STRAZAdocs

Standalone and enterprise compared

Every difference between the two profiles in one table, with the setting that changes each one.

On this page

Straza runs in one of two profiles. Standalone is the default and suits one machine or a small team: it signs people in itself, keeps its data in SQLite and needs nothing else installed. Enterprise expects your identity provider and a Postgres database, and a shared NATS server once you run more than one replica, as the enterprise shape shows.

You choose the profile with profile in the configuration file, the STRAZA_PROFILE environment variable, or strazad serve --profile. The profile only picks defaults. A row that names a setting changes when you set that key, and the configuration reference gives each key’s environment variable. A row with no setting is fixed by the profile.

What differsStandaloneEnterprise
Sign-in and users
Who signs people in#oidc.issuer Straza’s own sign-in page, with a password and a one-time code. Clients use it even when oidc.issuer is set. Your identity provider, named in oidc.issuer. Until you set it, strazad still starts and every sign-in fails with no login issuer configured.
The break-glass admin# Created at the first start, with its password printed once in the log. It signs in on the same page as everyone. Created at the first start in the same way. Straza’s own page signs in this account and no other, under the title Emergency sign-in to Straza.
The first admin#oidc.bootstrapAdmin admin, created on an empty database at the first start. Its password is printed once in the log. The user named in oidc.bootstrapAdmin, at their first sign-in through your identity provider, while no other person holds straza-admin. No password.
A person your identity provider signs in who has no user in Straza yet#oidc.jitProvision Gets a user at that sign-in. Is refused. Your identity manager creates the user over SCIM first.
How an AI agent signs in# With a key of its own that an admin registers, checked by Straza’s own sign-in. With its own client at your identity provider, from STRAZA_CLIENT_ID and STRAZA_CLIENT_SECRET, or with a registered key of its own.
The rate limit on the token endpoint where AI agents sign in#server.loginPerIPRPS None. The limit covers the password form only. The same limit as the password form, 2 requests per second for each client address by default.
Decisions
A local tool call that no rule matches#governance.localToolDefault allow deny
A policy on a new install# standalone-starter, seeded on an empty database. It denies recursive force-delete, such as rm -rf. None. You write the first policy.
A client that cannot reach strazad#governance.offlineGraceTTL Keeps deciding from its last signed policy until 15 minutes after its session token expired. Denies every governed call as soon as its session token expires.
The lowest install a session accepts#governance.minAttestation none: any install. managed: an install whose files match the hashes you registered.
Audit records while the database is down#governance.auditBackpressure drop-with-counter: decisions go on, and a record the database cannot take is dropped and counted. block: once 4,096 records wait, each new server decision waits up to 25 seconds for room and is then refused, so nothing runs without its record.
Network and servers
Main listener#server.listen 127.0.0.1:8420, this machine only. :8420, every interface.
Phone approver listener#server.approverTLS.autoMint On at the first start on port 8443, every interface, with a self-signed certificate it creates in the data directory. Off until you configure it.
Plain HTTP on the main listener#server.tls.certFile Served with no warning. Served, with a warning in the log at every start.
The signed policy at /v1/snapshot# Served to anyone who reaches the listener, with no token. Served only to a checked-in session.
An MCP server at a loopback address such as 127.0.0.1#apps.allowLoopbackUpstreams Allowed. Refused until you set the key.
An MCP server that runs as a command# Runs as a child process of strazad. Refused, with no setting to allow it. Run the server as its own service and add it over HTTP.
Data
Database#store.driver SQLite, in the data directory. Postgres, at the address in store.dsn.
Transcript bodies in an S3 bucket#capture.bodyStore.type Refused at start. Bodies stay in the database. Accepted with type: s3.

Every row has its own address, such as #offline for the client that cannot reach strazad, so a guide can link to the one difference it depends on.

The same in both profiles

Some defaults are often taken for differences and are not. Both profiles run the event bus inside strazad, with no network socket, until you set events.embedded: false and events.url. A session lasts at most 12 hours and a device credential 30 days in both, as Lifetimes and timeouts lists. The audit sentinel is off, a person may publish their own change, and every approval setting starts from the same value.

The same decision rules hold in both profiles. An MCP tool call that no rule matches runs when one of the caller’s roles has access to the tool, and is denied when none has. An event kind Straza does not know is denied before any rule is read. The break-glass admin exists on every database, whatever the profile.

Search documentation

Search page titles, commands, and article text.

↑ ↓ Choose resultEnter OpenEsc Close