Plans, seats & Enterprise SSO
Free covers one synced folder, Pro unlocks the paid single-user capabilities, Team unlocks the encrypted team brain, and Enterprise adds single sign-on for your whole organization.
What each tier unlocks
There are four tiers: Free, Pro, Team, and Enterprise.
| Free | Pro | Team | Enterprise | |
|---|---|---|---|---|
| The full local editor, graph, search, bring-your-own-AI | Yes | Yes | Yes | Yes |
| Synced folders (through a folder you choose) | One | Unlimited | Unlimited | Unlimited |
| Publishing (hosted and local folder export) | — | Yes | Yes | Yes |
| Notion & Confluence connectors | — | Yes | Yes | Yes |
| Version history beyond the last 7 days | — | Yes | Yes | Yes |
| Encrypted team brain, roles, revocation | — | — | Yes | Yes |
| Signed audit export | — | — | — | Yes |
| Single sign-on (SSO / OIDC) | — | — | — | Yes |
Verifying a signed audit file is deliberately available on every tier, including Free — a recipient should never need a licence to check that what they were handed is intact. Only producing the export is Enterprise.
How seats work
A seat is consumed by every member on a team vault's roster, whatever their role — Owner, Admin, Writer and Reader alike.
Readers are not free. If you are sizing a plan, count everyone who will be on the roster, not just the people who will write.
Adding a member when the roster is already at the licensed seat count is refused, and the message tells you the current count and the limit. A roster that is already over the count — because it grew before the check existed, or after a plan change — is not invalidated: existing members keep working and only the next addition is refused.
Licences, devices and going offline
A licence is bound to the device it was activated on, and is checked against a signed grant from your Apilium account. If it can't be reached, Altretta keeps honouring a cached licence for a 14-day offline grace period; after that the app falls back to Free capabilities until it can check again. Nothing local is taken away — your notes, editor, graph and search never depend on a licence.
Individual sign-in vs. Enterprise SSO
Individuals sign in to their Apilium account with an email and password, or with social sign-in via Google, GitHub or Microsoft.
Enterprise organizations can enable single sign-on via OIDC, so members authenticate through your identity provider by email domain instead of managing separate credentials — see your Apilium account.
Enterprise SSO / OIDC
Enterprise unlocks single sign-on (SSO) using OIDC, configured per organization and keyed to your domain — when someone with your company's email domain signs in, they're routed through your identity provider. Consumer mailbox domains are refused, so an SSO configuration can't be claimed for gmail.com and its equivalents.
SSO is set up per organization on the Apilium side — the identity-provider configuration, including the client secret, lives there and is never stored by the desktop app. Altretta supports standard OIDC single sign-on; specific provider setup is arranged as part of onboarding your organization.
Related
Team brain overview
The section this page belongs to.
Roles & permissions
The four roles, and how seats are counted.
The encryption model
What "end-to-end encrypted" actually guarantees for your team.
Licensing & activation
Activating a plan, and what each tier changes.
Glossary: seat & roles
Plain-language definitions for the billing terms here.