The installed Sitecore XM, XP and XC Software (Experience Manager, Experience Platform and Commerce) is licensed on different terms from the SaaS Products: a licence key, a Subscription Term, usage reports and audit rights. Order Definitions group the Software under section 3(A) as “Sitecore XM/XP/XC”.[1] Sitecore also offers a Managed Cloud Hosted Service in which the Software runs in Azure.[1]
Licence grant and key
On execution of an Order including Software, the customer receives a licence key that gives access to the Software; the key is time-limited until full payment is received.[2] Sitecore and its licensors retain all rights, and the customer receives a non-exclusive, non-transferable, non-assignable, non-sublicensable licence, solely during the Subscription Term, to copy and use the Documentation and the Software in compliance with law and solely for the Permitted Usage; the Order may set other terms.[2] See Software licence key.
Sitecore’s documentation describes the technical side. A Sitecore Host application requires a valid Sitecore license file to run, which is read and validated at start-up, and a problem with the file causes a LicenseException; by default the file is loaded from the host’s sitecoreruntime folder and the location can be changed in the host configuration.[3] For XP service roles, the license.xml file is placed in the App_data folder, and some worker role licence files must be updated as well.[4] Replacing a file at renewal is therefore an operational step across every role in a deployment.
The Software warranty runs for 120 days after the Order effective date, with repair or replacement as the remedy, or a refund if Sitecore cannot repair within 30 days.[2] On termination or expiry the customer must cease use, delete all copies and, on request, certify that use has ceased.[2]
Metrics
The Order Definitions define the following units for the Software.[1]
| Metric | Definition summary | Counting notes |
|---|---|---|
| Domain | A single second-level domain with a single top-level domain and all subdomains | Redirect-only domains and translation-only domains do not count; a domain that is translated and otherwise localized does |
| Environment | Software installed on any number of servers all pointing to a single instance of the main content database | Production Environments perform Production Activities; Non-Production Environments only support them |
| User | Each individual person concurrently logged into the user interfaces of any installation for editing content, site administration, development, testing or similar actions | Concurrent, across all installations |
| Visit | Presentation of content or functionality of the Software to a single person within a Time Frame | Time Frame ends after more than 1800 minutes, 30 minutes of inactivity, or application closure |
Production Activities are the creation, authoring, publishing or delivery of digital content to a website, email, mobile visitor or service, including separate commerce, email or print capabilities if purchased, and the processing and reporting of Visits for use in xDB.[1] An asset manager therefore needs to classify each installation as production or non-production by what it does, not by what it is called. Because an Environment is defined by the content database, adding web servers behind the same content database does not add Environments, while a second content database does.[1] Domains whose sole purpose is to redirect visitors do not count against authorized Domains.[1]
Annual Usage Report and records
No later than the 15th calendar day after each 12-month period beginning on the Order effective date, the customer must submit a usage report identifying the number of Visits in that period, based on use of the Software; invoicing for overages indicated by the report is as set out in the Order.[2] Where the customer cannot use the Software to monitor Visits, it must use monitoring software reasonably acceptable to Sitecore.[2] For the non-Visit metrics such as Domains, Environments and Users, the customer maintains accurate records of compliance during the Subscription Term and provides them promptly on request, which Sitecore may do only once in any 12-month period.[2] See Annual Usage Report (Software).
Audit rights and licence verification
If the Annual Usage Report or the Additional Records are not produced on time, or Sitecore has reasonable grounds to question their accuracy, Sitecore may at its own expense engage an independent third-party auditor to audit use of the Software.[2] The audit is on reasonable notice, during normal business hours, without material interference, using an auditor reasonably acceptable to the customer. The auditor must sign a non-disclosure agreement, be accompanied by a customer employee or representative, follow reasonable security instructions and not introduce audit software without prior vulnerability testing and approval; no remote access is provided to customer systems during any audit.[2]
The consequences are set out in the same clause.[2] If the audit finds more Visits than purchased, Sitecore invoices overages under the Order. If it finds unauthorized use, Sitecore invoices all such use at its then-current retail prices computed from the date the excess usage commenced; if that invoice exceeds 5% of the fees paid or payable under the applicable Order including Software for the most recent three years, the customer also pays the expense and costs of the audit; and the customer pays all such invoices within 30 days of receipt. Separately, the Software may track and report to Sitecore the License Key ID, customer name, hostname (the customer’s website URL), host IP, version and other usage information.[2] The general MSTC liability exclusions do not apply to use outside the scope of the licences granted.[5] See Software audit and licence verification.
Entitlement overage for Software
The MSTC automatic upgrade clause applies to Sitecore Products unless Addendum B or the Order provides otherwise.[5] For Software, Addendum B instead routes overages through the Annual Usage Report and the Order, so the Order must be read to see which mechanism applies to each metric.[2][5]
Managed Cloud
Managed Cloud is a Hosted Service. The definitions are as follows.[1]
- A Production Set is a single, mutually exclusive online environment hosting the Software exclusively for Production Activities, and a Non-Production Set hosts it exclusively for Non-Production Usage.
- Azure Spend is the cost in USD of all hosting components in the Production Set or Non-Production Set, as calculated and reported by Sitecore’s third-party providers and subject to change over time; the Azure Spend Commitment is the amount of Azure Spend over which overages apply, as set out in the Order.
- Disaster Recovery is offered as Basic DR (cold standby, rebuilding in an alternate location from backups) or Managed DR (hot standby using data replication).
- Topology Customizations, also called Hosting Extensions, are additional Azure resources that complement the standard topology.
- A User for Managed Cloud means any user of the Customer Applications, which are the software and services that depend on the Hosted Services.
- If Cloudflare Enterprise is purchased as an Additional Hosted Service, further Cloudflare-related definitions apply.
Hosted Services are licensed under Addendum A on the same basis as SaaS Products (the Subscription Term and Permitted Usage, subject to the Usage Policy).[6] Because Azure Spend is reported by third parties and may change, overage exposure under the Azure Spend Commitment can move without a change in the customer’s own activity. See Azure Spend Commitment.
Counting guidance
- Maintain a register of installations with their content database, role (production or not) and domains.[1]
- Record peak concurrent logins across all installations, including developers and testers.[1]
- Calendar the Annual Usage Report on the 15th day after each contract-year anniversary.[2]
- Keep Visit evidence from the Software, or approved monitoring, because the audit trigger is a late or doubtful report.[2]
Out of scope
Prices, part numbers and the exact Entitlement tiers are in the Order, not in the cited documents. Sitecore Commerce Order Definitions beyond the XM/XP/XC grouping, support and maintenance terms, and legacy perpetual licences from before the current MSTC are not covered.