OpenFrame is on your phone now!

Invite Your Team to OpenFrame

GUIDEIMPLEMENTATIONONBOARDINGOPENFRAME

Phase 1 — Account & Workspace Setup · Step 3

Section

July 8, 2026

Published

Vlad Rudnitskyi

Vlad Rudnitskyi

Video Editor | AI Generalist

Invite Your Team to OpenFrame

Phase 1 — Account & Workspace Setup · OpenFrame Onboarding

OpenFrame is more useful with your whole team in it. Get your technicians invited now, so by the time devices start reporting in, everyone's already got access and the right role. It takes about two minutes.


Before you start

  • You need an Admin role to add people.
  • Have your team's email addresses handy. Ideally these match the identity provider you set up in Set Up SSO with Google or Microsoft — if SSO is on, invited users sign in with Google or Microsoft instead of a password.

Where to find it

Left nav → Settings → Employees & Permissions. This opens your workspace's user list, showing everyone's name, email, role, and status.


Invite people

  1. Click Add Users (top right). The Add Employees dialog opens.
  2. Type a teammate's address into User Email.
  3. Pick a Role from the dropdown (more on roles below).
  4. Adding more than one person? Click Add More Users to get another email + role row, and repeat. You can send a whole batch in one go.
  5. Click Send Invites.

Each person gets an email invitation to register. Until they accept, they show up in the list with an Invite status rather than Active.

No CSV upload today. If you've seen "bulk import a CSV" mentioned, note the current build doesn't have it — you add people by email, using Add More Users to queue several at once. For a big onboarding, just paste them in one after another.


Understanding roles

OpenFrame's user list shows two roles in play:

  • Owner — the top-level account, typically whoever first stood up the tenant. Full control.
  • Admin — full operational access to the platform.

When you send an invite, Admin is the role you'll assign. Owner and Admin are the two roles the platform offers today; if finer-grained, least-privilege roles matter to your shop, keep an eye on the console (role options may expand release to release) and see Managing Team Roles and Permissions (Phase 9).

Rule of thumb: give people the least access that lets them do their job. It's easier to grant more later than to walk back access after something goes sideways.


Reading the user list

The Status column tells you where each person stands:

  • Active — they've accepted and can sign in.
  • Invite Expired — the invitation lapsed before they accepted. Re-add them to send a fresh one.
  • Deleted — the account's been removed; it stays visible for the record but can't log in.

To remove someone, click the ⋯ menu on their row and choose Delete. Do this the moment a technician leaves — it's the fastest way to cut off access, and pairs with your SSO offboarding.


A note on SSO + invites

If you turned on auto-provision during SSO setup, people on your domain can sign in without a manual invite — an account is created for them on first sign-in. That's convenient, but it means new accounts can appear without you adding them. Either way, swing by this page periodically to confirm everyone's role and status are what you expect.


Quick checklist

  • Added each technician by email under Add Users
  • Assigned a role to each
  • Sent invites and confirmed they appear in the list
  • Followed up on anyone showing Invite Expired
  • Confirmed there are no stale or unexpected accounts

What's next

That's Phase 1 done — your workspace is configured, SSO is on, and your team is in. Next up is Phase 2 — Device Deployment: getting the OpenFrame agent onto your first macOS and Windows machines.


Based on OpenFrame v0.9.19. Screens and defaults may shift between releases — when in doubt, what's in your console wins.

Vlad Rudnitskyi

Video Editor | AI Generalist

Hi! I'm Vlad, a Video Editor and AI Generalist. I run the full AI video pipeline: concept, script, prompting, generation, editing, sound design, final grade. Beyond video, I'm always happy to take on anything visual. I'm originally from Zhytomyr, Ukraine 🇺🇦, now based in Lviv.

Related Content

Product Releases

Webinars

Case Studies

Blog Posts

Frequently Asked Questions

MSP AI Agents

Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
It is the total power a switch can supply across all its ports, which is almost always less than ports times the per-port maximum. Add up the device draws at their IEEE class: 802.3af phones at 12.95 W, 802.3at access points and cameras at 25.5 W, 802.3bt devices at 51 W or 71.3 W. Add 20% headroom and buy a switch whose total budget exceeds that figure.
For a single site with under a hundred devices, plan a day on site for discovery and the wireless survey, a week of passive counters for performance, and two days for the scan review and the report. Multi-site and heavily segmented networks scale roughly with the number of subnets, since each one needs its own discovery pass.
A one-page executive summary, the inventory and topology diagram, findings grouped by severity with evidence for each, a roadmap with costs and dates, and an appendix of raw scan output. Each finding carries what was found, the evidence, the risk, the fix, the cost, the owner and a target date.
Yes. Switch the signed-in account to a local one from Settings, Accounts, Your info, then Sign in with a local account instead. The profile folder, apps and files stay. Only removing another user's account from Other users deletes that user's data from the PC, so copy anything you need out of C:\Users\name before you remove it.
Windows will not let you remove the account you are signed in with. Either switch that account to a local account from Your info, or sign in as a different administrator and remove it from Settings, Accounts, Other users. If the PC has no other administrator, add a local one first.
Go to Settings, Accounts, Access work or school, select the account and choose Disconnect. On an Entra registered personal device that only removes work access. On an Entra joined company device it unjoins the whole PC, so confirm the BitLocker key is in Entra ID and create a local administrator first, and expect Intune policies and conditional access to stop applying.
The firmware has no embedded key. That happens on self-built PCs, machines whose motherboard was replaced, and devices that were never sold with Windows preinstalled. If the machine is still activated, it is running on a digital licence, a retail key or a volume key, and slmgr /dlv will name which.