The limits Offision applies, and what people see at each one
Every limit an administrator or user can run into: how many emails a tenant can send, how often invitations, password resets and sign-in codes can be resent, how often a user's email address can change, request rate limits, sign-in lockout, free-tier daily limits, public booking, visitor code resends and export sizes, with the message shown at each.
Offision puts a ceiling on anything that can be repeated fast enough to hurt someone: email that lands in other people’s inboxes, guesses at a password, floods of requests. Every limit below counts over a rolling window: “24 hours” means the last 24 hours from now, not since midnight. A limit never deletes anything. It only makes the next attempt wait.
Licence seats and monthly booking or visitor quotas are a different kind of limit. They are on What your licence covers.
Every email Offision sends counts, whatever sends it: invitations, password resets, booking, visitor and event notifications, workflows, test emails. That includes email sent through your own mail server.
| Limit | Free | Paid | Counted per | What people see |
|---|---|---|---|---|
| Recipients a tenant can email | 40 per 10 minutes 200 per 24 hours | 10,000 per 10 minutes 50,000 per 24 hours | Tenant. A message to 30 people counts 30 | The administrator who triggered it sees Email limit reached. Try again later. Other emails over the limit are not sent later: they show as Held by Offision in Email history |
| Invitation, password reset and email verification, together | 3 per hour 5 per 24 hours | 3 per hour 5 per 24 hours | Each user and each email address | On the sign-in page the reply is the same as always (“If an account with that email exists, we’ve sent password reset instructions”), but no new email is sent. An administrator sees Email limit reached. Try again later. |
| Sign-in verification codes | 10 per hour 30 per 24 hours | 10 per hour 30 per 24 hours | Each user and each email address | The code already sent stays valid. No new code is sent until the window frees up |
| Test emails from Email setting | 10 per hour 20 per 24 hours | 10 per hour 20 per 24 hours | Tenant | Email limit reached. Try again later. |
| Changes to a user’s email address | 3 per 24 hours 5 per 30 days | 3 per 24 hours 5 per 30 days | Each user | Saving the user is refused with This user’s email address was changed too often. Try again later. |
A few details matter when you plan a roll-out:
- Changing the address does not reset the count. The invitation limit follows the person, so moving their account to a new address and resending still counts against the same user.
- Upper and lower case don’t count as a change.
Ann@example.comtoann@example.comis free. - Changing an address cancels what was sent to the old one. Any invitation or password-reset link already sent stops working.
- Inviting a large team? The free daily recipient limit is 200, and booking, visitor and event emails count toward it too. Invite in batches, or ask about a paid subscription, which raises it to 50,000.
Seeing what was sent
Email history shows recipients, subject, template, status and sending times. The email body and preview are no longer displayed; every record shows Email content hidden. Emails sent through Outlook or Google Workspace user calendars are not recorded here.
| Limit | Value | Counted per | What people see |
|---|---|---|---|
| Email history retention | 30 days by default; the configured period appears below Email history | Each record’s creation time | Kept for 30 days. (with the default period) Older records are removed |
The three statuses are Handed to mail server, Held by Offision and Mail server refused. Acceptance by a mail server does not prove inbox delivery. Held records show a Hold reason and are not sent later; refused records show a Failure reason. For filters, recipients and sending times, see See which emails were handed over.
Requests
| Limit | Value | Counted per | What people see |
|---|---|---|---|
| Apps and the management console | 100 requests per 5 seconds | Signed-in user, or network address when not signed in | Too many requests. Please slow down and try again in a moment. |
| Forgot password, resend invitation, self-registration, send sign-in code | 10 per minute, 100 per hour | Network address | Too many requests. Please try again in N second(s). |
| External API and OAuth sign-in | 1,000 requests per 5 seconds | API token or network address | HTTP 429 with a Retry-After header |
Sign-in
| Limit | Value | What people see |
|---|---|---|
| Wrong passwords before lockout | Set by your administrator, off unless set. See password policy | The account is locked for the minutes your policy says |
| Wrong sign-in verification codes | 5 attempts, and the code expires after 5 minutes | Sign in again to get a fresh code |
| Invitation link | Valid for 72 hours | The page offers to resend the invitation |
| Password reset link | Valid for 24 hours | Request a new reset email |
Other limits
| Area | Limit | What people see |
|---|---|---|
| Free subscription, daily actions | Bookings, visits, service requests, tickets, parcels, events, announcements, polls, workflows and new users each have a daily limit set by your subscription | The action is refused until the 24-hour window frees up |
| Guest booking page | 60 bookings per hour per network address, 2,000 per page per day. Attachments up to 5 MB each | Too many requests |
| Guest booking email code | 1 per minute and 5 per hour for each address | No new code is sent; the last one still works |
| Visitor check-in code resend | 3 per 24 hours for each badge, at most 1 per minute | No new code is sent |
| Exporting logs and lists | 50,000 rows per export | Narrow the date range or filters and export again |

