Zscaler workload, branch and consumption metrics are the licence units Zscaler uses for things other than people: servers and cloud workloads, branch sites and the devices behind them, cellular SIMs, cloud data stores, vulnerability assets, identities, SaaS applications and generative AI tokens. Each product has its own licensing and fair use article on the Zscaler Help Portal. Most follow the same pattern: a purchased quantity, a periodic review by Zscaler “to ensure license compliance”, and a fair use threshold expressed as an average.[3][4][8] Under the End User Subscription Agreement, usage above purchased quantities, including usage limits in the Documentation, must be purchased promptly.[15] Several of these metrics are forms of subscription and consumption licensing rather than device licensing in the classic sense, because the unit is observed traffic or objects, not installations.
Editions
The products covered here are sold as standalone subscriptions or add-ons. They include Zero Trust for Workloads (Workload Communications and Zero Trust Gateway), Zero Trust Branch and Branch Connector, Zero Trust Device Segmentation, Zscaler Cellular, Data Security Posture Management (DSPM), Unified Vulnerability Management (UVM), Identity Protection, SaaS Security Posture Management (SSPM) and AI Guard.[3][4][5][7][8][9][10][11][12] Package names and sizes are listed on Zscaler platform bundles and editions.
Metrics
| Product | Zscaler metric | Catalog row | Zscaler definition (summary) |
|---|---|---|---|
| ZIA / ZPA workloads | Workload | Workload | A unique domain name, an IP address, or a set of IP addresses; VMs, VDI, serverless functions and containers[1] |
| Zero Trust Gateway | Gateway Instance; Monthly Traffic | Gateway Instance | A Zero Trust Gateway instance in an Availability Zone in any AWS region; GB of workload traffic per month[3] |
| Branch Connector; Device Segmentation | Device | Device | An endpoint such as a printer, camera, badge reader, RF scanner, IoT, IIoT, IoMT, server or desktop instance with a unique IP address[5] |
| Device Segmentation | Gateway | Gateway | Hardware or a virtual machine sitting between different networks or applications[5] |
| Zero Trust SD-WAN, IoT | Site | Site | A site or location subscription[1] |
| Zscaler Cellular | Cellular device | Cellular Device | An endpoint with a Zscaler SIM or e-SIM, or a unique IP address accessing Cellular Edge[7] |
| DSPM | Data store | Data Store | A single cloud service instance such as a VM, storage bucket or database[8] |
| UVM | Asset | Asset | Total assets processed and stored in UVM[9] |
| Identity Protection | User identity | User Identity | Each unique individual represented in the application, whether or not they log in[10] |
| AI Guard | Token | Token | Generally four characters (UTF-8 code points, excluding white space)[12] |
| DNS-Based Guest WiFi Security | DNS Transaction; Location | DNS Transaction, Location | A recursive DNS query; a specific access point to the internet[13] |
The SLA document defines further terms: a Device as a subscription for each physical or virtual machine running an operating system on which the agent is installed, and a Workload as a subscription for a single cloud workload (virtual machines, database services, cloud storage and similar IaaS and PaaS resources).[13] These differ from the Help Portal wording above. The document used for a given SKU is the one referenced in the Order.
Counting / floors
Workloads (replacement effective 2024-04-19). The separate Workload Communications policy was replaced on 19 April 2024 by the ZIA and ZPA policies and their Workload metric.[2] Where a subscription is licensed per workload instead of per GB of monthly traffic, each unique domain name, IP address or set of IP addresses counts as one workload.[1] Platform bundles include a workload traffic allowance per subscribed user, covered on the bundles page. Catalog proof: Workload Communications policy replaced by ZIA and ZPA Workload metric.
Zero Trust Gateway (undated, retrieved 2026-09-26). Two licences apply: Monthly Traffic (workload GB, which includes ZIA and ZPA entitlements for workloads) and Gateway Instance. Each 1 GB of ZIA and ZPA egress traffic brings 10 GB for Layer-4 policy enforcement on east-west and ingress flows. At least two gateway instances are needed to use a gateway in an AWS region.[3] Catalog proof: Zero Trust Gateway: 10 GB of Layer-4 enforcement per 1 GB egress; two instances per region.
Zero Trust Branch Connector (undated, retrieved 2026-09-26). Licensed by the number of sites or locations protected and the data usage of protected devices. Devices are counted as unique IP addresses at an hourly interval, averaged over the month. Endpoints and gigabytes covered by Guest Wi-Fi SKUs are excluded.[4] Fair use is an average data transfer of 100 GB per month from 50 devices or servers per site.[4] Because the count is an hourly average, a device that appears briefly counts less than one that is always online. Catalog proof: Branch Connector devices counted hourly by unique IP and averaged monthly.
Zero Trust Branch and Device Segmentation (undated, retrieved 2026-09-26). Zero Trust Branch is licensed by the number of appliances enabled for protected devices during the term.[6] Zero Trust Device Segmentation (formerly Airgap) is licensed by gateways and devices. Installed gateways are counted and applied to the subscription term, and additional entitlements allow more devices per gateway.[5] Catalog proof: Device Segmentation counts installed gateways over the term.
Zscaler Cellular (undated, retrieved 2026-09-26). Protected devices are the Zscaler SIMs purchased, or the unique IP addresses accessing Cellular Edge. A data pool is purchased for them. It resets on the first day of each calendar month, and unused data does not carry over.[7] Above the pool, service continues and overage is charged automatically at the per-GB rate in the Order Form. The overage is co-terminous with the Subscription Term and “uncapped unless otherwise expressly stated”. Zscaler provides no real-time usage alerts, spending caps or throttling.[7] Catalog proof: Zscaler Cellular data pool resets monthly and overage is uncapped.
DSPM (undated, retrieved 2026-09-26). Data stores are counted as the unique VMs (every instance counts as one), storage buckets, databases and other supported services configured for scanning over the subscription period. Scanned volume should not exceed 1 TB per data store on average across all subscribed data stores, and exceeding it requires a volume add-on.[8] Catalog proof: DSPM fair use: average scanned volume under 1 TB per data store.
UVM and Identity Protection (undated, retrieved 2026-09-26). UVM counts assets processed and stored. Its fair use limits are no more than 3 MB of uncompressed data per asset per day and 4K queries per account per day, both on average.[9] Identity Protection counts user identities processed and stored, “regardless of whether such individual directly accesses or logs into” the application, with the same 3 MB and 4K limits per user identity.[10] Catalog proof: UVM fair use: 3 MB per asset per day and 4K queries per day, Identity Protection counts every represented identity.
SSPM (undated, retrieved 2026-09-26). Licensed by seat (unique users over the previous rolling 90 days) and by application. A “2 Apps” subscription covers up to two supported SaaS applications, with one tenant each. “The seat-based licensing requirement continues to apply in conjunction with any application-based licenses.”[11] Fair use is average data transfer per seat below two times the cloud-wide average, currently 8 GB per seat per month.[11] Catalog proof: SSPM seat licensing applies alongside application licenses.
AI Guard (undated, retrieved 2026-09-26). Licensed on a platform subscription fee plus the number of tokens purchased. Consumption is the total number of tokens in prompts and responses.[12] For the wider topic, see generative AI licensing. Catalog proof: AI Guard counts tokens in prompts and responses.
Virtualization & partitioning
Virtual machines matter to these metrics only as objects to count. A VM can be a workload,[1] a DSPM data store,[8] or a Device Segmentation gateway.[5] No processor, core or host-level rules apply, and nothing like the partitioning rules described in virtualization and partitioning. Zscaler-provided hardware, such as Zero Trust Branch appliances, is governed by the Hardware Usage Terms. The hardware stays Zscaler property and may not be moved to another location without prior written approval.[14] If Zscaler determines that usage exceeds hardware capacity, the customer must add or upgrade hardware, or reduce utilization, within 30 days.[14] Hardware must be returned within 21 calendar days after the term ends.[14] Catalog proof: Hardware remains Zscaler property and must be returned within 21 days of term end.
Cloud / BYOL
Zero Trust Gateway instances are provisioned in AWS regions and Availability Zones, and each instance licence is valid “in any Amazon Web Services (AWS) region”.[3] DSPM data stores are cloud service instances in the customer’s public cloud environments.[8] None of these products has a bring-your-own-license model.
Programs
These products follow the general Support Services and SLA Service Credits programs. The SLA document lists separate SLAs for DSPM, UVM, Zscaler Cellular, Zero Trust Device Segmentation, Zero Trust Gateway, Zero Trust Branch, AI Guard, Identity Protection and others.[13]
Out of scope
- Workload Communications feature tiers (Standard, Advanced, Advanced Plus), apart from their listing on the bundles page.
- Posture Control (ZPC) and other products under End-of-Sale notices.
- Per-GB overage rates and add-on prices, which are set in the Order Form.
- Agentic SecOps, AI Asset Management, Endpoint AI Security and other newer products whose licensing articles were not catalogued in this pass.
Catalog rows
Catalog rows for this article, grouped by table.
- Metrics
- Rules
- Workload Communications policy replaced by ZIA and ZPA Workload metric
- Zero Trust Gateway: 10 GB of Layer-4 enforcement per 1 GB egress; two instances per region
- Branch Connector devices counted hourly by unique IP and averaged monthly
- Device Segmentation counts installed gateways over the term
- Zscaler Cellular data pool resets monthly and overage is uncapped
- DSPM fair use: average scanned volume under 1 TB per data store
- UVM fair use: 3 MB per asset per day and 4K queries per day
- Identity Protection counts every represented identity
- SSPM seat licensing applies alongside application licenses
- AI Guard counts tokens in prompts and responses
- Hardware remains Zscaler property and must be returned within 21 days of term end