How buying MADDOX works.

There are no figures on this page. There is no self-serve checkout, no card form and no published price list, because the right level depends on what you are already running rather than on a headcount. What this page can tell you exactly is what a level is, what changing one does to a workspace, and what no level can take away from one.

Plans

Four levels. One platform underneath.

Every level runs the same software. A level can take a module away and it can never switch one on over your head, so what a rung changes is what is available to you — never how much of the work happens without somebody doing it.

Starter

The entry rung, and the only one that takes anything away.

  • Core CRM: contacts, companies, activities, lists, properties
  • Sales: deals, pipelines, quotes, forecasting, meetings
  • Reporting and custom dashboards
  • Data operations, including import, export and erasure
  • Marketing, content and the app marketplace
  • Telephony, live chat and the whole AI surface
  • Support desk, account management and IT Audit

Elite

The same software as Pro. What changes is the agreement.

  • Every module, exactly as Pro
  • Configurable AI agents, sandboxed, with a kill switch
  • Onboarding and configuration done with you, not sent to you
  • Usage, spend caps and terms set by agreement
  • Still no module gated by the level itself

Enterprise

For regulated, multi-entity and channel businesses.

  • Every module, exactly as Pro
  • Reseller and multi-workspace arrangements
  • Retention, consent and erasure policy set per workspace
  • Review, sign-off and support handled directly
  • Gates no module, permanently and by decision

The last three columns look alike because they are alike: every module gate on this ladder sits on Starter, and Pro, Elite and Enterprise take nothing away between them. What separates them is the agreement, not the software. There is no self-serve checkout either — every level starts with an invitation and a conversation, because the right rung depends on what you are already running.

The mechanism

A level is a ceiling, not a bundle.

Each rung is a row in one table, and the only thing on that row which changes what a workspace can reach is a map of module names. It is read as a deny list, and reading it that way is what makes the whole ladder safe to move somebody up and down.

Silence grants. Only an explicit denial takes something away.

A module named in the map and set to false is removed for that workspace, ahead of every other check — before the workspace’s own module registry, before its settings, before the platform default. A module that is simply absent from the map does nothing at all: availability resolves exactly as it would if there were no ladder.

A module set to true also does nothing, and that is deliberate rather than an oversight. A level cannot switch on something the workspace has switched off. “Your level includes campaigns” is a statement about the ceiling, not an instruction to the room underneath it.

  • Denied — removed everywhere, unconditionally, including for an administrator.
  • Absent — no opinion; the workspace’s own choices decide, exactly as before.
  • Set to true — also no opinion. A ceiling cannot be a floor.

What is denied today, named in full.

Starter is the only rung whose map has anything in it, and it names nine: marketing, support, content, chat, AI, telephony, accounts, IT Audit and the partner and marketplace ecosystem. Core CRM, sales, reporting and data operations stay, and the last of those is a deliberate ruling — data operations carries erasure, and putting a compliance obligation behind a paid rung would be the wrong kind of product decision.

Pro, Elite and Enterprise deny nothing. Not “nothing yet”: the rung that was written to differentiate on contract terms and limits gates no module by decision, and if that ever changes it is a new migration and a new ruling rather than a quiet edit. Nothing puts a workspace on Starter automatically either — a signup lands on Pro, which is the default rung.

The one module no level is allowed to take.

Core CRM is the only module marked as a system module and it is the declared dependency of the twelve others. A level that denied it would produce a workspace that signs in, loads, and can reach neither a contact nor a company nor an activity. The refusal is written twice on purpose: the migration that seeds the matrix refuses to write such a row, and the service that puts a workspace on a level refuses to assign one.

A malformed entry resolves towards denial rather than towards a grant. False, the string “false”, zero and null all mean taken away. A ceiling that failed to hold is a customer reaching something they are not paying for, and unlike the opposite mistake nobody ever reports it.

The boundary

Four things decide what somebody sees. You only buy one of them.

Confusing the level with the other three is the difference between a purchase order and a support call, so here they are separately.

Your own module switches, which sit under the ceiling.

Every workspace has its own registry of modules and can turn any of them off. That choice is decisive wherever the ceiling is silent, which on three of the four rungs is everywhere. Turning a module off is not a downgrade and does not touch the subscription; turning it back on does not need us.

Roles, and permissions inside a role.

Access is granted per role and, where it matters, per field. A role that should not see a margin does not get the field rather than getting a blurred value, and the same table decides whether a field is visible-but-fixed or editable. None of that is a plan feature and none of it is sold: it is on every workspace on every rung.

Four domains nothing delegated may reach, on any level.

Data-subject erasure, API keys, user and role administration, and marketplace mutation are refused to the assistant and to a support operator working inside a workspace, regardless of what the workspace pays for and regardless of the role attached to the session. This is not a permission an administrator passes — it is a refusal to build the tool registry containing those domains at all, so there is no configuration in which the assistant reaches them.

Seats and limits, which do not exist yet.

Each rung carries a second map for limits — seats, storage, request rate — and it ships empty on all four. Nothing on the platform reads a seat cap today, so nothing enforces one. We would rather write that here than let a comparison table imply a number that no code checks.

When it changes

Moving a workspace between rungs writes three things, or it writes none.

Every transition — an upgrade, a suspension, a trial, a resume — goes through one service, and that service writes the head row, the mirror on the workspace and an append-only ledger entry in a single transaction.

The ledger cannot be corrected in place.

The event row that records a change can only ever be added to, never edited: the application refuses a change and the database refuses it underneath. So the answer to “what were they on in March” is a row nobody can quietly improve. Re-assigning the level a workspace is already on still appends an entry, with the same value on both sides, because the question somebody actually asks in a support conversation is who touched this and when — not only what changed.

A trial is a status, not a rung.

Trialing, active, past due, suspended and cancelled are the five states, and they are orthogonal to which of the four levels a workspace holds. Extending a trial that has already run out gives the promised days from today rather than landing in the past and leaving somebody still locked out, which is the only shape that request ever arrives in. Resuming a workspace during a live trial lands back on trialing rather than on active, so nobody quietly loses the rest of a trial.

A closed workspace says which kind of closed it is.

A suspension is answered with 402, not 403. The difference is not pedantry: 403 says “you are not allowed to do this”, which is untrue and gives the reader nothing to act on, while 402 says “this workspace is not in service”, which is true and has an obvious remedy. A suspension also needs a written reason before the service will record it, because that reason is both what the customer is shown and what the ledger keeps.

Two doors

You can buy this from us, or from somebody who already runs your systems.

They produce the same platform. What differs is who provisions the workspace, who holds the level, and who you call.

Direct.

A signup stands the whole workspace up in one transaction: the activity-outcome vocabulary, the compliance expectation rules, the coaching advice library, the module registry, the administrator and the subscription row. If any step fails, none of it is written — there is no half-provisioned workspace to clean up, which there used to be.

Through a partner.

Every workspace belongs to exactly one reseller, and a customer who signed up here belongs to a real house-reseller row rather than to a null. A partner provisions their client’s workspace themselves, sets and changes its level, and can work inside it — on the record, with a reason attached to the session. The partner programme is the page for that side of it.

Questions

The things people actually ask.

Why are there no figures on this page?

Because there is no self-serve checkout to attach them to. Every workspace starts with an invitation and a conversation, and the right rung depends on what you are already running rather than on how many people you have. The columns that would carry a published price exist in the database, are nullable, and are read by nothing.

What changes if we move up a level?

On the ladder as it stands today, moving from Starter unlocks the nine modules Starter denies: marketing, support, content, chat, AI, telephony, accounts, IT Audit and the partner and marketplace ecosystem. Pro, Elite and Enterprise deny nothing between them, so moving between those three changes limits and contract terms rather than what is switched on.

Can a level switch a module on for us?

No, and that is by design. A level can only take a module away. If your workspace has switched something off, no rung switches it back on over your head – you do. This is what makes it safe to move a workspace up or down without auditing what it was running first.

Is there a seat limit?

Not one the software enforces. Each rung carries a limits map for seats, storage and request rate and it is empty on every rung today, so nothing reads a seat cap and nothing counts against one. If that changes it will be written on this page before it is written into a contract.

What happens to our data if we stop paying?

A suspended workspace answers 402 – not in service – rather than 403, and a suspension has to carry a written reason before it is recorded. Nothing is deleted by a suspension. Retention and erasure are separate, tenant-controlled policies described on the security page.

The level is the last decision, not the first.

Ask for an invitation and we set you up on your own pipeline, or bring us the one you already argue about and we will tell you which rung it needs.