Join our Newsletter — 33% off our NHI Course

Monthly High Watermark

The monthly high watermark is the highest number of users present in a client organisation at any point during a billing month. MSPs use this value to determine the billing quantity, so charges reflect peak usage rather than end-of-month headcount. It is a common control for avoiding underbilling when users are added and removed within the same cycle.

Expanded Definition

Monthly high watermark is a billing measurement that records the peak number of active users seen during a monthly cycle, not the ending user count. In managed service agreements, that distinction matters because the charge basis tracks the highest operational footprint a customer reached, even if accounts were later removed before month end. That makes it different from average usage, current active headcount, or licensed seat inventory.

For NHI Management Group, the security relevance is indirect but real: whenever access, user provisioning, or agent permissions expand and contract quickly, billing data can become a proxy for how rapidly identities and entitlements are changing. That is why monthly high watermark reporting often sits alongside access governance, joiner-mover-leaver processes, and service reconciliation. The concept is operational rather than regulatory, but it still benefits from the disciplined control mindset reflected in the NIST Cybersecurity Framework 2.0, especially where inventories and accountability must stay accurate.

The most common misapplication is treating end-of-month active users as the billing basis, which occurs when organisations reconcile usage only after removals have already lowered the final count.

Examples and Use Cases

Implementing monthly high watermark billing rigorously often introduces reconciliation overhead, requiring organisations to weigh billing accuracy against the administrative cost of tracking intra-month user movement.

  • A SaaS provider adds 40 temporary analysts mid-month, then offboards 20 before renewal. The customer is billed on the peak 40-seat increase, not the reduced month-end number.
  • An MSP manages shared admin access for a client. When a project creates a short-lived spike in privileged accounts, the billing record captures the highest number of active users during the month.
  • A platform with automated provisioning syncs identity changes from an HR system. The watermark becomes the audit point for confirming that short-term access was reflected in the invoice.
  • A customer disputes a charge after seeing fewer active users on the final day. The provider uses time-stamped usage logs to show the peak count occurred earlier in the billing window.
  • In environments with agentic AI tools or non-human identities, vendors may apply the same peak-count logic to named seats or managed entities, but definitions vary across vendors and contracts, so the billing method should be written explicitly.

Where usage is tied to identity events, monthly high watermark can be supported by evidence from access logs, provisioning systems, and entitlement reports. Guidance from frameworks such as the NIST Cybersecurity Framework 2.0 is useful when customers expect a defensible record of how counts were derived.

Why It Matters for Security Teams

Security teams should care because billing metrics can reveal whether identity governance is under control. Sudden watermark spikes may indicate provisioning drift, orphaned accounts, shared access patterns, or short-lived privileged activity that was not properly reviewed. In NHI and agentic AI environments, the same issue can surface when machine identities or autonomous agents are added faster than inventory and ownership records are updated.

That creates both cost and assurance risk. If a provider cannot explain why a watermark increased, it may also struggle to explain who had access, when access was granted, and whether removals were completed on time. In practice, high-watermark disputes often expose weak joiner-mover-leaver processes, incomplete asset records, or delayed synchronization between identity platforms and billing systems.

Organisations typically encounter the operational impact only after an invoice challenge, at which point the monthly high watermark becomes unavoidable to validate usage, access history, and entitlement accuracy.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 ID.AM Asset and inventory management supports accurate user and identity counts for billing and assurance.
NIST SP 800-53 Rev 5 AC-2 Account management underpins the lifecycle events that drive monthly high watermark changes.
NIST SP 800-63 Digital identity assurance is relevant when user counts depend on verified account lifecycle records.
OWASP Non-Human Identity Top 10 NHI inventory and ownership gaps can distort peak counts when non-human accounts are billed as entities.
NIST AI RMF AI RMF governance is relevant where agentic AI seats or tool-using agents affect monthly usage counts.

Keep identity and service inventories current so peak-user billing can be reconciled against real usage.