> ## Documentation Index
> Fetch the complete documentation index at: https://docs.zenable.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Marketplace

> Browse and manage curated requirement bundles and individual requirements

## Overview

The Zenable Marketplace is an opt-in catalog of governance requirements. Browse curated **bundles** or individual requirements, subscribe to the controls you need, and customize subscribed requirements without changing the publisher's definition.

Access the marketplace at [zenable.app/marketplace](https://www.zenable.app/marketplace?utm_source=docs\&utm_medium=web).

<Note>
  A subscription is one source of coverage. A requirement can also be covered by another bundle, an individual subscription, or a company-wide subscription. Removing one source does not deactivate a requirement that is still covered elsewhere.
</Note>

## Browsing the Catalog

The **Browse** tab shows published bundles and individual requirements. A bundle is a curated, versioned collection of related requirements; subscribe to a bundle when you want the complete set, or subscribe to individual requirements when you only need specific controls.

Use the search, type, and category filters to narrow the catalog. Grid and list views show the publisher, version, category or bundle, and current subscription state. List columns are sortable.

To act on multiple items, hold <kbd>Ctrl</kbd> or <kbd>Command</kbd> while clicking to toggle items, or hold <kbd>Shift</kbd> to select a range. **Subscribe selected** and **Unsubscribe selected** skip items already in the requested state.

Requires the `marketplace:read` permission. See [Roles and Permissions](/permissions?utm_source=docs\&utm_medium=web) for details.

## Bundles

Bundles let you opt into a related set of requirements at once. Open a bundle to review its requirements and changelog before subscribing. Requirements that are already active are marked in the bundle, and **Hide subscribed** lets you focus on requirements the bundle would add.

Open a requirement inside a bundle to review its details or **Subscribe individually**. An individual subscription keeps that requirement active if you later unsubscribe from the bundle. Requirements can belong to multiple bundles, but Zenable includes each active requirement only once.

## Subscribing and Unsubscribing

Subscribe to bundles or individual requirements from the catalog. Requires the `marketplace:manage` permission (Professional tier and above).

Click **Subscribe** on a requirement or bundle, then choose where it applies:

* **This workspace** applies it only in the workspace you are currently viewing, with the scopes you choose.
* **All workspaces in my company** enforces it in every current and future workspace with the scope you choose. Only built-in scopes are available for company-wide requirements. This option requires `company:manage` and is available to Company Owners.

Subscribed requirements appear on the [requirements page](/requirements-and-guardrails). Connected review and IDE integrations evaluate them according to each requirement's scopes and enforcement settings.

A workspace can give a company-wide requirement its own scope with **Override scope here** on the Subscriptions tab, or from **Customize** on the requirement. That creates a workspace subscription for the same item, which replaces the company decision in that workspace only. Unsubscribing the override restores the company-wide scope there.

Use the **Subscriptions** tab to review company-wide subscriptions, workspace subscriptions, and workspace exceptions:

* **Enforce Company-Wide** changes a workspace subscription so every current and future workspace is subscribed, with the company-wide scope you choose in the confirmation.
* **Stop enforcing this subscription company-wide** keeps it subscribed in the current workspace, with the same scope, but stops other workspaces from inheriting it.
* **Edit scope** changes where a subscription applies in place. On a company subscription it edits the company-wide scope; on a workspace subscription it edits that workspace's scope.
* **Block Inheritance** stops an inherited company subscription from applying in the current workspace only.
* **Stop blocking inheritance** removes that workspace exception and restores company-wide enforcement there.

Before unsubscribing, Zenable previews the affected requirements and customizations. Unsubscribing removes that subscription source. Saved customizations remain available and become active again if another subscription covers the requirement later.

## Pinning and Extending

Subscriptions track the latest published versions by default. Pin versions when you need a stable baseline:

* **Pin a bundle** to keep its current set of requirements.
* **Pin a requirement** to keep its current definition and guardrails.

Bundle and requirement pins are independent. The **Updates** tab shows pinned content with newer versions available so you can review and update it when ready.

Customize a subscribed requirement from the requirements page without changing the marketplace definition. Workspace customizations remain separate from publisher updates and are retained if you unsubscribe.

## Permissions

| Permission | Description | Availability |
| - | - | - |
| `marketplace:read` | Browse the catalog, bundles, and requirements | Any tier |
| `marketplace:manage` | Subscribe, unsubscribe, pin, and customize marketplace content | Professional and above |
| `company:manage` | Manage company-wide subscriptions and workspace inheritance | Company Owner |
| `marketplace:publish` | Publish marketplace requirements and bundles | Enterprise publishers |

See the full [Roles and Permissions](/permissions?utm_source=docs\&utm_medium=web) matrix.

## Becoming a Publisher

Want to share your requirements with the Zenable community?

Email **[hello@zenable.io](mailto:hello@zenable.io)** to apply to become a marketplace publisher. We're particularly interested in organizations and project maintainers or power users who can contribute:

* Deterministic static analysis tool integrations
* Guardrail language implementations
* Security and compliance frameworks
* Industry-specific best practices
* Open source project guidelines
* Enterprise governance standards

## Next Steps

* [Browse the marketplace](https://www.zenable.app/marketplace?utm_source=docs\&utm_medium=web) to subscribe to bundles
* [View requirements and guardrails](/requirements-and-guardrails) in the management console
* [Install MCP](/integrations/mcp/getting-started) for IDE integration
* [Set up VCS reviewers](/integrations/vcs-reviewers/github) for automated enforcement


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.