The on-premise edition validates a signed license on the server before protected operations. Browser code cannot grant a license, change employee limits, or self-attest payment.
license.json and store it as a read-only secret./run/secrets/projectxit-workbench-license.json.ACH, wire, purchase-order, and provider exceptions require an approved reconciliation before license issuance.
The signed file identifies the license, customer, employee limit, optional MSSP managed-customer limit, modules, effective and expiration dates, grace period, support date, optional deployment fingerprint, signer key ID, payload hash, and digital signature.
Project X IT retains the private signing key. The customer installation receives only the public verification key.
The server checks license state before connector creation and sync, CSV/XLSX import, scanner import, collector-token issuance, evidence upload, report generation, quantitative risk package generation, MSSP workspace creation, and protected API access.
Read-only access may remain available during a contractual grace period so the customer can export data and renew.
The default unit is active canonical employees. Service accounts, shared accounts, application identities, and faceless enterprise applications do not count as employees, but they must still be discovered and mapped to owners.
Customer administrators monitor current volume and expiration in Billing. When usage approaches the licensed limit, renew or adjust the subscription before the limit is exceeded. Existing evidence remains readable when the server enters an approved grace state; new imports and synchronization may be restricted according to the contract.