Licenses & Credits¶
Audience: All client users can view; managers/owners manage registrations and spend
capacity · Where: Settings → Licenses (/settings/licenses), also linked from the
Administration console.
Overview¶
Your organization's plan is expressed as licenses — one per testing capability — each with limits and usage this period. This page shows what you own, how much you've used, and how much is left, so you know your capacity before launching assessments. Nothing here is irreversible; it's a status view plus the web-app registration control.
Reading your licenses¶
Each active license is a card showing its status (Active), its limits, usage this period, and when it was Created. Typical licenses and the quotas they track:
| License | Limits & usage tracked |
|---|---|
| Web App | Application slots (e.g. 0 / 100). Web-app testing works by registering apps into slots (see below). |
| Internal Network | A Max IPs cap and Monthly internal IPs used (e.g. 1 / 100). |
| External Network | Max IPs, Monthly external IPs used, TLD slots (how many top-level domains ASM can watch), and ASM hosts (e.g. 8 / 10) used. |
Attack Surface (ASM) is part of your External Network license
Continuous external monitoring is part of your External Network license above, not a separate purchase; its usage appears on that card as TLD slots and ASM hosts. (Depending on how your plan was provisioned, the page may show these quotas on a separate ASM card, but they draw on the same External Network entitlement.)
License status badges¶
Each card shows a status badge and, when set, an Expires date with a "days remaining" hint that turns red inside 30 days:
| Badge | Meaning |
|---|---|
| Active | The license is in force. |
| Inactive | Not currently in force. |
| Expired | Past its expiry date — reads Expired even if it was otherwise active. |
The usage bars turn red as you approach a limit. You only see cards for the licenses your organization actually owns.
One-off Credit Packs¶
Below your licenses, any one-off web-app credit packs your organization has purchased appear as their own cards — separate from the recurring Web App license so each pack keeps its own provenance. Each shows its credits used / total (with remaining balance), an expiry date, optional notes, and when it was purchased. Packs are consumed independently of your annual slots.
Registered Applications (web-app seat model)¶
Web-application testing uses a seat model: each registered app can be pentested once per month (retests are unlimited and free). Slot cost depends on complexity:
| App class | Slots | Notes |
|---|---|---|
| Standard | 1 slot | The common case. |
| Complex | 2 slots | Many roles, multi-tenant isolation, or handling cardholder/health data. |
| Enterprise (6+ distinct roles) | — | Can't be self-registered; needs a bespoke engagement — contact sales to set them up. |
To register an app: pick it from Select an application to register… (the list comes from your Asset Library web-app assets, each showing its slot cost) and click Register. The panel shows slots used / cap and how many applications are currently registered; each registered app lists its complexity and slot cost with a Release button. Registering reserves a slot; releasing an app frees it for another.
How usage is consumed¶
- Launching an assessment draws from the relevant license (internal/external IP counts, or a web-app slot). This is why only managers/owners can submit — it spends shared capacity.
- Retests of already-covered work don't cost extra.
- Recurring assessments consume capacity on each run — plan cadence against your limits.
- Usage counters labelled "this period" reset monthly.
Tips¶
Manage your capacity
- Check this page before scheduling recurring scans so a weekly cadence doesn't exhaust a monthly IP or slot allowance.
- Watch the ASM hosts and TLD slots bars if you rely on Attack Surface monitoring — they cap how much external estate is watched.
- Need more capacity or a limit raised? Contact your Canima account manager — limits are set by your subscription, not self-served in the client portal.
Related: Running an Assessment · Asset Library · Attack Surface · Settings & Security