Enterprise
Above 2,500 employees, with the prices published rather than hidden behind a form.
An annual agreement covering engagement cycles for the whole organization and manager seats for everyone who needs them. From $25,000 a year.
What a cycle costs at this size
The four bands below 2,500 employees are bought in the app. The two above it are quoted — and published anyway, because a number you can take to your finance team before you talk to anyone is worth more than a form.
| Employees | One cycle | Per employee | How it is bought |
|---|---|---|---|
| Up to 100 employees | $999 | $9.99 | In the app |
| 101–250 employees | $1,799 | $7.20 | In the app |
| 251–500 employees | $2,999 | $6 | In the app |
| 501–1,000 employees | $4,999 | $5 | In the app |
| 1,001–2,500 employees | $9,499 | $3.80 | In the app |
| 2,501–5,000 employees | $15,499 | $3.10 | Quoted |
| 5,001–10,000 employees | $24,999 | $2.50 | Quoted |
The per-employee column is the whole story of this table. It falls by roughly half for every tenfold increase in headcount, and it does that at every band rather than only at the ones we quote — the figures above 2,500 are the same curve continued, not a different pricing philosophy applied to larger customers.
Above 10,000 employees there is no published figure, and that is honest rather than coy: we have not run a cycle at that size, so a number in this table would be a guess dressed as a price.
What manager seats cost at this size
The manager tools are priced per manager, never per employee, and the rate falls as you add managers. Seats up to 500 are bought and changed in the app; above that they are part of the agreement.
500 managers
$64,416
a year — an effective $10.74 per manager per month
750 managers
$91,416
a year — an effective $10.16 per manager per month
1,250 managers
$139,392
a year — an effective $9.29 per manager per month
The ladder is graduated, which means each band prices only the managers inside it: the first 24 seats are always $16 whether you buy five or five hundred, and only the seats past each boundary get the cheaper rate. It is the arrangement that makes the bill impossible to reduce by growing, and it is the same principle the cycle top-up blocks use — those come ten or fifty seats at a time, depending on the band: a marginal seat costs what the seats beside it already cost.
The floor is $7 a manager a month, reached past 1,000 seats. Your employees are not counted, not licensed, and do not appear on the invoice — a company of 10,000 people with 1,200 managers is a 1,200-seat customer.
What the agreement covers
An annual cycle allowance
Up to 4 cycles in the year, on one renewal date and one purchase order, rather than a separate purchase each time. Below this size cycles are bought one at a time, which is right for a company that runs one a year and wrong for one that pulses quarterly.
Single sign-on, and a roster that keeps itself
SAML sign-in for your managers against your own identity provider, and a roster fed from your HR system rather than a spreadsheet somebody re-exports every quarter. What exists today and what is built to order is set out below.
The paperwork procurement asks for
A signed data processing agreement with standard contractual clauses, a sub-processor list with notice of changes, a named contact, and a security review answered by a person rather than a badge wall.
The works-council pack
What is asked, what is stored, who can see which numbers, what the reporting floor does, and why no free-text answer is ever shown verbatim — written to be handed to a works council or a European employee representative body, in the form they actually ask for it.
A raised per-manager tracking limit is part of it too. The standard cap of 35 people is a fair-use ceiling rather than a product limit, and it is genuinely too low in retail, hospitality and manufacturing, where one manager can carry sixty reports. Raising it is a term in the agreement, not a favour.
Where your data lives
Three arrangements, and the only difference that matters is who holds the credential that can read the database. The instrument, the reporting floor and the prices are identical in all three.
A dedicated instance we run
Your own database and your own deployment rather than a share of ours — in the region you pick, on your retention and deletion timetable, with an export of everything whenever you ask for one.
Who can read the raw answers: nobody, in the sense the rest of this site means it. We hold the service credential, and no signed-in account has a read policy on those tables — yours or ours.
What it takes: provisioning rather than engineering. It is how Facets already runs, once per customer.
Your cloud account, we operate it
The same deployment, inside your own Amazon, Microsoft or Google account. The tenancy, the backups and the infrastructure bill are yours. Running it, patching it and answering for it stay with us, through an access path you can revoke without asking.
Who can read the raw answers: the application credential is ours, and the disks and the snapshots are yours. An administrator in your own account with a reason has a route the first arrangement gives nobody.
What it takes: a containerized build and a migrator that runs itself. Both are engineering we do for the engagement, scoped and quoted before anything starts.
Your servers, you operate it
An image you pull into your own registry — an internal GitLab is a perfectly good one — and run behind your own firewall, with no outbound connection required. The written half of a report falls back to the deterministic version, so nothing has to leave the building to be written up.
Who can read the raw answers: your administrators. That is the point of the model and it is also what it costs, which is the paragraph below rather than a footnote.
What it takes: everything the second arrangement needs, plus the operator tooling stripped out, an entitlement path that works with no payment processor attached, and a route for upgrades. The most work of the three by a distance.
What moving the install toward you actually costs
The reporting floor, the joint unit-and-manager suppression and the rule that no free-text answer is ever shown verbatim are enforced by code, running on a database nobody at your organization can read. That is the basis of what your employees are told before they answer a single question. On your own servers it becomes an undertaking instead: the floor is a row somebody with the credential can edit, and the raw answers are one query away. We will not ship that arrangement with the wording your people see left as it is — they are who the promise is made to, and they have to be told who is operating the install. If that is unacceptable, it is the wrong model and one of the first two is the answer.
None of the three carries a list price. Each is built for the organization that asks for it and quoted before anything starts, because what it costs is setup and the support that follows rather than a license — and both of those depend on which arrangement you pick, whether it has to run with no network at all, and how often you want upgrading. A multiplier printed here would be a number nobody could stand behind, which is the same reason the table further up stops where it does.
What is built, and what is built to order
The self-serve ceiling exists because of the second column. Everything in it is work we scope, price and put a date against in the agreement — which is why a rollout this size starts with a conversation rather than a card.
Working today
- SAML single sign-on, built and running against our own test provider. It has not yet been walked end to end with a customer’s identity provider, and the first one will be done with us in the room rather than over a support ticket.
- Manager seats, invitations, seat reassignment when somebody leaves, and an organization-wide administration view.
- The engagement instrument, the reporting floor, joint unit-and-manager suppression, and group results with error bars at every level of your unit tree.
- Export of everything, permanently, whatever happens to the agreement.
Built to order
- More than one language. The instrument exists in English. Every item is a validated translation problem rather than a string file, so this is weeks of careful work and it is priced into an agreement that needs it.
- SCIM provisioning. Rosters are imported as a file today, which is the wrong mechanism at ten thousand people. The connector is built for the agreement that needs it.
- SOC 2. Not held. If procurement needs a Type II before you can sign, it goes into the agreement as scoped work with a date on it rather than a box ticked optimistically, and the security page says what is in place meanwhile.
- Running anywhere but here. A dedicated instance is provisioning we can do today. Putting the install in your cloud account or on your own servers needs a containerized build, a migrator that runs itself and the operator tooling stripped out. Scoped work, quoted per engagement, built to the timetable in your agreement.
If you need any of these before you can sign
Say so in the first conversation and they go into the agreement with dates against them. They are real work on a real calendar, and a schedule both sides can hold to is worth more than an assurance that everything is already in place.