← All articles
Account & Billing

Understanding your plan limits

Blacksands plans aren't feature-gated in the traditional sense — every tier runs on the same certificate-based zero-trust fabric. What differs across tiers is capacity, measured along two dimensions: apps and MCP clients.

Apps

An app is a service, device, or endpoint you're protecting through Broker or Bouncer — a database, an internal admin tool, a switch, a PLC, anything you've brought under Blacksands' identity-based access model. Your plan determines how many apps your organization can have connected at once. As your footprint grows — more services, more sites, more devices — you'll eventually need a tier with a higher app limit.

MCP clients

An MCP client is a distinct AI agent identity issued through Bursar (see Understanding agent identities and scoped access). Because each agent gets its own certificate identity rather than sharing a credential, your plan's MCP client limit is effectively the number of distinct agents you can run under Bursar's management at one time. Teams doing heavier AI-agent automation — multiple specialized agents each with narrowly scoped access — will use up MCP client capacity faster than teams running a single general-purpose agent.

Why these two dimensions specifically

Apps and MCP clients map directly to the two things Blacksands protects: things (services and devices, via Broker/Bouncer) and agents (AI identities, via Bursar). Rather than bundling arbitrary feature flags into each tier, plan limits scale with your actual usage of the platform — which is also why upgrading (see Upgrading or changing your plan) is usually straightforward: you're not migrating to a different feature set, you're raising a ceiling.

Checking your current usage

Your organization's console shows current app and MCP client counts against your plan's limits. If you're approaching a limit, it's worth planning your next tier before you hit it — running out of MCP client capacity mid-rollout, for example, would block a new agent from obtaining an identity until you upgrade.

Team seats are separate

Seats — the number of people on your team who can administer the organization — are a related but distinct concept from apps and MCP clients, and only apply from the Team tier upward. See Adding team seats for how that works.