Sample kits are a good acquisition tool and a soft target. You subsidize the unit and the shipping because a sample converts into a wholesale account. The economics only hold if a buyer takes one.
What kind of rule is this actually
"One kit per customer per month" is not a cart rule. A cart knows what is in it right now; it does not know what this person ordered in September. That makes this a per-customer limit, and per-customer limits need something a cart does not contain: purchase history, plus a reliable answer to who the buyer is.
Shopify has no native setting for a cumulative cap. Its native maximums, documented in the B2B quantity rules, define "the greatest number of a product that can be purchased at one time", which is a basket cap. We went through the difference between per-order and per-customer.
The identity problem, stated honestly
Any per-customer rule is really a per-identity rule, and identity on a storefront is soft:
Guest checkout produces no customer record until the order exists.
A second email address takes fifteen seconds.
Requiring an account closes the gap and costs conversion. In Baymard Institute's cart abandonment research, 18% of shoppers who abandoned for a specific reason said the site required them to create an account.
For a sample kit, that trade is often worth making, and this is one of the clearer cases where it is. A sample is the start of a relationship you want recorded anyway, so asking for an account is proportionate rather than obstructive.
A setup that holds
Gate the kit behind an account. If you cannot identify the buyer, you cannot run the rule. Say why on the page: one kit per customer, so everyone gets one.
Cap the basket as well. A per-order maximum of one stops the simplest abuse immediately and needs no history at all.
Scope by tag for the exceptions. Existing wholesale accounts and sales reps often legitimately need more. A tag-scoped exemption is cleaner than an override on every order.
Enforce it server-side. Sample abusers are motivated buyers, which is precisely who defeats theme-level rules. Shopify's validation documentation describes the enforcing layer as running "on Shopify's servers" with rules that "can't be bypassed by customers".

Leave yourself a door
You will want to send a second kit to a serious prospect. Draft orders are the right instrument: validation applies there, per the changelog of 11 December 2024, and the same entry documents a bypassCartValidations argument on draft order completion so a person with admin access can make a deliberate exception. That is the shape you want: shoppers cannot bypass the rule, your team can.
The number is a business decision, not a technical one
One per month, one per quarter, one ever. The tighter the window, the better the economics and the more legitimate requests you refuse. Pick the number from your conversion rate on samples, not from what the software makes easy.




