How can we help? How can we help?

Understand masquerade‑only users

MRI Box and Dice MRI Box and Dice

Summary

Learn how masquerade‑only users allow authorised staff to act as another user in Box+Dice without providing direct login access, while maintaining accurate audit logs and billing.

This article covers:


About masquerade‑only users

Masquerade‑only users are special user accounts in Box+Dice that allow authorised staff to temporarily act as another user without granting that user direct login access.

They are commonly used for troubleshooting issues, testing permissions, validating workflows, and providing internal or franchise‑level support. When a real user masquerades as a masquerade‑only user, actions appear in the Box+Dice interface as if they were performed by the masquerade‑only user, while audit logs continue to record the identity of the real user.

This approach helps teams replicate user behaviour safely, investigate issues, and provide support without sharing credentials or impacting real user accounts.

Note: Masquerade‑only users are feature‑flagged and disabled by default. They must be enabled by Box+Dice Support before they become available.

Key limitations and behaviour

Masquerade‑only users behave differently to standard users.

  • They cannot sign in directly
  • They must be accessed by masquerading from a real user
  • They cannot be converted into a real user, and real users cannot be converted into masquerade‑only users
  • They cannot be assigned the Franchise Admin role
  • They are treated like standard users for billing purposes
  • OKTA and SSO settings are not available for masquerade‑only users
Note: Masquerade‑only users that belong to another office group are only visible to the Franchise Admin role.
Admin users cannot view masquerade‑only users outside their own office group.

Add a masquerade‑only user

Once enabled, masquerade‑only users can be created directly from the Staff area.

To add a masquerade‑only user:

  • Go to: More > Staff
  • Click + Add
  • Enter the user’s first name and last name
  • Tick Masquerade only
  • Tick the box to confirm you agree to the terms and conditions
  • Click Add New User

Selecting Masquerade only hides the login email field automatically.

Tip: Masquerade‑only users still require names so their activity can be identified clearly in the interface.

Manage masquerade access for users

When the feature is enabled, a Masquerading button appears at the bottom of the Staff screen.

This allows authorised users to control which masquerade‑only users another user can access.

Note: Access to this option requires the Edit Staff ACL.

To assign or remove masquerade access:

  • Go to: More > Staff
  • Select the real user
  • Click Masquerading
  • Select or remove available masquerade‑only users
  • Click Save to save your changes

Note:

  • If the logged‑in user does not have the required permission, the button appears greyed out with a tooltip
  • Inactive masquerade‑only users do not appear and are removed automatically

Masquerade as another user

Users who have been granted masquerade access can switch into a masquerade‑only user at any time.

While masquerading:

  • Actions appear in the UI as if performed by the masquerade‑only user
  • Audit logs record the real user’s identity
  • Two real users can masquerade as the same masquerade‑only user simultaneously

To start masquerading:

  • Click your Name
  • Click the Masquerading search field
  • Select one of the available masquerade‑only users

To stop masquerading:

  • Click the login chevron
  • Select Stop masquerading
Important: You cannot switch directly between masquerade‑only users without first returning to your real account.

Stop Masquerading.png