Feishu is ByteDance’s work platform for the mainland China market, combining messaging, documents, meetings, email, knowledge, approvals, projects, and multi-dimensional tables with separate AI packages and agent-facing tools. It should be evaluated as a collaboration and business-workflow platform, not as a single magical AI layer or as automatically identical to the international Lark service.

This review uses public information checked on September 14, 2026. Product editions, AI quotas, regional service entities, and cross-border arrangements are dynamic and must be confirmed in the customer contract.

Core suite and current pricing

Feishu’s current product page identifies the service as a ByteDance AI work platform and lists messaging, documents, meetings, Base, email, approvals, tasks, knowledge, and other collaboration functions. Its edition comparison lists a free tier and paid business editions with different member, storage, meeting, history, administration, and security limits.

On the checked date, the public comparison showed free at RMB 0, Business Standard at RMB 50 per user per month, Business Professional at RMB 80, and Business Flagship at RMB 120, with annual payment stated. Enterprise pricing was not fully public. These are website prices, not a total quote. Add-on products, services, implementation, storage, AI usage, and regional requirements can change cost.

The platform is strongest when a team wants communication and lightweight business applications to share identities, permissions, documents, and workflows. That breadth also expands the blast radius of weak permissions or uncontrolled automation.

AI is packaged separately

The Feishu AI package page publishes annual packages and shared AI-credit allowances. On the checked date it listed a Basic package at RMB 9,900 per year, an Enterprise package at RMB 99,000, and higher tiers by sales contact, with different credit quantities and included services.

Those prices and quotas are vendor-published and may not include the required main suite, every model, or every product. A buyer should ask how each action consumes credits, which features share the pool, what happens at the limit, which model processes the request, and whether data is retained or used outside the tenant’s intended purpose.

Do not calculate return from purchased credits. Measure completed work, error correction, cycle time, and human review against a baseline.

Agent access has a defined permission boundary

Feishu’s official CLI security explanation says the CLI wraps existing OpenAPI capabilities, uses user or application identity, remains limited to approved scopes, and records OpenAPI calls in administrative audit logs. It also describes future security directions separately from current controls.

That distinction is valuable. A current scope and audit log are delivered controls; a future AI-specific scope or confirmation mechanism is roadmap. Buyers should not count roadmap items as available safeguards.

For an agent deployment:

  1. create a dedicated application rather than reuse an administrator’s credentials;
  2. grant only required scopes and resources;
  3. separate read, draft, send, edit, delete, and approval actions;
  4. require human confirmation for destructive or external actions;
  5. log the initiating user, application identity, target, and outcome;
  6. test revocation, token expiry, retry, and duplicate execution;
  7. cap bulk actions and define an emergency stop.

The published control model does not prove that a customer’s custom agent, prompt, or integration is safe. The customer owns that implementation boundary.

Data and regional diligence

Feishu and Lark branding, contracts, hosting, certifications, and feature sets should not be assumed interchangeable. For a cross-border organization, identify the contracting entity, tenant region, storage location, subprocessors, support access, transfer route, encryption, retention, and export before deployment.

China’s Ministry of Industry and Information Technology publishes the full text of the Personal Information Protection Law. It defines personal-information processing broadly and addresses notice, purpose, consent, sensitive data, processors, and cross-border activity. The law’s applicability depends on the real processing. This article is not legal advice.

Run a data map for messages, documents, meeting recordings and transcripts, directory data, Base records, app credentials, AI prompts, and outputs. Check that deletion and retention propagate to connected apps and exports.

Decision rule

Feishu should advance when the organization benefits from an integrated collaboration layer, the correct regional service and contract are explicit, and administrators can govern apps, agents, data, and AI consumption. It should pause when the case depends on broad AI positioning, unpriced add-ons, assumed equivalence with Lark, or permissions that are wider than the workflow needs.

Pilot a real business process end to end, including a failed API call, revoked user, shared external document, sensitive field, and recovery. The result should be judged by correct execution and controllable risk, not by how many work products appear in one interface.