HomeJournal › How OpenPass handles indirect access
OpenPass & Negotiation · Field Note

How OpenPass handles indirect access

Published 2026-05-29 · By OpenText Audit Defense · Buyer side only

Indirect access is the part of a software contract that catches buyers by surprise, because it charges for use by people and systems that never log in to the product at all. When a downstream application reads from a content repository, when a reporting tool queries a security platform, or when an automated process pulls data through an integration, the question is whether those interactions count as licensed use. How OpenPass handles indirect access decides whether ordinary system to system integration is treated as background plumbing or as a population of unlicensed consumers. Left undefined, indirect access is one of the largest and least visible sources of an inflated finding.

The difficulty is that modern estates are interconnected by design. Applications share data, services call one another, and integration is the normal state of an enterprise architecture. A reading of indirect access that counts every system touching a licensed product as a consumer can manufacture a finding out of architecture that exists for entirely legitimate reasons. The buyer's task is to make sure the agreement defines indirect access narrowly and clearly, before a measurement defines it broadly.

What indirect access actually means

Indirect access refers to use of a licensed product by a user or system that does not interact with it directly, but reaches it through another application, an interface, or an integration layer. The classic example is a downstream system that presents data originating in a licensed product to end users who never touch the product themselves. Whether those end users require licences, and whether the integrating system itself does, depends entirely on how the agreement defines indirect use. Where the definition is absent or vague, the vendor's measurement supplies its own, and that definition will be the broad one. Pinning this down is part of the wider discipline of fixing every term that drives a count, examined in defined metrics in an OpenPass enterprise agreement.

Modern estates are interconnected by design. A definition of indirect access that counts every system touching a licensed product as a consumer turns ordinary architecture into a finding.

Why indirect access inflates the finding

The reason indirect access is such a productive source of findings is that it is invisible until someone goes looking for it. A direct user count is bounded by named accounts; an indirect access claim can expand to include every person served by every downstream system that touches the licensed product. When a measurement counts these populations as consumers, the number can dwarf the direct user count many times over. This is the same dynamic that makes indirect access a central topic in audit defense generally, and the way it is handled across products is part of the broader method set out in the complete OpenText audit defense playbook. The defense is to insist on a definition that distinguishes genuine human consumers from the system to system traffic that simply moves data between applications.

Drawing the line at system to system traffic

The most important boundary is between human use and machine use. An integration that moves data from one system to another, with no human reading the licensed product through it, is plumbing, not consumption. A reporting layer that aggregates data for analysis is a different case from a portal that presents the licensed product's content directly to a population of users. The agreement should draw these lines explicitly, so that automated integrations and internal data flows are not counted as indirect consumers. Where the agreement is silent, the buyer should negotiate language that excludes system to system traffic from the indirect access definition, and should document the integration architecture so the distinction can be demonstrated. Keeping such terms out of the count is closely related to the work of stripping problematic language from the draft, covered in what audit clauses to remove from an OpenPass draft.

Indirect access across two governing frameworks

An OpenPass estate often spans both the content management line, governed by the OpenText end user license agreement, and the acquired Micro Focus products, mostly governed by the Additional License Authorizations. Indirect access can arise in either, but the definitions and the entitlement logic differ between the two frameworks. A reading borrowed from one framework and applied to a product governed by the other produces the wrong answer, and indirect access is exactly the kind of cross cutting concept where that confusion is easy to introduce. Reading each product's indirect access rules under its correct governing document is part of our ALA and entitlement review track, and it matters because the same integration may be treated differently depending on which framework governs the product it touches.

How this works in practice

In a recent engagement, an estate faced a finding in which a large population of users was counted as indirect consumers of a licensed product because a downstream application presented some of that product's data to them. On examination, much of the claimed indirect access turned out to be system to system traffic, automated integrations moving data between applications with no human reading the licensed product through them, and the genuine human population was a fraction of the claimed figure. The defense documented the integration architecture, distinguished the machine traffic from the human consumers, and negotiated forward language that excluded system to system integration from the indirect access definition. The finding fell sharply once the plumbing was separated from the people. The reconstruction approach behind that result runs through our broader method, and similar reductions appear across our engagements.

Defining indirect access before it defines you

Indirect access is too important to leave to the vendor's measurement. Insist on a clear definition in the agreement, draw the line firmly between human consumers and system to system traffic, document the integration architecture so the distinction can be proven, and read indirect access under the correct governing framework for each product. Done well, ordinary integration stays out of the count and the finding reflects genuine use. Done poorly, the interconnected nature of the estate becomes the vendor's largest claim. This work sits within our OpenPass enterprise agreement negotiation track and rests on the verified estate record described in documenting your estate for an OpenPass negotiation. If indirect access is part of your estate or your finding, open a case before the integrations are counted as consumers.

When an OpenText or Micro Focus audit notice arrives, the first seven days carry more weight than any week that follows. OpenText Audit Defense is an independent, buyer side firm founded in 2020 by former vendor compliance leadership. Across more than 200 defended audits we have brought the average finding down by 68 percent and mitigated more than $90M in claims against vendor positions. We do not resell OpenText software and we are not affiliated with OpenText Corporation. To open a case, use the contact form on this site.

Keep the plumbing out of the count.

We define indirect access narrowly, separate system to system traffic from human consumers, and document the architecture that proves it. Buyer side only. Not affiliated with OpenText Corporation.