Finlay.worksBareBones Ticketing manual

Licensing

Everything on this page happens in Admin SettingsProduct License. This is the last install step: after it, people can use the product.

Before you start

  • Signed in as a System Administrator. See First administrator.
  • A licence key, obtained through your organization's commercial process. This manual does not tell you where to get one.
  • Approval from your licence owner to consume an activation.

Step-up verification

Product License requires step-up verification before any change: proving your identity again, recently, immediately before a sensitive action. It grants you nothing new — it confirms that the permissions you already hold are being used by you, now.

Without a recent step-up the page still opens and still reports status, but the licence controls are not shown at all — no key field and no action buttons. In their place is a note that licence changes still require step-up, with a button to Open Admin Settings. Complete the verification there and return.

Enter and activate the licence

  1. Open Admin Settings, then Product License.

  2. Complete step-up verification if the licence controls are not shown.

  3. Enter the licence key.

    Add an installation label if your procedure uses one. The label is not secret, so do not put a customer secret, username, private address, or raw hostname in it.

  4. Select Save key and verify, once.

    The product stores the key, then asks the licensing service what it entitles. Check that the edition, expiry date, worker limit, and activation limit that come back are what you expected.

  5. Select Activate installation, once.

    This registers this installation against the key and consumes one activation. Wait for the result. Do not click it again or open a second request.

  6. Read the Product use summary.

The three cards

The top of the page shows three cards: Product use, Returned entitlement, and Installation.

Card What it reports
Product use Whether the product's already-authorized functions are enabled on this installation.
Returned entitlement What the licensing service last reported for the stored key: edition, status, and expiry. This is the last answer received, not proof that the service is reachable now.
Installation Activated or Activation needed for this installation.

Product use is the combination of four conditions, each checked separately. All four must hold.

Condition What it means What it does not mean
A key is stored The key is stored on this installation. The licensing service has accepted it.
The entitlement is active The licensing service reports the key as active, or unavailability grace is in force. The service merely answered. An expired key returns complete details and is not active.
This installation is activated Activation proof exists for this installation and is less than 30 days old. The installation was never registered. Proof older than 30 days reports as not activated until a heartbeat refreshes it.
Workers are within the limit The counted worker total is at or below the returned limit. Any person can see any ticket.

Two of these catch people out. A key that has expired still returns edition, expiry, and limit details, so details on the screen are not proof of an active entitlement — an expired key yields the ReadOnly state. And an installation that was genuinely registered reports as needing activation once its proof goes stale; run a heartbeat to refresh it.

That last cell matters too. Reaching allowed product use turns the product on for the organization. It grants no individual access to anything. Access is configured separately.

Check it worked

  • Product License shows the key redacted, never in full.
  • Edition, expiry, worker limit, and activation limit are visible and match what you expected.
  • The installation shows as activated.
  • Product use reports whether use is allowed.

Never copy the licence key, any part of it, the installation fingerprint, a password, a request or response body, a cookie, a token, payment data, or a private address into notes, tickets, or evidence.

The four licensing actions

Action Use it when What success means
Verify stored key You want current entitlement details without creating activation proof. The service returned the key's edition, status, and limits. Product use may still be blocked.
Activate installation The key is stored and this installation needs activation proof. The service registered or refreshed this installation's binding.
Run heartbeat This installation is already activated and its proof needs refreshing. The service refreshed this installation's activation proof.
Deactivate installation You intend to release this installation's binding. The service processed the deactivation. Local activation proof and product use stop.

Run one action at a time. Read the result. Stop if the product reports backoff or a hard denial.

Heartbeat

A heartbeat refreshes this installation's activation proof against the licensing service. It is not a health check, a backup check, or an uptime guarantee, and it does not extend entitlement.

  • Activation proof stays current for at most 30 days.
  • If the licensing service is unreachable or has rate-limited this installation, the product can allow use for at most 72 hours of grace. Grace applies to those two states only. Expiry, a hard denial, a licence clear, a deactivation, or worker use above the limit all end that grace earlier.
  • Worker overage blocks product use and cannot use grace at all. If the service is unreachable while you are over the worker limit, the product clears any stored grace deadline and continues to block use.

To run one:

  1. Confirm the page shows current activation proof for this installation.
  2. Complete step-up verification if the controls are not shown.
  3. Select Run heartbeat, once.
  4. Read the returned state, expiry, and limits.
  5. If the result is rate-limited or unavailable, wait for the displayed next-attempt time. Do not retry in a loop.

Nothing refreshes activation proof on its own — schedule the heartbeat yourself. There is no background service that runs a heartbeat; the only thing that refreshes activation proof is a person selecting Run heartbeat (or the equivalent SystemAdmin API call). Because proof lapses after 30 days and a lapse reports the installation as not activated, put a recurring reminder on your own calendar or automation to run a heartbeat well inside that window — every one to two weeks is comfortable. Do not wait for day 30.

Deactivation

Deactivation releases this installation's binding so the activation can be used elsewhere.

  1. Confirm your organization intends to release this binding and accepts that product use stops afterwards.
  2. Confirm you are on the right installation.
  3. Complete step-up verification if the controls are not shown.
  4. Select Deactivate installation, once.
  5. Confirm the installation no longer shows activation proof and that product use is blocked.

Local activation proof is cleared when the call to the licensing service is made and fails. It is not cleared if the product refuses to make the call at all: when a backoff window is open, Deactivate installation stops before contacting the service, and nothing changes locally or remotely. A backoff window is open in exactly the situations that lead operators to deactivate, so check the displayed next-attempt time and run the action after it passes.

The remote activation slot is released only when the service confirms it. If the call did not complete, do not assume the slot is free — have your licence owner reconcile before trying again.

Deactivation targets only this installation. It does not clear the stored key, delete any product data, or deactivate a different installation.

Worker and activation limits

The key stored on this deployment supplies its own limits. Capacity does not pool across keys, and an account-level total does not add capacity here.

Limit What it counts What it does not count
Worker limit Unique active internal users who have SystemAdmin reach, or group membership mapped through active department access to an enabled department The same person counted twice for a second access path; requester-only users; external participants
Activation limit Active installation bindings the licensing service reports for this key Workers, departments, tickets, or another key's activations

Count people, not roles, groups, memberships, or departments. Someone who is both a SystemAdmin and has three department paths is one worker.

Before granting access to more people

  1. Note the current worker count, the returned worker limit, and the remaining workers.
  2. List every active internal person who would gain SystemAdmin or department access from the change.
  3. Remove from that list anyone who already counts as a worker.
  4. Add the rest to the current count.
  5. If the result is within the limit, make the change through your normal access procedure.
  6. If the result exceeds the limit, stop. The product rejects the grant before it is saved, so that no misleading success appears in the audit trail.

This applies to every path that adds worker reach: activating a user, granting SystemAdmin, department and group access, directory mapping, and import.

If you are already over the limit

  1. Do not retry the blocked change.
  2. Check that the count, the limit, and the proposed identities are right.
  3. If access was granted unintentionally, remove only the unintended access through your normal access procedure.
  4. If the access is genuinely needed, your licence owner obtains a higher limit for this same key.
  5. When the service returns the new limit, verify the stored key once, confirm the limit, then make the access change once.

Being over the limit blocks product use even when the licence is active and the installation is activated. Existing data and authorized read access are preserved while you correct it.

Installation identity

The installation fingerprint stays the same across restarts, upgrades, activation, heartbeat, deactivation, and an ordinary local licence clear. Do not rotate or regenerate it to get around a worker limit, an activation limit, or a Trial/Free reuse denial.

If it does not work

The page uses two different vocabularies, and they do not match each other.

The enforcement state is the installation's overall licensing state. There are eight: MissingKey, Active, ReadOnly, Inactive, ActivationLimitReached, RateLimited, WebsiteUnavailable, and ConfigurationError. All eight are listed in Licence states.

The Last result field shows something else: the lowercase code the licensing service returned for the most recent call, such as rate_limited, activation_limit_reached, trial_installation_already_used, or license_not_found. Do not look for RateLimited in Last result; look for rate_limited.

RateLimited / rate_limited. Wait until the displayed next-attempt time. Do not click repeatedly and do not automate retries.

WebsiteUnavailable. The licensing service could not be reached. Check your network, DNS, and TLS path outside the product. Retry once, after the displayed backoff.

ActivationLimitReached / activation_limit_reached. Stop. Your licence owner reviews the existing activations and deactivates an old installation if that is appropriate.

ReadOnly. The entitlement has expired. Details still come back from the service and look complete, so check the expiry date. Renew through your licence owner, then verify the stored key.

Inactive / license_not_found. There is no active entitlement for the key — invalid, revoked, not found, or reuse-denied. Resolve it with your licence owner.

MissingKey. No key is stored on this installation. Save the key, then verify it.

ConfigurationError. Stop retrying. Have the product or deployment owner review the configuration.

A Trial or Free Edition reuse denial (trial_installation_already_used). Do not clear, rotate, or regenerate the fingerprint. Use your licence owner's account-resolution process. Free Edition includes no support entitlement.

You deactivated by accident. There is no local rollback. Confirm intent and current limits with the licence owner, then activate once.