Managing Users
OpenBoxes Lift makes it straightforward to control who has access to your account and your OpenBoxes instance. All user management happens from the Users section of the portal at app.openboxes.cloud.
User Limits by Tier#
Each plan includes a set number of users. These limits apply to the total number of active users on your Lift account.
| Plan | Included Users | Additional Users |
|---|---|---|
| Shared | Up to 10 | +5 users add-on, $25/mo ($240/yr) per pack, up to 2 packs (20 users) |
| Dedicated | Up to 50 | +25 users add-on, $100/mo ($960/yr) per pack, up to 2 packs (100 users) |
| Enterprise | 100 included | +$100/mo per 25, added to your agreement (more than 500 per agreement) |
You can see your current user count on the dashboard and on the Users page. On Shared and Dedicated, add a user pack from Billing in the portal (the Add-ons card, then Browse add-ons) once your subscription is paid — the extra seats are available once the add-on shows Active on your Billing page (usually within a minute) and is charged pro-rata for the rest of the current period, then with your plan. See Billing & Plans for how add-ons are charged and cancelled.
Inviting Users#
To add someone to your Lift account:
- Go to Users in the portal sidebar
- Click Invite User
- Enter the person's email address
- Select a role (see below)
- Click Send Invitation
The invited person receives an email from noreply@openboxes.cloud with the subject "You're invited to OpenBoxes Lift — set up your account" and a link to choose a password. Once set up, they can sign into the portal and launch OpenBoxes using SSO.
Invitation Details#
- Invitation links expire after 12 hours. You can resend an invitation from the Users page at any time while the user is still pending.
- If the email doesn't arrive, ask the invitee to check their spam or junk folder — and consider asking your IT team to allow email from
noreply@openboxes.cloud. - Invitations count toward your user limit immediately. If you are at your limit, the invitation is refused: remove a user, add a user pack under Billing > Add-ons, or change your plan before sending a new one. (While an add-on is active, moving between Shared and Dedicated hosting is arranged with support rather than as a self-serve plan change.)
User Roles#
The person who signed up for the account is the account owner — they have full control over the organization account, billing, and subscription, and they are the one who invites and removes team members. Each account has exactly one owner.
Invited team members are assigned one of four roles:
| Role | What it's for |
|---|---|
| Admin | Broad management access to the instance and portal surfaces |
| Manager | Day-to-day operational access |
| User | Standard access to the OpenBoxes instance |
| Viewer | Read-only access |
Changing a User's Role#
- Go to Users in the portal sidebar
- Find the user in the list
- Click the role dropdown next to their name
- Select the new role
Role changes take effect immediately. If you downgrade someone from Admin to Viewer, they lose access to the broader features on their next page load.
Removing Users#
To remove a user from your Lift account:
- Go to Users in the portal sidebar
- Find the user you want to remove
- Click the Remove button (trash icon)
- Confirm the removal
What Happens When a User Is Removed#
- Their access to the Lift portal is revoked immediately
- Their SSO session is terminated, so they can no longer launch OpenBoxes
- Their user account in OpenBoxes is deactivated (not deleted) — this preserves audit trails and data integrity
- Any data they created in OpenBoxes (purchase orders, shipments, etc.) remains intact
- The user slot is freed up, and you can invite someone new
Removing a user does not delete their historical activity. OpenBoxes maintains a complete record of all actions for accountability.
Bulk Operations#
For accounts with many users, the Users page supports:
- Search — Filter users by name or email
- Sort — Sort by name, role, or date added
- Export — Download your user list as CSV
SSO and External Identity Providers#
Team members can sign in with Google, Microsoft, or GitHub on every plan. Connecting your organization's own identity provider (Okta, Azure AD, or any SAML IdP) is not available on any plan today; organizations that require it can discuss it as part of an Enterprise agreement.
Best Practices#
- Use the User or Viewer role for most team members. Only grant Admin or Manager to people who need broader access.
- Review users periodically. Remove users who have left the organization or no longer need access.
- Prefer Google/Microsoft/GitHub sign-in. Fewer passwords to manage, and access follows your existing identity provider account.