Enterprise · Early access

The same vault. Governance on.

Marje Enterprise hands IT the factory layer — rules, routing, permissions, audit, identity — while your team works in the same fast, AI-aware desktop app they already love. We are shaping the rollout with early customers. If your team needs governance now, we want to hear from you.

Direct line: [email protected]
Status
Foundation shipping in the lifetime app
Audit log infrastructure live
RBAC & approval workflows live
Centralized factory push (early access)
SSO & SAML provisioning (early access)
Per-seat billing & admin console (Q2/Q3)
Why this exists

Most knowledge tools force a tradeoff. We refused.

Either the tool is fast and consumer-grade but ungoverned, or it is enterprise-grade and miserable to use. Marje keeps the desktop experience your team will actually adopt and puts governance underneath — not on top. The end user never feels the policy layer. IT sees every byte.

What you get

Eight controls IT will care about.

🔐

Two-tier governance

The factory layer is the difference. IT and compliance own the rules, permissions, routing, and rendering — centrally, encrypted, out of reach of end users. Your team customizes the surface without ever touching the underlying system.

📋

Audit logging

Every vault action logged. Who read what, when, and what Claude requested through the MCP server. Append-only. Tamper-evident. Streams to your SIEM.

👥

Role-based permissions

Three roles out of the box: Admin, Editor, Viewer. Per-folder. Per-module. Sensitive folders can require explicit per-session AI access before a tool call fires.

Approval workflows

Flag any document type to require manager sign-off before it leaves the building. The approval queue lands on the manager's dashboard with a side-by-side diff.

📡

Centralized policy push

Push factory rules to every seat in your organization from one console. Versioned. One-click rollback. Beta and stable channels, on your cadence.

🔑

SSO & SAML

Okta, Azure AD, Google Workspace, generic SAML 2.0. Map IdP groups to Marje roles. Auto-provision and auto-deprovision from your identity source.

🛡️

Data masking

Regex-based masking before any AI request. SSN, card numbers, custom patterns. The model sees [REDACTED]. Your audit log keeps the original.

Scheduled AI access

Restrict MCP access to defined windows — business hours, weekdays only, any custom schedule. Outside the window, tool calls don't fire.

Lifetime vs Enterprise

Same product. Different controls.

LifetimeEnterprise
Lifetime license, $49 one-timePer-seat, custom
Local-first vault on your machine
Built-in MCP server (bring your own Claude)
Module marketplace + cloud sync
Two-tier factory configurationYou own both layersIT controls factory layer
Centralized rule management across team
Audit logging (append-only, tamper-evident)
Role-based permissions
SSO / SAML / Okta / Azure AD
Approval workflows
Remote policy push
Data masking on AI requests
Scheduled AI access windows
Dedicated supportEmail, 24hNamed contact, SLA
How it ships

Pricing and rollout.

Pricing
Per-seat, with annual and multi-year terms. Volume tiers at 25, 100, and 500 seats. Early access pricing lands where it makes sense for the kind of team that needs governance — not where it flatters a spreadsheet.
Deployment
The same app your team already runs. Enterprise features unlock through a signed policy bundle pushed from the admin console. No second install. No migration.
Onboarding
White-glove during early access. We model your folder structure, write the factory rules, wire up SSO, and configure the audit pipeline alongside your team. Then we hand you the keys.
Support
A named contact. A defined SLA. A direct line to engineering during early access — real people who can fix things, not a tier-1 queue.
Early access

Open a conversation.

Tell us about your team. We respond within 48 hours — usually faster. Early access customers get hands-on rollout and direct input on the roadmap.

Prefer email? [email protected].