Three things determine what your workspace can do, and they are easy to confuse:

- **Edition** — SMB or Enterprise. Selects the workspace and authorization model: which roles exist and how administration is scoped.
- **Plan** — Starter, Professional or Business. Your self-service subscription. Controls which features are unlocked.
- **Contract allowances** — how many subsidiaries and assets you may hold. Set by agreement, and they override the plan defaults.

## SMB

SMB is a workspace with a focused navigation and four fixed roles:

- Owner
- Analyst
- Viewer
- Remediator

Self-service signup creates an SMB workspace. Subscription billing is managed through Polar.

## Enterprise

Enterprise adds organisation-scoped administration:

- tenant-wide and organisation-scoped memberships;
- Enterprise built-in roles and custom organisation roles;
- portfolio views;
- governance, the document library and advanced intelligence; and
- temporary Perimeter support-access grants.

Enterprise workspaces are provisioned by Perimeter rather than through self-service signup, and commercial terms are arranged directly.

## What each plan includes

| Capability | Starter | Professional | Business | Enterprise |
| --- | --- | --- | --- | --- |
| Dashboard, assets, findings, scans, discovery, seeds | Yes | Yes | Yes | Yes |
| Reports | Yes | Yes | Yes | Yes |
| Risk register | — | Yes | Yes | Yes |
| SLA policies | — | Yes | Yes | Yes |
| Organisation hierarchy and subsidiaries | — | Yes | Yes | Yes |
| Single sign-on (OIDC) | — | — | Yes | Yes |
| Cloud asset import (AWS, Azure/Microsoft, GCP) | — | — | Yes | Yes |
| Intelligence feeds and credential exposure | — | — | — | Yes |
| Governance and document library | — | — | — | Yes |
| Custom roles | — | — | — | Yes |
| Perimeter support-access grants | — | — | — | Yes |

Feature access is enforced by the API, not only hidden in the interface. Intelligence, credential exposure, the document library, maturity assessments and each cloud importer refuse the request outright on a plan that does not include them.

## Hierarchy and subsidiaries

**Subsidiaries are not Enterprise-only.** Organisation hierarchy is available from the Professional plan upward. What differs by plan is how much of it you get.

| | Subsidiaries included | Nesting depth |
| --- | --- | --- |
| Starter | 0 | — |
| Professional | 2 | 2 levels |
| Business | 10 | 3 levels |
| Enterprise | Uncapped unless your contract sets a figure | 10 levels |

Both numbers come from your contract where one is recorded, and the plan default only applies when it is not. Perimeter staff set contract figures; you can see them and your usage against them, read-only.

Assets, findings, reports and risk records belong to an organisation. Organisation-scoped memberships can see their assigned organisation and permitted descendants.

Creating a subsidiary requires both the **Create subsidiaries** permission and a membership covering the selected parent. Visibility in the tree alone is not sufficient. Moving a subsidiary to a different parent re-checks everything creating one there would check, and additionally refuses a move that would place an organisation inside its own subtree.

See [Roles and permissions](roles-and-permissions) for the role and scope rules.

## Asset allowances

Your contract may record a maximum asset count. Until one is recorded, asset count is uncapped.

When a scan discovers an asset that would take you past that figure, it is **reported as a coverage gap rather than silently dropped** — you see that it was found and why it was not recorded, instead of a scan that quietly under-reports.

## Billing

SMB uses self-service subscription billing through Polar. Price, trial length, benefits and other commercial information shown in Perimeter come from the configured Polar product rather than from documentation, so what you are quoted is always what you would be charged.

Subscription status determines product access and whether the billing portal remains available. Managing the subscription requires billing permission.

Enterprise commercial terms are arranged directly and are not purchasable through checkout.

## Moving between editions

An edition change is not an ordinary plan upgrade.

Because SMB and Enterprise use different role and hierarchy models, moving an existing customer requires a controlled provisioning or migration decision. Contact Perimeter rather than editing database rows or assuming that changing a subscription product changes edition.
