Standalone and enterprise compared
Every difference between the two profiles in one table, with the setting that changes each one.
On this page
Straza runs in one of two profiles. Standalone is the default and suits one machine or a small team: it signs people in itself, keeps its data in SQLite and needs nothing else installed. Enterprise expects your identity provider and a Postgres database, and a shared NATS server once you run more than one replica, as the enterprise shape shows.
You choose the profile with profile in the configuration file, the STRAZA_PROFILE environment variable, or strazad serve --profile. The profile only picks defaults. A row that names a setting changes when you set that key, and the configuration reference gives each key’s environment variable. A row with no setting is fixed by the profile.
| What differs | Standalone | Enterprise |
|---|---|---|
| Sign-in and users | ||
| Who signs people in#oidc. |
Straza’s own sign-in page, with a password and a one-time code. Clients use it even when oidc.issuer is set. |
Your identity provider, named in oidc.issuer. Until you set it, strazad still starts and every sign-in fails with no login issuer configured. |
| The break-glass admin# | Created at the first start, with its password printed once in the log. It signs in on the same page as everyone. | Created at the first start in the same way. Straza’s own page signs in this account and no other, under the title Emergency sign-in to Straza. |
| The first admin#oidc. |
admin, created on an empty database at the first start. Its password is printed once in the log. |
The user named in oidc.bootstrapAdmin, at their first sign-in through your identity provider, while no other person holds straza-admin. No password. |
| A person your identity provider signs in who has no user in Straza yet#oidc. |
Gets a user at that sign-in. | Is refused. Your identity manager creates the user over SCIM first. |
| How an AI agent signs in# | With a key of its own that an admin registers, checked by Straza’s own sign-in. | With its own client at your identity provider, from STRAZA_CLIENT_ID and STRAZA_CLIENT_SECRET, or with a registered key of its own. |
| The rate limit on the token endpoint where AI agents sign in#server. |
None. The limit covers the password form only. | The same limit as the password form, 2 requests per second for each client address by default. |
| Decisions | ||
| A local tool call that no rule matches#governance. |
allow | deny |
| A policy on a new install# | standalone-starter, seeded on an empty database. It denies recursive force-delete, such as rm -rf. |
None. You write the first policy. |
| A client that cannot reach strazad#governance. |
Keeps deciding from its last signed policy until 15 minutes after its session token expired. | Denies every governed call as soon as its session token expires. |
| The lowest install a session accepts#governance. |
none: any install. |
managed: an install whose files match the hashes you registered. |
| Audit records while the database is down#governance. |
drop-with-counter: decisions go on, and a record the database cannot take is dropped and counted. |
block: once 4,096 records wait, each new server decision waits up to 25 seconds for room and is then refused, so nothing runs without its record. |
| Network and servers | ||
| Main listener#server. |
127.0.0.1:8420, this machine only. |
:8420, every interface. |
| Phone approver listener#server. |
On at the first start on port 8443, every interface, with a self-signed certificate it creates in the data directory. | Off until you configure it. |
| Plain HTTP on the main listener#server. |
Served with no warning. | Served, with a warning in the log at every start. |
The signed policy at /v1/snapshot# |
Served to anyone who reaches the listener, with no token. | Served only to a checked-in session. |
An MCP server at a loopback address such as 127.0.0.1#apps. |
Allowed. | Refused until you set the key. |
| An MCP server that runs as a command# | Runs as a child process of strazad. | Refused, with no setting to allow it. Run the server as its own service and add it over HTTP. |
| Data | ||
| Database#store. |
SQLite, in the data directory. | Postgres, at the address in store.dsn. |
| Transcript bodies in an S3 bucket#capture. |
Refused at start. Bodies stay in the database. | Accepted with type: s3. |
Every row has its own address, such as #offline for the client that cannot reach strazad, so a guide can link to the one difference it depends on.
The same in both profiles
Some defaults are often taken for differences and are not. Both profiles run the event bus inside strazad, with no network socket, until you set events.embedded: false and events.url. A session lasts at most 12 hours and a device credential 30 days in both, as Lifetimes and timeouts lists. The audit sentinel is off, a person may publish their own change, and every approval setting starts from the same value.
The same decision rules hold in both profiles. An MCP tool call that no rule matches runs when one of the caller’s roles has access to the tool, and is denied when none has. An event kind Straza does not know is denied before any rule is read. The break-glass admin exists on every database, whatever the profile.