Skip to content

Enterprise

Identity, governance and scale, for organisations

The Enterprise Edition adds what only an organisation needs on top of the free Community Edition: who may do what, teams kept apart, single sign-on, an audit trail you can prove, and more than one replica.

What it adds

Six capabilities, built and tested

Each one runs on the extension points of the same open core, and each is switched on by the features your licence names.

  • People, service accounts and their own keys

    Every request is made by someone: a person, or a service account for CI and scripts, each with API keys of their own.

    • Keys are stored as hashes, shown once, may expire, and are revoked rather than deleted
    • The first administrator comes from one setting or one command
    • Everyone else is managed over the REST API or the CLI
  • Role-based access control

    Five roles, from Administrator to Read Only, checked on every REST route and every MCP tool.

    • Administrator, Architect, Developer, Reviewer and Read Only
    • Roles can follow your identity provider's groups
    • Existing static keys keep working: an admin key acts as an Administrator
  • Organisations on one deployment

    Several teams share one deployment, and each sees only its own repositories.

    • Every organisation can have its own backend repository, under the same name
    • Another organisation's repositories read as missing from every route and MCP tool
    • An organisation's administrators manage their own people only
    • Teams stay apart even if the licence lapses
  • Single sign-on with OIDC

    People sign in to the console with their corporate identity, and scripts can send the provider's access tokens.

    • The authorisation-code flow with PKCE, and an HTTP-only session cookie
    • Tested against Keycloak, with set-up guides for Okta, Microsoft Entra ID and Google Workspace
    • A user is created at first sign-in, with roles from their groups
    • SAML 2.0 is planned
  • An audit log you can prove

    Every security-relevant event, append-only and hash-chained, so altering, removing or reordering a record is detectable.

    • Sign-ins and refusals, roles, keys, indexing, deletions, flag changes and the licence's state
    • Who, which organisation, what, the outcome, the endpoint and the caller's address
    • Exported as JSON Lines for your SIEM, and an export verifies offline
    • Retention you choose, with pruning that keeps the chain verifiable
  • High availability

    Several API replicas behind a load balancer, on shared stores, with one queue of background index jobs between them.

    • Any replica accepts a job, any one runs it, and every one shows its progress
    • A job whose replica stops is picked up by another
    • A Helm profile with rolling updates, a disruption budget and spreading across nodes

The licence

One key, checked offline

A licence key unlocks the Enterprise features. Without one, or after it lapses, BBM-Atlas is the Community Edition.

  • A signed key, checked offline

    Nothing phones home, so air-gapped sites work. The key names your organisation, its features, its seats and its dates.

  • Seats are people

    Users take the licence's seats. Service accounts, for CI and scripts, don't.

  • Never locked out of your data

    An expired key keeps working through a grace period, 14 days by default. After that BBM-Atlas runs as the Community Edition: no data is deleted, and a renewed key restores everything.

  • An extension, not a fork

    The Enterprise Edition is a package on top of the same Apache-2.0 core, so what you evaluate is what you run.

Turn it on

The same server, with a key

There is nothing new to run: the Enterprise package extends bbm-atlas serve, the CLI and the console. On Kubernetes, the Helm chart mounts the key from a Secret and has a high-availability profile.

terminal
# With the Enterprise package installed, give it your keyexport BBM_ATLAS_EE_LICENSE_KEY_FILE=./license.keybbm-atlas enterprise license   # state, features, seats# The first administrator: their key is printed onceexport BBM_ATLAS_EE_BOOTSTRAP_ADMIN_EMAIL=you@example.combbm-atlas serve

Every setting is in the Enterprise README, with set-up guides for Keycloak, Okta, Microsoft Entra ID and Google Workspace.

Talk to us about Enterprise

Tell us how many people will use BBM-Atlas and how you plan to run it. We will reply with a quote, or an evaluation key to try it first.

Or write to info@byteblendmatrix.com