | Priority email + chat, 8h | Chat + phone (24×5), 2h | 24×7, dedicated engineer |
| SLA | - | 99.9% | 99.95% | 99.99% |
A few things worth calling out beyond the table:
- Starter covers automatic SSL/TLS certificates, basic instance security scanning, and monitoring/alerting alongside the numbers above.
- Professional adds the browser-based SSH terminal for your fleet and just-in-time elevation with an approval workflow - this is also the first tier with unlimited webhooks and AI-assisted FinOps anomaly detection.
- Business adds a policy engine with governance scoring and NIS2 evidence reporting, plus SSO/SCIM and advanced RBAC - the point at which identity typically moves from individual accounts to your IdP.
- Enterprise is the only tier with an on-premise deployment option - the fleet agent runs the same way on your own hardware as it does on a cloud instance - plus multi-org management, custom SLAs and contracts, and SOC 2 / ISO 27001 documentation.
What happens when you hit a limit
Section titled “What happens when you hit a limit”Creating a resource, environment, or user seat beyond your plan’s limit is blocked with a clear error rather than silently allowed and billed extra - you’ll be prompted to upgrade rather than left guessing why the action failed. Nothing you already have is removed or disabled just because you’re at the limit; the block only applies to new creation.
Upgrading or downgrading
Section titled “Upgrading or downgrading”From Settings → Subscription, choose a new plan and confirm - for a
brand-new subscription (no plan yet, such as coming off the trial) this
takes you to a dedicated plan-selection screen at
/gravity/settings/upgrade first. Changing an existing paid plan goes
through Stripe Checkout at /gravity/checkout/upgrade, where you confirm
payment details before the change takes effect.
Downgrading works the same way - pick a lower tier and confirm. If your organization is currently using more than the lower tier allows (more managed resources, more users), resolve that first; the platform won’t silently delete resources to fit a smaller plan.
You can also cancel entirely from the same page - see Payment, invoices and failed payments for what cancellation does and doesn’t do to your data.
Who can change the plan
Section titled “Who can change the plan”Changing plans, and everything else on the Subscription page, requires the Owner or Admin role. An organization can additionally restrict a specific Admin’s billing access to read-only through a per-resource permission override - see Roles & permissions.
What’s next
Section titled “What’s next”- Billing overview - how organization and personal plans fit together
- Payment, invoices and failed payments
- SSO - set up SSO/SCIM once you’re on a plan that includes it
- Support & SLA