Netskope AI security licensing covers a group of Netskope services that inspect and govern traffic to generative AI applications, large language models (LLMs) and Model Context Protocol (MCP) servers, together with DataSec Command Center, which aggregates data security signals. Each service has its own licensing terms in the “Product Terms and Use” section of Netskope’s documentation: AI Guardrails, AI Gateway, Agentic Broker, AI Command Center, AI Red Teaming and DataSec Command Center (DCC).[1][2][3][4][5][6] Unlike Netskope’s inline services, which are sized by users over a term, these services combine a user or instance entitlement with a monthly consumption allowance of transactions, probes or events that resets each calendar month.[1][5] All of them are subject to the Netskope Subscription Services Agreement.[7]
Editions
| Service | What it does (vendor description) | Licensing models |
|---|---|---|
| AI Guardrails | Scans prompts and responses for AI threats and unsafe AI usage for user and agent-generated traffic | User-based (User plus monthly Transactions); Transaction packs |
| AI Gateway | Secures traffic between AI agents and LLMs, and between MCP clients and servers, from a gateway deployed in a customer-controlled environment | Per Gateway instance with monthly Transactions; add-on packs |
| Agentic Broker | Decodes, inspects and applies access controls to MCP traffic | User-based (User plus monthly Transactions); Transaction packs, also standalone |
| AI Command Center | Visibility and risk assessment for AI applications, MCP servers and the identities that use them | Volume of AI Assets |
| AI Red Teaming | Vulnerability assessments of LLMs before deployment and in production | Monthly Probes |
| DataSec Command Center | Unified data inventory, risk posture and remediation across Netskope data-security products | User-based (User plus monthly Events); Event packs |
Sources: the respective licensing terms.[1][2][3][4][5][6] AI Gateway includes AI Guardrail functionality, while DLP “may be licensed as part of an add-on subscription”.[2] Netskope does not publish the monthly Transaction, Probe or Event quantities attached to each SKU; the terms refer to “the applicable SKU description” or the customer’s Order.[1][5]
Metrics
Transaction
AI Guardrails defines a Transaction as “a combined prompt-response pair, where a prompt is entered by a User or is Agentic-generated, and a response is provided by the application or LLM”.[1] Agentic Broker defines it as a combined agentic protocol request and response, which for MCP maps to a request from an MCP client and the response from the MCP server.[3] AI Gateway counts a request and its response for LLM traffic (agent to model) and an HTTP request-response pair for MCP traffic.[2] The catalog records these as one metric, Transaction (AI services), with the per-service definitions noted.
User
The User-based models use Netskope’s standard User definition and count unique Users over a rolling 90-day period; a User entitlement cannot be shared between individuals, while Transaction or Event entitlements are shared among Users.[1][6] See User.
Gateway, AI Asset, Probe and Event
- Gateway (AI Gateway instance): “a single deployed instance of the Netskope AI Gateway software installed in a customer-controlled environment”; one subscription unit is one installation.[2]
- AI Asset: an AI Web App identified by the Netskope App Catalog, an MCP server, or an AI identity used to access either; each counts as one Subscription Unit.[4]
- Probe: a single prompt submitted by AI Red Teaming as part of a Test against a target LLM.[5]
- Event (DCC): “a discrete unit of activity, such as a logged transaction, request, record, scan, incident, or alert generated or captured by Netskope”, used to build DCC views.[6]
Counting / floors
Monthly allowances and suspension
Transactions, Probes and Events are measured cumulatively per calendar month and unused allocations “do not roll over to the subsequent period”.[1][5][6] The services behave differently when the allowance runs out:
- AI Guardrails and Agentic Broker: “the service is suspended until the end of the month” and resumes with the purchased quantity at the start of the next month; Netskope gives notice at 80% of the licensed Transaction quantity (rule).[1][3]
- AI Gateway: the same suspension applies per Gateway, with notice at 80% of the licensed Transactions for any Gateway.[2]
- AI Red Teaming: Netskope “will cease the execution of new Tests” until more Probes are bought or the allowance resets on the first day of the next month (rule).[5] The UI shows the estimated Probes a Test will need before it starts.[5]
- DataSec Command Center: dashboards and risks are not updated through the end of the month (rule).[6]
- AI Command Center: above the purchased quantity, “the service stops displaying new AI Assets” until more capacity is bought or usage is reduced (rule).[4]
In each case the customer may buy additional quantities for the rest of the Subscription Period to restore the service.[1][2]
Commentary: because exhaustion is enforced technically, the compliance exposure for these consumption units is service interruption rather than an overage invoice. The User component is different: for Users in excess of the entitlement the customer must, within 30 days of notification, license additional User packages for the rest of the term or stop use by the excess Users.[1][3][6]
Tenant scope
Pooling rules vary and affect multi-tenant estates:[1][3][2][5][6][4]
| Service | Users / volume | Transactions, Probes or Events |
|---|---|---|
| AI Guardrails | Users pooled at account level | Transactions per tenant, shared only among that tenant’s Users |
| Agentic Broker | Users pooled at account level | Transactions per tenant (rule) |
| AI Gateway | Gateway assigned to one tenant; separate subscription per tenant (rule) | Transactions per Gateway |
| AI Red Teaming | Separate subscription per tenant | Probes per tenant |
| DataSec Command Center | Users pooled at account level | Events pooled at account level |
| AI Command Center | AI Assets pooled at account level | Not applicable |
Measuring usage
AI Command Center counts AI Assets discovered over a rolling 90-day period.[4] AI Gateway counts active Gateways at any time and totals Transactions per Gateway monthly; usage can be monitored in the tenant and through Netskope APIs.[2] The tenant License page includes a Usage Report tab for AI Guardrails and AI Gateway that shows entitled quantity, actual quantity and a Compliant or Overage status (rule).[8] On reasonable request the customer may have to provide written confirmation of Users, Transactions, Gateways or Tests.[1][2][5]
Virtualization & partitioning
AI Gateway is the only self-hosted component. It is counted per deployed instance in a customer-controlled environment, regardless of the size of the host, and add-on transaction packs must be assigned to a specific Gateway.[2]
Cloud / BYOL
Not applicable. The AI services protect use of third-party AI applications and models; the customer remains responsible for holding the licences needed to use the third-party services monitored by Netskope (rule).[7]
Programs
No program is specific to the AI services. API endpoints used by AI Red Teaming have been deprecated and replaced, with the old endpoints removed on January 31, 2027, which illustrates that these services change quickly; the licensing terms are dated only by page modification date.[9]
Out of scope
Inline web, cloud and firewall services are licensed separately per User; see Subscription units and true-up. CASB API coverage of generative AI applications is discussed in CASB API, DSPM and posture licensing.