Key takeaways
- The models are usually identical across tiers. You are buying administration, identity and contract terms.
- Four triggers justify enterprise: automated deprovisioning, a contractual obligation, audit logging, and scale.
- The cheapest business tier is a real answer for a lot of firms and nobody in a sales process will tell you that.
- Starting lower and upgrading is usually cheaper than buying capability you have not configured.
Once a firm has chosen a provider, the next question is which plan, and it is asked in circumstances designed to produce the wrong answer. The comparison pages list features rather than consequences, the sales conversation is naturally weighted toward the higher tier, and the person deciding usually has no way to judge whether automated user provisioning is something their organisation needs or something it will never configure.
The good news is that the decision has only four real inputs, and you can work them out in an hour.
What you are actually buying
The first thing to understand is that the underlying capability rarely differs. Across the major providers, the model you get on a business tier is the same model you get on an enterprise tier. You are not buying intelligence, you are buying control.
Tier names differ by provider and change over time, so it is more useful to think in terms of three levels of control:
| Capability | Individual | Business tier | Enterprise tier |
|---|---|---|---|
| Your data excluded from model training | Sometimes, by setting | Yes, contractually | Yes, contractually |
| Central billing and one invoice | No | Yes | Yes |
| Administrator can see and remove users | No | Yes | Yes |
| Shared workspace and shared assistants | No | Yes | Yes |
| Single sign-on through your identity provider | No | Sometimes | Yes |
| Automated provisioning and deprovisioning | No | Rarely | Yes |
| Audit logs of administrative activity | No | Limited | Yes |
| Configurable retention periods | No | Limited | Yes |
| Negotiable contract terms | No | No | Yes |
| Named support and response commitments | No | No | Usually |
| Minimum seats or annual commitment | No | Usually low | Usually both |
Read that table looking for the rows that describe a problem you actually have. Most organisations find two or three, and the pattern of which ones tells you the answer.
The single most important row is the second self-service one. Whether your data is excluded from model training is the difference between an individual account and any business tier, and it is the reason consolidation matters. Once you are above that line, everything else is administrative convenience rather than risk reduction.
The four triggers for enterprise
Trigger one: you need deprovisioning to be automatic. If someone leaves on a Friday, does their AI access end on Friday? On a business tier the answer is yes if an administrator remembers. With identity integration the answer is yes because it is tied to the same directory that closes their email. Below about fifty staff, remembering works. Above a few hundred, or in any organisation with contractors and turnover, it does not, and the gap between policy and reality becomes the exposure.
Trigger two: a contractual or regulatory obligation. A signed business associate agreement for healthcare, specific data processing terms a client demands, a data residency requirement, or an insurance policy condition. These are binary. If you need it, the tier that offers it is the tier you buy, and the cost comparison is irrelevant.
Trigger three: you need audit evidence. Not chat content, but a record of administrative actions: who was granted access, when settings changed, who removed what. If you are subject to examinations, audits or client security reviews that ask for this, the higher tier is where it lives.
Trigger four: scale makes manual management painful. There is a headcount somewhere between one hundred and three hundred where an administrator managing users by hand stops being a small task and becomes someone's ongoing job. The tier that automates it costs less than the person.
If none of the four applies, the business tier is very likely the correct answer, and buying above it means paying for a category of control you will not configure.
What sales conversations get wrong
Two patterns worth recognising.
The first is the security framing, where enterprise features are presented as though the lower tier is insecure. It is not. The business tier already excludes your data from training and gives an administrator control over access. The enterprise tier adds integration and evidence, which are different things from security. Ask specifically what risk the upgrade removes and whether you currently carry that risk.
The second is the annual commitment, which is presented as a discount and is also a decision you cannot reverse for a year. In a category moving this quickly, a twelve-month lock at a fixed seat count is a real cost, particularly for an organisation that has not yet learned what its usage pattern looks like. If a provider will not do a shorter first term, that is information about the relationship.
A question worth asking before signing anything: what happens to our data and our workspace if we downgrade or leave? The answer varies more than you would expect, and it is much easier to ask now than to discover in twelve months when you are trying to move.
Seat counting, which is where budgets go wrong
Firms consistently get this wrong in one direction and then the other. The first pass underestimates, because only the obvious knowledge workers are counted. Then usage spreads to operations, finance and administration, who turn out to benefit as much or more, and the licence count grows unplanned.
The second pass overcorrects, buying a seat for everyone including people who will sign in twice and never return. Every organisation has a group like this and paying for them monthly is a slow leak.
A practical approach is to buy for the people who will actually use it, review at ninety days using the administrator view of who has signed in recently, and adjust. Any tier worth buying gives you that visibility, and if it does not, that is itself a reason to look elsewhere.
The recommendation for most mid-size firms
For an organisation of roughly thirty to two hundred staff, with no healthcare or heavily regulated data obligation, and with an identity provider that an administrator can manage manually, the business tier is usually right for the first year. Configure it properly, run it, and revisit at renewal with actual usage data and a list of the two or three things you wished you had.
The firms that regret their choice are rarely the ones that started lower. They are the ones that bought enterprise, never connected single sign-on, never looked at an audit log, and are now twelve months into a commitment for control they did not implement.
Frequently asked questions
What actually differs between business and enterprise plans?
Not the models. The business tier gives you a shared workspace, contractual exclusion of your data from training, administrator control and central billing. Enterprise adds identity integration, automated provisioning, audit logging, configurable retention, negotiable terms and named support. You are buying control and evidence, not capability.
When is enterprise genuinely worth it?
When you need automated deprovisioning through your identity provider, when a regulation or client contract requires specific terms, when you need audit evidence for examinations or security reviews, or when your headcount makes manual user management a real job. If none of those apply, the business tier is usually the right answer.
Should we sign an annual commitment?
Be cautious in the first year. An annual lock at a fixed seat count is a real cost in a category changing this fast, especially before you know your usage pattern. Ask for a shorter first term. A provider unwilling to offer one has told you something useful about the relationship.
How many seats should we buy?
Buy for the people who will genuinely use it, then review at ninety days using the administrator view of recent sign-ins. Under-counting is common because operations and administrative staff benefit more than expected, and over-counting is common because every organisation has people who will sign in twice and never return.
Have the tier decision made properly
We work out which tier your obligations actually require, configure it, cap the spend, connect single sign-on where it is warranted, and hand over an administrator view your own team runs. No sales process, no upsell, fixed price, live in 30 days or less.