Applies to: MAS 8.x, 9.0, and 9.1
You are here because you need a number, or because a renewal quote came in higher than you expected, and IBM's licensing page reads like it was written for a contract lawyer, which is not much help to the person who has to make the number work.
AppPoints confuse almost everyone the first time, and it is not your fault. IBM documents the model accurately and organizes it for their license agreement, not to be something you work off of. The math you need is split across three different sections of the page, every tier has two numbers depending on a setting most people do not realize they are choosing, and the costs that can blow up a budget are buried in text between paragraphs about service providers and indirect access. By the time you find what you need, you are not sure you read it right.
I have sized AppPoints for shops running 40 users and shops running several thousand across multiple sites. This is the model, the traps, and how to put a real number on your own Maximo needs. I keep it platform-neutral on the concepts and specific where Maximo behavior matters. Everything here is current as of MAS 9.1, and I flag what changed from 9.0 at the end. Every number comes straight from IBM's published licensing documentation, and I link both pages at the end so you can check them against your own contract.
An AppPoint is a pool, not a seat
Here is the first thing to wrap your head around, because most people start with the wrong mental model. An AppPoint is not a per-user license. It is a unit of value in a shared pool. You buy a quantity of AppPoints, and every user, every administrator, and certain installed components draw from that pool based on what they are entitled to use.
That changes how you think about buying AppPoints. You are not counting heads and multiplying by a price. You are adding up what every user costs in points, adding the install costs on top, and making sure the pool covers the total. Two shops with the same headcount can need wildly different pools depending on what those people do in the system.
The reason that matters: a single user who needs one extra application can cost you three times what their coworker costs, and you will not see it unless you understand the tiers.
Everything pulls from one shared pool, not separate buckets. Users draw by tier, installs come off the top as a fixed cost before you license a single person.
The three tiers decide almost everything
Every user is assigned to one of three tiers. The tier controls what they can do and how many points they consume. Get the tier assignment right and the rest is arithmetic. Get it wrong and you either overpay or fail an audit.
Limited is your read-and-update tier. A Limited user can view records across every module, run and view reports, change record status, update work orders assigned to them, and complete inspections. On top of that, they get full use of any three Manage modules they choose, with one important exception: the three cannot be Planning and Scheduling, Administration, Integration, Security, or System Configuration. Those are reserved for higher tiers. Limited users can also get Maximo Mobile, within their three modules, and Maximo Monitor. This is the right tier for the bulk of a maintenance workforce: technicians who close their own work orders, do inspections on a phone, and look things up.
Base is your full-operator tier. A Base user gets everything Limited gets plus the modules Limited cannot touch: Planning and Scheduling, Administration, Integration, Security, and System Configuration. Base also includes Maximo Health. This is the tier for planners, schedulers, supervisors, and reliability folks who live in the system all day and need the planning and configuration applications. Base does not include the industry solutions or add-ons.
Premium is everything. A Premium user can be granted access to any application in the suite except the suite administration page itself. That includes the industry solutions (Aviation, Transportation, Utilities, Nuclear, Oil and Gas, Civil Infrastructure), the add-ons (Asset Configuration Manager, Service Provider, Health Safety and Environment), Maximo Predict, and Maximo Visual Inspection. If a user needs any of those, they are Premium, full stop.
| Tier | Includes | Cannot access | Typical role |
|---|---|---|---|
| Limited | View across all modules, status change, update assigned work orders, inspections, reports, plus full use of any 3 Manage modules. Mobile and Monitor available. | Planning and Scheduling, Administration, Integration, Security, System Configuration (none can be one of the 3 modules) | Technicians, inspectors |
| Base | Everything Limited has, plus Planning and Scheduling, Administration, Integration, Security, System Configuration, and Maximo Health. | Industry solutions and add-ons | Planners, schedulers, supervisors, reliability |
| Premium | Any application in the suite except suite administration. Includes industry solutions, add-ons, Predict, and Visual Inspection. | Suite administration only | Anyone needing an IS, add-on, Predict, or MVI |
Not sure which tier a given user lands in? That is what the Access and License Quick-Score is for. Tell it which applications a user needs and it returns the tier they will be licensed at, so you can sort a whole user list without second-guessing each one.
The ratios, and the number everyone misreads
Now the arithmetic. Each tier has a point cost, and this is where IBM's page trips people up, because every tier has two costs depending on whether you license the user as Authorized or Concurrent.
An Authorized user is a named person with a dedicated set of AppPoints. Those AppPoints are allotted to that one person and cannot be shared. A Concurrent user still requires AppPoints, but instead of being permanently assigned, they are loaned out to the user while they are logged in and returned when the user logs out. The pool counts the points allotted to Authorized users and installs, and then with what is left it counts the maximum number of people accessing the system at the same time as Concurrent users, regardless of how many named people there are. Ten people who share five concurrent slots because they never log in at the same time cost you five concurrent licenses, not ten.
| Tier | Authorized (per named user) | Concurrent (per simultaneous user) |
|---|---|---|
| Limited | 2 AppPoints | 5 AppPoints |
| Base | 3 AppPoints | 10 AppPoints |
| Premium | 5 AppPoints | 15 AppPoints |
| Base administrator | 10 AppPoints | Authorized only |
| Premium administrator | 15 AppPoints | Authorized only |
The mistake I see constantly: someone grabs the Limited number as 5 without noticing that is the Concurrent rate, then budgets every technician at 5 points when their Authorized rate is 2. On a 200-technician shop, that is the difference between 400 points and 1,000. Remember that before you do any math.
So which do you choose? Authorized makes sense for dedicated daily users: planners, schedulers, anyone in the system every shift. Concurrent makes sense when your logged-in-at-once count sits well below your headcount, which is the classic shift-work pattern. Say you have 100 technicians across three shifts and never more than 35 are logged in at once. Authorized costs 100 x 2 = 200 points. Concurrent costs 35 x 5 = 175. Concurrent is the better financial option, but only because the simultaneous count is low relative to headcount. Run the same comparison for your dedicated office users and Authorized almost always wins. You can mix both in the same environment, and you should.
You do not have to run that comparison by hand for every group. The Concurrency Calculator takes a population's headcount and its peak simultaneous logins and tells you whether Authorized or Concurrent costs less at each tier. Run your field crews through it and the answer is usually obvious.
Administrators have their own rates: a Base administrator costs 10 AppPoints, a Premium administrator costs 15, both as Authorized entitlements. And admin points behave differently, which I get to in the gotchas.
Install AppPoints: the cost people forget
Users are not the only thing that pulls from the pool. Several components cost a fixed number of AppPoints just to install, separate from any user licensing. Miss these in your sizing and you will come up short.
| Component | Install AppPoints |
|---|---|
| Maximo Spatial | 20 |
| Maximo Civil Infrastructure | 50 |
| Maximo Optimizer | 220 (or 60 for Optimizer Limited) |
| Maximo Visual Inspection | 45 |
| Maximo Visual Inspection Edge | 1 per device |
| Connector for SAP, Oracle, or Workday | 80 each |
| Connector for TRIRIGA | 0 |
| Connector for Envizi | 0 |
| MREF Reserve (9.1): Limited / Base / Advanced | 20 / 120 / 200 |
A couple of these are big enough to reshape a buy on their own. Optimizer at 220 install points is not a casual addition. Visual Inspection at 45 plus Premium users on top adds up fast. If you are scoping a deployment that includes any of these, price the install points first, because they are fixed and they come off the top of your pool before you have licensed a single user.
The gotchas that wreck your count
The tiers and ratios are the easy part. These are the things that can quietly change your number after you thought you were done.
Some industry-solution or add-on applications force Premium. This is the big one. If your environment has an industry solution or add-on installed, and you grant a user access to even one of those applications, that user cannot be Base. They are either Limited or Premium. According to the AppPoint documentation, there is no Base tier for industry-solution access. So the planner you budgeted at Base because they mostly do planning, but who also needs one Transportation application, just jumped to Premium. That is 3 points becoming 5 on every affected user, and it is a common reason a real count comes in over the estimate.
Maximo decides the tier from security groups, not from a dropdown. You do not pick a user's tier directly. Maximo calculates it from the user's security group membership and the applications those groups grant. Here is the part that bites: when you combine security groups, access widens. The most permissive grant wins. So a user in two groups gets the combination of what both allow, and if one of those groups quietly includes a Premium-only application, that user is now consuming Premium points no matter what you intended. One over-broad group, copied around, can push dozens of users up a tier. You can see the resulting tier impact in the Security Groups application. Do not try to read it by querying the field directly, because the license impact value is calculated, not stored, and you will get nothing useful. This is exactly why AppPoints and security group design are the same problem, and why you cannot right-size one without the other.
Administrators reserve their points continuously. An administrator's AppPoints are held out of the available pool at all times, the same way an authorized user's are, so the admin always has access. They do not share or float. One bonus worth knowing: an administrator who holds a tier entitlement can be granted higher application access without spending more points. A Base administrator, at 10 points, can be given Premium application access, including Maximo Predict, without paying the additional Premium difference. It is a small lever, but on a tight pool it is real.
Self-service is free. Self-service applications consume zero AppPoints. Entering and viewing service requests, creating and viewing requisitions in Desktop Requisitions, the Mobile Service Request app, and several industry-solution incident and condition-report functions all cost nothing. If you have a population of people who only ever submit requests, do not assign AppPoints to them. This is the cheapest tier of all, and it is the one shops forget exists.
Indirect access still needs a license. If a third-party system or custom front end writes to Maximo, and Maximo is the source of truth for that data, the people driving those writes need licenses even though they never log into Maximo directly. Updating a work order through a third-party mobile app, creating or changing asset records, changing record status: all of it counts. The flip side is the part that saves you money: if the other system is the master of the data and it just syncs into Maximo for reference, no license is required. The Maximo Integration Framework running as the integration admin user does not need a user license either. The test is always which system owns the data, not which screen the person is looking at.
| Watch for | What it does to your number |
|---|---|
| IS or add-on access | Forces the user to Premium. There is no Base tier for industry-solution or add-on access. A Base user who needs one such app becomes Premium. |
| Security groups | Maximo derives the tier from group access, and the most permissive grant wins. One over-broad group can push users up a tier. Read the impact in the Security Groups application, not by querying the field. |
| Administrators | Reserve their points continuously. A Base admin can be granted higher app access, including Predict, without paying the Premium difference. |
| Self-service users | Cost zero AppPoints. Do not assign points to people who only submit and view requests. |
| Indirect access | If a third-party system writes to Maximo and Maximo owns the data, those users need licenses even if they never log in. If the other system owns the data and only syncs in, no license. |
What changed in 9.1
If your reference point is 9.0, a few things shifted in 9.1 that affect sizing. IBM's MAS 9.1 licensing page carries the full detail, and here is what matters most.
Maximo Real Estate and Facilities (MREF) joined the suite with its own tier structure, including a Self-Service tier on top of Limited, Base, and Premium, plus Reserve install points (20 for Limited, 120 for Base, 200 for Advanced). Maximo IT moved into the Base tier's included applications. Maximo Assist was renamed Maximo Collaborate. And IBM added the Maximo AI Service, which is licensed in a new unit called content tokens: one billion content tokens per month converts to 10 AppPoints, billed on actual usage. If you are planning to turn on the AI assistant features, that is a consumption-based line you did not have in 9.0, and it behaves differently from every other item here because it scales with use rather than with a fixed install or user count.
The user ratios themselves did not change. Limited, Base, and Premium cost the same in 9.1 as they did in 9.0 and 8.x.
How to size your own AppPoints
Here is the sequence I use. Work it in this order and you will not double-count or miss a category.
- Inventory your install components first. List anything that costs install points: Spatial, Optimizer, Visual Inspection, the ERP connectors, MREF Reserve. Add those fixed costs up. This is your floor before any users.
- Sort your people into the four buckets, not three. Self-service (request submitters, zero points), Limited (view, update assigned work, inspections, three non-restricted modules), Base (full operators who need planning and configuration but no industry solutions), Premium (anyone touching an IS, add-on, Predict, or MVI). The self-service bucket is the one people skip, and it is basically free money.
- Apply the IS and add-on rule before you finalize Base. Walk back through your Base list and ask whether each person needs any industry-solution or add-on application. Every yes moves to Premium. Do this deliberately, because it is the step that changes the answer.
- Choose Authorized or Concurrent per bucket. For each bucket, compare named headcount at the Authorized rate against peak-simultaneous count at the Concurrent rate. Pick the cheaper one. Dedicated office users almost always land on Authorized. Shift-based field crews are where Concurrent can pay off.
- Add administrators on top. Count your Base and Premium admins at 10 and 15 points. Remember they reserve continuously, so they are never part of a concurrent pool.
- Sum it and add headroom. Total the install points, the four user buckets, and the admins. Then add 10 to 20 percent for growth and for the user who inevitably needs one more application next quarter. Running your pool at exactly 100 percent means the next hire fails to get access until you buy more.
That is the manual version, and it is worth doing once by hand so you understand the shape of your own license. To work it on paper, the free AppPoints Sizing Guide and Worksheet lays out every tier, ratio, and install cost on one reference, with a fill-in worksheet and a worked example. After that, the AppPoints Estimator runs the same sequence for you: enter your user counts by bucket, your Authorized or Concurrent choice, and your install components, and it returns a total pool with the install points, the four user buckets, and admins broken out. It is the fastest way to build a defensible number before a renewal conversation.
That sample utility is a useful gut check. Sixty field technicians, the largest group by far, cost the least per head at 2 points each. The three reliability engineers who need Predict cost more than twice that per person because Predict drags them to Premium. The shape of a maintenance license is usually a wide, cheap Limited base with a small, expensive Premium cap on top. If your estimate looks inverted, with most of your points going to a small group, go back and check whether an IS or add-on quietly pushed your operators to Premium.
What good looks like
You will know your sizing is sound when three things are true. Your tier assignments match what people actually do, not what their title implies, because Maximo charges for access, not job descriptions. Your security groups are clean enough that nobody is consuming a higher tier than they need through an over-broad group they happened to inherit. And your pool has enough headroom that onboarding a new user is a same-day action, not a procurement cycle.
If you cannot currently see who is consuming what tier and why, that is the gap to close first. IBM's License consumption report in Suite administration shows your actual AppPoint usage over time, which is the place to start. The number on your renewal quote is the output. The security group design is the input, and it is where the money is won or lost.
If you already suspect you are over-licensed, put a number on it. The AppPoint Value Recapture calculator takes your current pool and your right-sized pool and shows the AppPoints and the annual cost you would recover by closing the gap. That figure is usually what gets a right-sizing project funded.
Check the numbers against IBM
I would rather you trust the math than take my word for it. Every figure above comes from IBM's published licensing guidance. Here are both pages:
Each page links a PDF version near the top if you want a copy to keep. If a number here ever disagrees with IBM's page, trust IBM's page, and let me know on LinkedIn so I can correct it for everyone else.
Where this goes next
This article covers the AppPoints model: the tiers, the ratios, the install costs, the traps, and how to put a defensible number on your operation. That is enough to read your own entitlement, sanity-check a quote, and have an informed conversation with IBM or your reseller. I am giving you the shape of the decision, not financial advice. The number that matters is the one on your quote, not the one in this article.
If you are doing this for real, against your own user list and your own security groups, that is a project, not an afternoon. The AppPoints and Security Groups Right-Sizing Workshop and the companion Playbook walk through the full exercise: building the user inventory, mapping every role to the right tier, redesigning security groups so they stop inflating your consumption, and producing the defensible AppPoint count you take into a renewal. The free model here tells you how the system works. The Workshop and Playbook do the work of right-sizing your specific environment and holding the number down year over year.
Frequently Asked Questions
What is a Maximo AppPoint?
An AppPoint is a unit of value in a shared pool, not a per-user license. Every user, every administrator, and certain installed components draw from that one pool based on what they are entitled to use. You size a license by adding up what each user costs in points, adding install costs on top, and covering the total with headroom to grow.
What are the three Maximo AppPoint tiers?
Limited, Base, and Premium. Limited is the read-and-update tier for technicians and inspectors, with full use of any three non-restricted Manage modules. Base adds Planning and Scheduling, Administration, Integration, Security, System Configuration, and Maximo Health for full operators. Premium covers everything else, including industry solutions, add-ons, Predict, and Visual Inspection. Needing any of those forces a user to Premium.
What is the difference between Authorized and Concurrent AppPoints?
An Authorized user is a named person with a dedicated set of AppPoints that are not shared. A Concurrent user draws points from a shared pool only while logged in and returns them at logout, so the pool only has to cover the peak number on at once. Limited costs 2 Authorized or 5 Concurrent, Base costs 3 or 10, and Premium costs 5 or 15. Mixing up the two columns is the most common sizing error.
What pushes a Maximo user to a higher AppPoint tier?
Access drives the tier, and the most permissive security group wins. Granting a user even one industry-solution or add-on application forces them to Premium, because there is no Base tier for that access. One over-broad security group copied across users can quietly push a whole population up a tier. Maximo calculates the tier from group access, so read the impact in the Security Groups application rather than querying the field.
Quick Maximo questions are always free. Reach out on LinkedIn. I never charge for chatting.