Seats and licences

How a licence is consumed, why an invitation gets refused, and why removing someone only reduces your bill if you ask it to.

<!-- Reviewed 2026-08-27 (provisionDemoTenant deleted): the covered usage.ts lost a caller-less dev-only function that seeded a 25x-oversized demo allowance (the root of the dev CI overspend incident). Nothing this page documents changes — seats, licences and the billing meters read and behave exactly as written. -->

Every person with access to a workspace occupies one licence. This page explains the accounting, because the two questions it answers — "why was my invitation refused?" and "why is my bill unchanged after removing someone?" — are otherwise genuinely confusing.

This page is about member licences. It deliberately does not quote prices or plan limits, which change; the billing screen is the authority for what your workspace currently has.

Licences, not members

Think of it as two separate numbers:

  • Licences — how many people your workspace is entitled to. You change this deliberately on the billing screen.
  • Members — how many people currently hold access, including pending invitations.

Members can never exceed licences. Everything below follows from that one rule.

An invitation reserves a licence immediately

The check happens when you create the invitation, not when the person accepts.

This is on purpose. The alternative — checking at accept time — means you send three invitations, and whichever two people happen to click first get in while the third hits a wall you created days earlier. Reserving up front makes the refusal land on the administrator who can act on it.

So a pending invitation occupies a licence exactly as a member does. If you are at your limit, cancelling an unaccepted invitation is a legitimate way to free one.

Why an invitation is refused

On the free plan — the workspace includes a small fixed number of members, enough for you plus a colleague. The next invitation after that is refused and points you at upgrading. This is enough to exercise a full review cycle, including the rule that a submitter cannot approve their own document, which needs two people.

On a paid plan — licences are what you have bought. When your members and pending invitations already fill all of them, you are stopped before the invitation goes out and offered the choice: add a licence now, or free one by removing a member or cancelling a pending invitation. If an invitation is sent anyway without a free licence, it is refused, and the refusal names how many licences are in use and how many are held by invitations nobody has accepted yet.

No invitation raises your bill without telling you first. There is no path where adding a person quietly costs money.

Note what that guarantee is, and is not. It is not that billing only ever changes on the billing screen — if you are out of licences, the invite flow will offer to buy one for you, showing the extra cost and that it is prorated, and confirming it adds the licence from the Members screen and sends the invitation straight after. The guarantee is that a licence is never added except by someone who has read what it costs and clicked to accept it.

Buying licences ahead of time on the billing screen is the calmer version of the same thing, and the better habit if you know you are hiring.

Removing a member frees a licence; releasing it is a separate tick

When you remove someone, their licence returns to your pool and the next person can use it. Whether you keep paying for that licence is a second decision, and you make it in the same moment: the remove dialog offers a tickbox — also release their paid seat.

Left unticked, which is the default, you keep the licence. That is usually what you want when you are backfilling the role. Tick it and the licence is given back as part of the removal, and the billing stops with it.

A removal you did not opt into never changes your subscription. Nothing is released behind your back, and nothing is bought behind your back either.

Two things you can rely on when you do tick it:

  • Ending their access always wins. Access is revoked first, and is never delayed or undone by a billing problem. If the payment provider cannot be reached, the person is still removed.
  • A release that fails says so. You are told the member is gone but the seat is still billed, and given a retry. If entitlements could not be read at all at that moment, you are told that instead, so you know to check rather than assume. What never happens is the silent version, where a failed release quietly bills you for a year.

You cannot release a seat someone is sitting in

Reducing licences is bounded by the people actually using them. If four members are active you will not be allowed down to three — you are told the count and asked to remove someone first. A subscription never drops below a single licence either.

So reducing can only ever walk your bill down toward the number of people really in the workspace, and never past it into stranding someone who already has access. Adding is deliberately not restricted the same way: a workspace that has ended up with more people than licences can always buy its way straight back.

Connections are not licensed

One thing your plan deliberately does not meter: how many of your own systems you connect.

On a paid plan there is no limit — connect every system your evidence actually lives in. Metering that would make Alchex worse at the one job it has, and the cost a connection really drives is your AI usage, which is already accounted for against your allowance.

The free plan includes a small number of connections. That is a boundary on the trial, not a per-system charge: it is enough to point Alchex at the systems you want to judge it on. If you reach it, the refusal names the number you have and offers the upgrade; disconnecting a system you are not using frees a slot immediately.

Two behaviours worth knowing at the free limit:

  • Reconnecting a system you already have is never refused. An expired token, changed permissions or a switched account re-runs the same connection rather than adding one, so being at your limit never blocks you from repairing something you already connected.
  • An abandoned connection costs you nothing. Closing the provider's consent window part-way leaves no claim behind — a slot is never silently held by a connection you did not finish.

How the AI allowance meters

Your plan's AI allowance is spent by the work Alchex's assistant actually does — generating a document, auditing, chatting. Three things worth knowing about how that figure is kept:

  • You are charged what a piece of work really cost, after it runs. There is no flat per-call fee: a short chat turn costs a fraction of a long document audit, and the meter reflects that. Every charge is a permanent entry in an audit ledger — the workspace total and each member's share are read from those entries, so the meter can always be traced back to the work that moved it.
  • The check happens before each piece of work starts. A workspace with allowance remaining is admitted; one at its cap is refused with a message saying so. Work already in flight when the cap is crossed is allowed to finish and is billed for what it used, so the final figure can end slightly past the cap — bounded, because only a few pieces of work may run at once.
  • A new period starts a new window; nothing is erased. When your allowance renews, the meter returns to zero because a new period began — the history of past periods stays intact in the ledger rather than being wiped.

Every paid plan carries an allowance and storage for each licence you hold, renewed each period, and you can raise the volume at any time without changing plan. A higher plan is never given less than the one beneath it: whatever a plan below includes per licence, yours includes at least as much, and anything agreed on top of that is added rather than substituted. The free plan is the one exception by design — a single fixed bucket that does not renew, sized to try the product rather than to run on.

Capacity: what your seats include, and what they don't

Two things scale with the people in your workspace: the AI allowance and storage, both granted per licence and pooled across everyone.

One thing does not: how much automation you run. Workflow runs are allowed per workspace, not per licence — deliberately, because the size of your team and the amount you automate are unrelated questions. A single person running a whole compliance programme through automations should not have to buy licences for people who do not exist in order to raise a limit.

Where extra capacity is offered, it is bought the same way: at the workspace level, in whichever mix you need. More AI without more automation, or the reverse, are both ordinary choices — neither forces the other.

Choosing capacity when you upgrade

Where your environment offers capacity packs, Upgrade asks what you need before sending you to payment: AI volume and automation runs are two separate choices, added in whatever combination suits you. Picking none is a normal answer — you get the plan and its included capacity, and can add more later without changing plan.

Storage is not one of the choices, and does not need to be. Every licence brings its own storage and it pools across your workspace, so the allowance grows as your team does. For the documents this product holds — policies, evidence, attachments — that allowance is far larger than a team will use, which is why there is nothing to buy.

You will only ever be shown packs your workspace can actually buy. If a kind of capacity is not offered yet, it is absent from the chooser rather than shown and refused at payment.

When storage runs out

Storage is counted across everything your workspace keeps: uploaded and external documents, document assets, evidence, register attachments, chat attachments and datasets. When an upload would take you past your limit it is refused before the file is stored, with a message saying so — you are never charged for something that was not kept, and a refused upload leaves your usage unchanged.

Deleting files gives the space back. The storage meter on the billing screen shows where you stand.

If your workspace does somehow approach its limit, the answer is not a bigger bill: clear what you no longer need, or add a licence if the team has genuinely grown, since each one brings more storage with it.

Paying monthly or yearly

Where yearly billing is offered, choosing it changes how often you are invoiced, not how the product meters. A yearly subscription is billed once a year at a discounted rate, and your AI allowance still renews monthly — the same monthly amount per licence a monthly subscriber gets, refreshed on the same cadence. The billing screen shows both dates honestly: when your allowance next resets (monthly) and when your subscription next renews (yearly). Yearly billing is available at upgrade time when your environment offers it; extra AI volume can ride a yearly subscription too, billed on the same yearly cadence.

Reading the numbers

The billing screen shows three meters: credits (your AI allowance), storage, and automation runs this month. Each shows what you have used against what you are entitled to, and each is hidden rather than shown empty where your plan does not meter it.

Two of the three are enforced today — spending your AI allowance and filling your storage both refuse further work. The automation-run figure is shown but not yet enforced: nothing stops a run at the limit. It is displayed first so you can see where you stand well before that changes.

You are also told when you pass 80% of your monthly AI allowance: every owner and admin gets one notice, once per month, so the first sign is not work being refused. See Your inbox.

Two honesty notes about what you are looking at:

  • The payment provider is the authority on what you are being billed. If you reduce licences, the new amount is billed straight away, while the copy of that number inside Alchex catches up moments later. Where the two could disagree, the licence decision uses the provider's number, so you are never handed a licence you have stopped paying for.
  • A number Alchex cannot verify is not guessed. If entitlements cannot be read at that moment, the screen says so rather than showing a plausible figure, and actions that depend on it are refused rather than allowed optimistically. The automation-run meter follows the same rule: where the count cannot be read it shows only what your plan includes, rather than claiming you have used none of it.

Practical guidance

  • Give approval authority to at least two people. With one approver, separation of duties collapses — their own submissions can never be reviewed by anyone else. This is the main reason to have a second licence before you have a second document.
  • Audit pending invitations before buying. An invitation someone never accepted is holding a licence.
  • Removing someone only saves money if you ask it to. Remember the tickbox: an offboarding done without it leaves a licence you are still paying for, which is fine while you are backfilling and pure waste when you are not.
  • Check for empty licences now and then. The billing screen shows bought against filled, so a gap is always visible. A gap is legitimate — it is a licence you are holding open — but it should be one you meant to hold.

Next