Overview
The Zenable Marketplace is an opt-in catalog of governance requirements. Browse curated bundles or individual requirements, subscribe to the controls you need, and customize subscribed requirements without changing the publisher’s definition. Access the marketplace at zenable.app/marketplace.A subscription is one source of coverage. A requirement can also be covered by another bundle, an individual subscription, or a company-wide subscription. Removing one source does not deactivate a requirement that is still covered elsewhere.
Browsing the Catalog
The Browse tab shows published bundles and individual requirements. A bundle is a curated, versioned collection of related requirements; subscribe to a bundle when you want the complete set, or subscribe to individual requirements when you only need specific controls. Use the search, type, and category filters to narrow the catalog. Grid and list views show the publisher, version, category or bundle, and current subscription state. List columns are sortable. To act on multiple items, hold Ctrl or Command while clicking to toggle items, or hold Shift to select a range. Subscribe selected and Unsubscribe selected skip items already in the requested state. Requires themarketplace:read permission. See Roles and Permissions for details.
Bundles
Bundles let you opt into a related set of requirements at once. Open a bundle to review its requirements and changelog before subscribing. Requirements that are already active are marked in the bundle, and Hide subscribed lets you focus on requirements the bundle would add. Open a requirement inside a bundle to review its details or Subscribe individually. An individual subscription keeps that requirement active if you later unsubscribe from the bundle. Requirements can belong to multiple bundles, but Zenable includes each active requirement only once.Subscribing and Unsubscribing
Subscribe to bundles or individual requirements from the catalog. Requires themarketplace:manage permission (Professional tier and above).
Click Subscribe on a requirement or bundle, then choose where it applies:
- This workspace applies it only in the workspace you are currently viewing, with the scopes you choose.
- All workspaces in my company enforces it in every current and future workspace with the scope you choose. Only built-in scopes are available for company-wide requirements. This option requires
company:manageand is available to Company Owners.
- Enforce Company-Wide changes a workspace subscription so every current and future workspace is subscribed, with the company-wide scope you choose in the confirmation.
- Stop enforcing this subscription company-wide keeps it subscribed in the current workspace, with the same scope, but stops other workspaces from inheriting it.
- Edit scope changes where a subscription applies in place. On a company subscription it edits the company-wide scope; on a workspace subscription it edits that workspace’s scope.
- Block Inheritance stops an inherited company subscription from applying in the current workspace only.
- Stop blocking inheritance removes that workspace exception and restores company-wide enforcement there.
Pinning and Extending
Subscriptions track the latest published versions by default. Pin versions when you need a stable baseline:- Pin a bundle to keep its current set of requirements.
- Pin a requirement to keep its current definition and guardrails.
Permissions
See the full Roles and Permissions matrix.
Becoming a Publisher
Want to share your requirements with the Zenable community? Email hello@zenable.io to apply to become a marketplace publisher. We’re particularly interested in organizations and project maintainers or power users who can contribute:- Deterministic static analysis tool integrations
- Guardrail language implementations
- Security and compliance frameworks
- Industry-specific best practices
- Open source project guidelines
- Enterprise governance standards
Next Steps
- Browse the marketplace to subscribe to bundles
- View requirements and guardrails in the management console
- Install MCP for IDE integration
- Set up VCS reviewers for automated enforcement