From one builder to the whole enterprise. Governance always included.
Per-seat plans with pooled governed runs. Every tier — including Individual — ships the full fail-closed gate chain, cost caps, and the tamper-evident Trust Ledger. You never pay extra for the ability to govern.
14-day full-featured Team trial · no credit card · prices exclusive of tax · run allowances pool across the workspace, overage bills per run in arrears
How runs work
One meter, no surprises.
Agents do work in governed runs. Here's exactly how the meter behaves — before procurement has to ask.
1 · An agent acts
Every invocation passes the 8-gate chain and lands in the ledger — executed, held, or blocked. That's one run.
2 · Runs pool across your team
On Team, 2,000 runs per user merge into one workspace allowance. Heavy operators draw from the pool — nobody hits a personal wall.
3 · Overage never interrupts
Past the allowance, runs bill per run in arrears at the published rate in your console. The meter warns early; workflows never stop mid-run.
What's always included
Governance isn't a line item. It's the runtime.
On most platforms, controls are an enterprise upsell. On Cortex, you cannot run an agent without the full gate chain — on every plan, including Individual. You pay for governed compute, never for the ability to govern it.
Every run passes 8 gates: identity → budget → guardrails → registry → control-tower → policy → execute → audit
Hard cost caps fail-closed at 100% — a runaway agent is blocked with a 402 before spend
Out-of-policy actions return 403; conflicting writes return 409 — deny is the default
Every outcome lands in a tamper-evident ledger (hashOk:false flags any edit)
The governance runtime is identical across plans — what scales is agents, pooled runs, workflow depth, identity controls, deployment, and support.
Feature
Individual
Team
Most popular
Business
Skills library
Core skills catalog + library installs
Premium & verified skills
Private team skills with versioning
Curated org catalog + approval policies
Agents & Studio
Active agents
5
25 / member
Unlimited
Shared studio (drafts, review, versioning)
Team templates
Sandbox + staging environments
Runs & Workflows
Included governed runs / month
500
2,000 / user, pooled
Custom, pooled
Overage
Per run, in arrears
Per run, in arrears
Volume commitments
Workflows
Manual triggers
Scheduled + event + approvals
Cross-team orchestration
Human-in-the-loop approval steps
Governance & security (runtime included in every plan)
Fail-closed gate chain (8 gates)
Tamper-evident Trust Ledger
Audit trail retention
30 days
90 days
Custom + SIEM export
SSO
Google & Microsoft
SAML/OIDC + SCIM
RBAC
Workspace roles
Fine-grained + policies
Data residency · VPC / air-gapped
Integrations & support
Connectors
Standard
Premium + API
Custom-built
Support
Community + email
Priority
Dedicated CSM
Uptime SLA
99.9%
Security-review concierge
What you pay for
A run is a governed invocation — executed, held, or blocked.
You pay for governed compute, not just successful output. Held and blocked attempts still produce a ledger entry — that's the point.
Executed
Executed
Passed all 8 gates, acted, and wrote a signed receipt to the ledger.
Hold
Held
Stopped at an oversight gate for human approval — recorded, replayable, awaiting sign-off.
Blocked
Blocked
Denied at a gate — 402 over budget, 403 out of policy, 409 on conflict.
audit/verify
head 0x9f3a…c1ok: true
verifyChain ▸ chained SHA-256 · signed receipts
Business
Run Cortex your way.
Regulated enterprises deploy Cortex in their own boundary: VPC, on-premise, or fully air-gapped, with data residency pinned per tenant and the Trust Ledger intact. Your security reviewers get a concierge, not a PDF chase.
A run is one governed agent invocation that passes through the 8-gate chain and produces a ledger entry — whether it executes, is held for human approval, or is blocked (402/403/409). Example: an agent that reads a claim, drafts a summary, and proposes a payout is one run; if the payout crosses your approval threshold and waits for sign-off, it is still one run.
What happens when we hit our run limit?
Nothing stops mid-workflow. Runs past your included allowance bill per run, in arrears, at the published overage rate shown in your plan console — and your usage meter warns you well before you get there. There are no prepaid credit walls and no mid-run cutoffs.
Need more than the included runs?
Pick a usage expansion on the plan card — 5× or 10× the included runs per seat, on the same plan with the same governance. 10× is priced sub-linearly (10× the usage for 9× the price). Switch tiers anytime; changes prorate to your billing cycle, and per-run overage remains available past any tier.
Are runs pooled across the team?
Yes. On Team, every member's 2,000 monthly runs pool into one workspace allowance — heavy operators draw from headroom that lighter users leave. Business plans size a custom pooled commitment with volume discounts.
Do you train models on our data?
No. Your prompts, documents, and run outputs are never used to train models — on any plan. Business adds contractual no-training guarantees, custom retention, and data-residency controls.
Is governance an add-on or extra cost?
Governance is never an add-on. The fail-closed gate chain — Agent IAM, cost caps, guardrails, policy-as-code, oversight modes, and the tamper-evident Trust Ledger — is included in every plan, including Individual. You cannot run an agent on Cortex without it.
How do seat changes and proration work?
Add seats any time — they prorate to your billing cycle from the day they activate. Removed seats stay usable until the cycle ends and stop billing at renewal. Mixing plan changes mid-cycle prorates the difference; you never pay twice for the same period.
What's in the free trial?
The trial is 14 days of the full Team plan — shared studio, pooled runs, oversight console, SSO — with no credit card required. When it ends you pick a plan; nothing is deleted while you decide.
Which SSO options come with which plan?
Team includes Google and Microsoft single sign-on. Business adds SAML/OIDC, SCIM provisioning, and fine-grained RBAC mapped to your identity provider's groups.
Can we deploy on-premise or in an air-gapped environment?
Yes — on Business. Single-tenant, VPC, on-premise, and air-gapped deployments are supported, with data residency pinning. Signed Solution Packs verify by hash and signature offline, so governed solutions install into environments with no outbound connectivity.
Which compliance frameworks is Cortex aligned with?
Cortex is built for and aligned with SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, the EU AI Act, NIST AI RMF, and FINRA. We are not making certification claims on this page — visit the Trust Center for current attestation status and security documentation.
“We budgeted for a governance project on top of the platform cost. With Cortex there wasn't one — the controls our auditors wanted shipped on day one, on the plan we already had.”