Portal feature cost
Portal RBAC and SSO Cost in 2026: Enterprise Tier Add-On Math
Most commercial developer portals gate SAML SSO, SCIM provisioning, and granular RBAC behind enterprise tiers that run 2x to 4x the standard rate. Here is a vendor-by-vendor breakdown of the enterprise tier jump, what it buys you, and what the self-hosted Backstage build equivalent costs as a comparison anchor.
Typical enterprise jump
2x-4x
over standard tier per-seat rate
Self-hosted build
$30K-$80K
platform-team one-time build cost
Enterprise add at 100 devs
$50K-$150K
annual cost above standard tier
The SSO Tax Pattern
The pattern is consistent across the developer portal market and across SaaS more broadly: SAML SSO, SCIM provisioning, and granular role-based access control are gated behind enterprise tiers that run materially higher than the standard tier. The technical cost of providing SSO is modest (the vendor integrates with an identity provider library and exposes a configuration UI); the commercial cost-allocation reflects buyer willingness-to-pay rather than vendor cost-of-service.
This pattern has been named the SSO tax by industry observers and has its own dedicated community resources (the sso.tax project tracks vendors that gate SSO behind enterprise tiers). The developer portal market is no exception. Cortex, Port, OpsLevel, Roadie all follow the pattern; the precise multiplier varies but the structural treatment is the same.
The honest framing for procurement: if SSO is a hard requirement, the enterprise tier is the only option on commercial portals. The negotiation lever is not whether you pay for SSO; it is how much SSO costs and what else is bundled with it at the enterprise tier.
What Each Vendor Publishes Below Enterprise
None of the four publishes an enterprise-tier rate, so the size of the jump is not a knowable number and we do not print one. What you can price is the rung below it, and that is what this table does. Every figure is a published list price checked 1 October 2026; the enterprise column is deliberately blank because that is the honest value.
| Vendor | Highest published tier | Published rate | Enterprise tier |
|---|---|---|---|
| Cortex | 50 Users SaaS Hosted (AWS Marketplace; no tier names published) | $39,000/yr $65.00/user/mo | Quote only. Not published. |
| Port | Standard, up to 200 seats (own pricing page) | from $40/seat/mo Port words it "starting at" | Quote only. Not published. |
| OpsLevel | 100 Users SaaS (AWS Marketplace); Standard and Enterprise both quote-only on its own page | $46,800/yr $39.00/user/mo | Quote only. Not published. |
| Roadie | Teams, 50 to 150 developers (own pricing page, existing subscribers only) | $24/dev/mo $22.00 on AWS Marketplace | Growth tier, quote only. Not published. |
The one published discount in the set is Cortex's, and it is a term discount rather than a tier discount: its marketplace listing offers up to 40 percent off on a 24-month contract and up to 46 percent on a 36-month. OpsLevel states that volume discounts are available but publishes no percentage. The practical move is to ask each vendor to quote the published tier and the enterprise tier side by side at your seat count, and to list which named controls (SAML SSO, SCIM provisioning, entity-level and action-level RBAC, audit-log retention and export) move between the two. That named-control delta, not a multiplier, is what tells you whether the jump is worth paying for.
What Granular RBAC Actually Buys
The RBAC capabilities that distinguish enterprise tiers from standard tiers fall into three categories. Team-level access controls determine which teams can see which entities. Most standard tiers include this; the enterprise upgrade is rarely about basic team-level visibility. Entity-level controls determine whether specific sensitive services or catalogue entries are hidden from non-owner teams; this is the first meaningful enterprise upgrade. Action-level controls determine who can run which self-service actions, who can edit which catalogue entries, who can author which scorecards; this is the deepest enterprise upgrade.
Whether the granularity is worth the price jump depends on the organisation's actual compartmentalisation requirements. Financial services with regulated trading-system separation, healthcare with PHI-access compartmentalisation, defence contractors with classified-data handling all have genuine requirements that team-level access cannot satisfy. Most non-regulated organisations do not have these requirements and end up paying for granular RBAC capabilities they never configure.
The procurement framing: do not buy enterprise tier specifically for the RBAC granularity unless you can name the specific compartmentalisation policy that requires it. Standard-tier team-level access is sufficient for the majority of buyers; the enterprise jump should be justified by SSO and SCIM requirements rather than by RBAC granularity assumed to be needed later.
Self-Hosted Backstage as Comparison Anchor
On self-hosted Backstage, RBAC and SSO are not licence costs; they are engineering costs. SAML SSO integration with standard providers (Okta, Auth0, Azure AD) is roughly 1 to 2 engineer-weeks. SCIM provisioning is 2 to 4 engineer-weeks because the upstream identity-provider integration requires more careful design. Granular RBAC beyond team-level uses the Backstage permissions framework, which is roughly 4 to 8 engineer-weeks of platform-team setup for a meaningful policy with the right unit tests and operational tooling.
Total self-hosted RBAC and SSO build cost: $30,000 to $80,000 of platform-engineer time as a one-time investment, plus modest ongoing maintenance. Compared against the $50,000 to $150,000 per year enterprise tier add-on on a commercial portal, the build economics look favourable. The trade-off: the build is platform-engineer time you have to allocate, the build risk (getting SSO and RBAC right is a non-trivial security exercise) is real, and the long-term operations of the built RBAC and SSO layer are on your team. Most organisations buy at enterprise tier rather than building, and pay the SSO tax as the cost of avoiding the build risk.