Pricing
Start with one gated action. Scale the evidence with your production use.
Offline verification stays available to every plan. Paid tiers add the governance, identity, retention, and support needed as more teams depend on the control.
Developer
$0 / month
Prove the flow on a high-risk action.
- Human approval and offline verification
- 3 seats · 5 agents
- M-of-N approval rules and hardware-key enforcement
- 14-day hosted evidence & proof access
- Embedded approvals: 1 live Relying Party (test RPs unlimited)
Start freeStarter
$149 / month
or $134/mo billed annually — save 10%
For a small team gating real actions.
- Everything in Developer
- 5 seats · 10 agents
- 90-day hosted evidence & proof access
- Embedded approvals: 1 live Relying Party (test RPs unlimited)
Choose StarterMost commonTeam
$499 / month
or $449/mo billed annually — save 10%
Put production pipelines behind governed approvals.
- Everything in Starter
- 10 seats · 25 agent identities
- 1-year hosted evidence & proof access
- Embedded approvals: 3 live Relying Parties
Choose TeamBusiness
$1,249 / month
or $1,124/mo billed annually — save 10%
Add enterprise identity and durable evidence.
- Everything in Team
- 100 seats · 250 agent identities
- SSO and SCIM, four-eyes / SoD, authenticator-model allowlist
- 3-year hosted evidence, plus bulk evidence / SIEM export
- Embedded approvals: 10 live Relying Parties
Talk to usEnterprise
Custom
For regulated, high-volume, or dedicated deployment needs.
- 7-year hosted evidence access and legal hold
- Unlimited seats, agent identities and live Relying Parties
- SLA, custom terms, and support
Talk to an engineerA Protected Op is one completed human approval. Not an API call, not a request, not a verification. If nobody signed, nothing is counted — denied, expired, and withdrawn requests are free, and verifying a receipt is free forever on every plan, including the free one. An MCP policy action labelled allow still goes through human approval; a completed signature is recorded as a Protected Op. INTYGA never refuses an approval because you crossed a plan-volume allowance, and Protected-Op volume is not billed. Embedding INTYGA in your own product is a capability of every plan — signatures are never volume-billed or capped there either; completed signatures remain visible as usage telemetry. A very large embedded audience is an Enterprise conversation, and nothing is ever refused while it happens.You can watch before you gate anything
Turning on a gate means finding out what it blocks, and production is a bad place to find out. So every plan, including the free one, can run in Discovery Mode. It records the eligible authorization requests you route through INTYGA and the human-approval requirements skipped for each one. Existing security checks still apply; unconnected activity is not observed.
Run it as a 14-day Runtime Assessment and you get a Security Risk Report at the end: which identities approved their own requests, which high-risk requests had a single signer, and which recorded requests had no human approval in the INTYGA path. That is usually the document that decides whether enforcement is worth turning on, and it costs nothing to produce.
One thing we will not blur: observations are not approvals. Nobody signed them, our verification library refuses them by default, and a workspace left observing forever is recording rather than governing. Discovery Mode is how you decide to enforce — not a substitute for enforcing.
An approval is never refused for billing
However many you need, on any plan including the free one. Completed approvals are counted as usage telemetry, not volume-billed. A billing counter cannot stand between you and a production change.
That is a design decision, not a promotion. A control that gates irreversible actions must not stop working because of an invoice: refusing the approval would take out your change-control path, probably during an incident, and the workaround people reach for next — routing around the gate — is worse than either.
One state worth knowing about in advance: if an invoice fails, we stop charging on top of money already outstanding. Nothing stops working — a declining card must never turn into a refused approval. A metering outage on our side is treated the same way and fails open, because that one is our fault, not yours.
Need a design partner path?
We can work with your team on one production workflow, the approval rules it needs, and the evidence your security reviewers expect.
Talk to an engineer →