SitecoreAI is the Sitecore platform that XM Cloud customers are upgraded into. The SitecoreAI FAQ says XM Cloud will be the core platform, with entry-level access to CDP and Personalize, Search and Content Hub, that all Sitecore-built AI use cases are included at no extra cost, and that all XM Cloud customers were to be upgraded automatically from the global launch on 10 November 2025.[1] The licensing units are in Order Definitions v2.6, dated 1 July 2026.[2] This article explains the SitecoreAI definitions first and then those for XM Cloud.
SitecoreAI metrics
Order Definitions define five platform-wide metrics for SitecoreAI.[2]
- Asset Storage is the storage and retention of file-based assets, including images, videos, document files, data models, prompts, embeddings and other digital content created, processed or managed by SitecoreAI or its agentic components, measured across all modules including CMS and DAM.[2] See Asset Storage.
- CDN Use is the distribution and delivery of digital content through the Sitecore Content Delivery Network, tracked by the total data transmitted and metered on the SitecoreAI CDN, including delivery initiated by automated or agentic processes.[2]
- Production Environments are those used for live, customer-facing or business-critical operations, and Non-Production Environments are those used for testing, development, staging or training only, in each case as included in or provisioned under the subscription.[2]
- Experience Interaction is any instance where the SaaS Product dynamically personalizes, delivers or responds to a user’s activity, profile or context across digital channels, such as search queries, personalized content, recommendations, messages or offers, and also system-triggered, agentic or user-defined events such as custom actions, signals or API calls.[2]
- Visit is described below for the CMS module.
For Experience Interactions the tracking rules differ by tier. For SitecoreAI only instances that return content are counted; for SitecoreAI Tiers 1 and above, every instance is counted whether or not the SaaS Product returns content, which Sitecore says lets customers configure usage rules or consumption management within the Essentials entitlements.[2]
The CMS Visit
A Visit means an instance in which an application, such as a website, mobile app or other software on a digital device, presents, uses, accesses or otherwise leverages content, data or functionality originating from the SaaS Product, directly or indirectly.[2] Indirect use includes content served from intermediate storage or delivery layers such as cache or a CDN, including where the product is not contacted at the time of use.[2] Three kinds of activity can produce a Visit.[2]
- Browser Activity covers direct human browser visits and indirect visits through web integrations such as RSS feeds, iFrames and browsing agents that emulate browsing. A Visit begins when the application first interacts with the product and ends at the earliest of more than 12 hours of continuous activity, more than 200 Rendered Page Events in a session, or closure of the session. A single session can give rise to more than one Visit.
- Identified Non-Browser Activity is automated access where the source can be identified and attributed, such as indexing, aggregation, marketplace listing or AI training and inference, by a client that consistently discloses its identity and comes from a verifiable source. The same Visit conclusion rules apply.
- Unidentified Non-Browser Activity is non-browser activity whose source cannot be reliably identified; each 200 Rendered Page Events counts as one Visit.
If an event could fall into several categories, Browser Activity prevails, then Identified, then Unidentified Non-Browser Activity.[2] A Rendered Page Event is a metering event recorded when an application renders a discrete user-facing page, screen or view that uses content, data or functionality originating from the CMS.[2] The definitions also state that the classification and treatment of identified and unidentified non-browser activity, including whether it constitutes billable Visits, shall be determined by Sitecore.[2] This matters for sites with heavy bot, crawler or AI-agent traffic. See the Visit (SitecoreAI CMS) row.
Tracking by SDK
The customer must implement and maintain the applicable version of the Sitecore Content SDK, including the tracking and metering components, for Visit tracking, and deploy it as a condition of continued access to Visit-level analytics and reporting; Sitecore may specify a minimum Mandated Version by written notice or Documentation update.[2] If the customer elects not to implement the Content SDK, disables the required components or implements them so that reliable measurement is impossible, usage is calculated from Content Requests recorded by Sitecore, with one Visit equal to 75 Content Requests for all of the customer’s digital properties and use cases.[2] A Content Request is a request or metering event for content, data or functionality served directly by the product or indirectly from cache, CDN, edge or replication layers.[2] See Content SDK Visit tracking. A second tracking-rules section in the same document refers to an Analytics SDK with a Visits-only version and a full analytics version, with usage calculated from content requests in Sitecore system logs if the SDK is not implemented.[2]
Changes and attacks
Sitecore may update the Visit definition or tracking methodology for legitimate business or technical reasons, but a material change affecting billing must be notified in writing at least 30 days in advance.[2] No overage is owed for Visits or Experience Interactions that the customer can demonstrate were caused by a distributed denial-of-service attack or similar automated malicious traffic not involving human interaction, if industry-standard measures were taken and any DDoS attack did not last more than 24 hours; an attack is treated as a single period of up to 24 consecutive hours from its first malicious request.[2] See DDoS overage relief.
SitecoreAI DAM and Agentic Studio
For the DAM module the definitions are Power Users, Consumers and Managed Content Objects.[2]
| Metric | Definition summary |
|---|---|
| Power User | Registered user who can manage and modify assets, content and content types, products, custom content, campaigns, collections and metadata (create, update, add, delete, lock, submit, publish, archive), and corresponding operations items such as projects, workflows and tasks; counted if permitted to do one or more of these |
| Consumer | Registered user who can view and download assets and content, share assets and approve within workflow tasks; includes employees whose main role is not website administration and third parties who upload materials |
| Managed Content Objects | Distinct Content Objects made available in the DAM capability, counted once as the primary entity without versions, renditions, metadata or workflow artifacts |
Managed Content Objects are counted across Production and Non-Production environments, so one object available in both counts as two.[2] An object is an MCO only where it is made available within the provisioned DAM capability and not merely because it is stored in or synchronized to a shared underlying repository.[2]
Agentic Studio uses the Builder Seat, a permission-based role that lets an individual create and configure Custom Agents.[2] A Custom Agent is a software or AI agent developed or supplied by the customer or a third party, integrated through an API, SDK, connector, plug-in or webhook, and not provided or supported by Sitecore; Custom Agents are used at the customer’s sole risk.[2]
XM Cloud metrics
For Sitecore XM Cloud the Order Definitions provide a different set.[2]
| Metric | Definition summary |
|---|---|
| Production and Non-Production Environments | Total environments available in the subscription |
| Projects | A collection of Experience Manager Cloud environments |
| Concurrent Users | Concurrent users supported across all Production Environments; each Production Environment supports up to fifty |
| Concurrent Builds | Builds that can operate at the same time; each Project can have one active Build and deployment at a time |
| Build | Tenant provisioning, developer customization requiring compilation or deployment, and automatic update deployments |
| Visit | Presentation of product content to a single person within a Time Frame |
The XM Cloud Visit uses a Time Frame that starts when a person first interacts with the application and ends when it exceeds 1800 minutes, when the person has not interacted for more than 30 minutes, or when the application is closed.[2] Because XM Cloud customers are upgraded to SitecoreAI, the metric that applies to a renewal can change, and the Order is the controlling document.[1]
Counting guidance
- Record whether the Content SDK is deployed and at what version; non-SDK usage converts at 75 requests per Visit.[2]
- Separate human, identified agent and unidentified bot traffic when forecasting Visits.[2]
- Count DAM users by permission, not by job title, and count each MCO once per environment.[2]
- Keep evidence of attack traffic to support overage relief.[2]
Out of scope
Prices, tier thresholds and Essentials entitlement values are set in the Order and are not published in the cited documents. SitecoreAI-specific SLA terms, Gen AI usage terms and partner-delivered implementation are not covered.