Users

The Users page manages the accounts that can log in to Docbox. Docbox supports two types of user account: Active Directory (AD/LDAP) users, whose details and roles are sourced from your organisation's directory, and internally managed users, whose accounts are created and maintained directly within Docbox.

Before your Docbox instance is shipped, CFH will configure an internally managed administrator account using an email address you provide. This account is your site administrator and is used for initial setup and as a fallback if AD authentication is unavailable. The site administrator can create additional internally managed users as required.

You can manage users via Control Panel > Users.

Only Administrators can access the Users page.

User List

Each entry shows the user's full name (surname, forename) and username. If no name is set, the username is shown instead. A search box at the top filters users by name or username as you type.

Users sourced from Active Directory are badged AD / LDAP. Internally managed users display no badge. The user's management type is also shown in the detail panel header and on each tab.

Click Add New User to create a new internally managed account.

Tabs

When a user is selected, the detail panel shows four tabs:

Tab Description
Details The user's account fields and role assignments.
Access Controls to enable, disable, lock, or revoke access for the user.
Login History A paginated audit log of the user's login activity.
Printer Access The printers assigned to this user.
Tokens API tokens generated for this user.

When creating a new user, only the Details tab is shown.

Details Tab

The Details tab contains the user's account settings and role assignments.
For Active Directory users, the Username, Email Address, Forename, Surname, Department, and Distinguished Name fields are read-only. These values are sourced from your directory and must be updated there, not in Docbox.

Field Description
Username The name used to log in. Must be unique. This is read-only for Active Directory users.
Email Address Used for notifications. Must be a valid email address. Read-only for Active Directory users.
Forename The user's first name. Read-only for Active Directory users.
Surname The user's family name. Read-only for Active Directory users.
Department Used for report filtering. Read-only for Active Directory users.
Distinguished Name The user's LDAP distinguished name. Used to match the directory entry when LDAP authentication is enabled. Read-only for Active Directory users.
Roles

Tick one or more roles to grant access to the corresponding features. 

Available roles are Administrator, Alert User, Control Panel User, Departmental Reporting User, Organisational Reporting User, and User. Refer to Access Control for role descriptions.

Roles for Active Directory users are synced from AD group membership on login and cannot be edited here

 

 

Token Timeout (seconds) Controls how long tokens generated by this account remain valid. Set to 0 to use the system default (12 hours). Enter a value in seconds to override the default for this user -- for example, 3600 for one hour. Contact CFH if you need to change the system-wide default.

The toolbar actions on the Details tab are 

  • Save - saves changes to the user record.
  • Delete - deletes the user . Only shown for existing users,

Refer to Docbox Help Centre for information on the deletion confirmation process.

Access Tab

The Access tab is where you control whether a user can sign in, without changing anything else about their account. Use it when access needs to change quickly, for example if a credential is suspected to have been compromised.

It brings together four actions that were previously scattered or unavailable, each gated behind a confirmation and showing the user's current status as a pill (Enabled/Disabled, Locked/Unlocked).

Account access

Enable or disable sign-in for this user. Disabling also ends any live dashboard session immediately, so a disabled user is signed out as well as blocked from signing back in.

Account lock

A reversible freeze. Locking blocks every authentication path without deleting anything, and forces a password reset before the user can sign in again. It clears automatically once the user completes that reset, or an admin can unlock manually.

The Password action, described below, is only available for internally managed users. Active Directory users manage their password through AD, so this row does not appear for them.

 

Password (internally managed users only)

Generates a password reset link, as before. Reset links now also carry an optional Revoke all access toggle, so you can force out every existing session at the same time as issuing the reset.

  1. Click Reset Password to open the dialogue.
  2. Optionally tick Lock account until password is changed. When checked, the user cannot log in with their current password until they set a new one via the reset link.
  3. Optionally tick Revoke all access. When checked, all existing sessions, tokens, and login links for this user are invalidated as soon as the link is generated, rather than waiting for the reset to be completed.
  4. Click Generate Link. The system generates a time-limited password reset URL.
  5. The URL is displayed in a text field. Click Copy to copy the reset link (along with its expiry date) to the clipboard.
  6. Share the link securely with the user. The link is valid until the date and time shown.
  7. Click Done to close the dialogue.

Danger Zone: Revoke all access

This is irreversible. It deletes the user's API tokens and any unredeemed login links, and signs them out of every live session immediately. Desktop print driver users will need to log in again afterwards.The confirmation dialogue states this before you proceed.

 

Use this for a suspected breach, where cutting off every access path outright matters more than convenience. It's also the reason we recommend service accounts rather than personal end-user accounts for File Agent: revoking a personal account this way will break any DFA pipeline authenticating as that user.

Login History Tab

The Login History tab shows a paginated audit trail of the user's authentication activity.

Column Description
Date / Time When the event occurred.
Action The type of event, for example Successful Login.
IP Address The IP address from which the request originated.
User Agent The browser or client that made the request. Long values are truncated; hover to see the full text.

Page through results using the pagination controls at the bottom of the list.

Printer Access Tab

The Printer Access tab shows all printers configured in Docbox and whether the selected user has access to each one.

Column Description
Printer The name of the printer.
Active Whether the printer is currently active (Yes/No).

The tab header indicates how the user's printer access is managed — Internally Managed or Active Directory.


Active Directory users

Printer access for Active Directory users is derived from their group membership and cannot be managed in Docbox. The Actions column and toolbar buttons are not shown.


Internally managed users

Printer access for internally managed users can be assigned and revoked directly. An additional Actions column is shown, and the following toolbar buttons are available:

  • Add Printer Access — opens a modal listing all printers not yet assigned to this user. Tick the printers you want to grant and click Grant Access.
  • Revoke All — revokes all printer access for this user after confirmation.

To revoke access to a single printer, click Remove in the row and confirm.

Tokens Tab

The Tokens tab shows all API tokens that have been generated for the selected user. This gives administrators visibility into token usage without needing to ask the user.

Column  Description
Token Name The descriptive name given to the token when it was created.
Client The client type associated with the token — either FileAgent or PrintDriver.
Created The date and time the token was created.
Expires The date and time the token will expire.
Actions A Revoke button to delete the individual token.
  • FileAgent tokens are created by the user and are used to authenticate Docbox File Agent pipelines. Refer to Tokens in the Docbox File Agent section for full details.
  • PrintDriver tokens are created automatically by the system when a user authenticates via the Docbox Print Driver.


Click Revoke on an individual row to cancel that token. Click Revoke All Tokens to cancel all tokens for this user at once. Revoking a token prevents any new jobs being submitted via that token. Jobs already in the system at the time of revocation will continue to process normally.

Deleting a user

Before deleting a user, ensure you are not removing an account that is required for system maintenance or support access. Deleting a user is permanent and cannot be undone.

 

The Delete button appears on the Details tab toolbar for existing users only.

  1. Click Delete. The Delete User dialogue appears.
  2. Type the username exactly as shown in the confirmation field to enable deletion.
  3. Click Delete to confirm, or Cancel to close without deleting.

Deleting a user is permanent. Their historical print job records remain in the system, but they can no longer log in.