Appearance
Support impersonation
Who this is for: Platform operators
What you'll achieve: Open a time-boxed portal session as a school user for troubleshooting
Before you begin
- Operator access to
/operatorwith theoperator.impersonatepermission (platform_adminorsupportvia SSO, or the API token) - A legitimate support reason (password, permissions, or workflow issue you cannot resolve from audit logs alone)
How it works
- Open
/operatorand sign in (SSO or API token). - Open Support access.
- Choose a school → Choose user → Impersonate on an active account.
- A new browser tab opens on the school's tenant host with a one-hour session as that user.
- A banner in the portal shows that the session is impersonated; MFA setup and tenant access gates are skipped for that session only.
- Every impersonation is written to the audit log with the operator id and email. Review history under Audit log.
Support only
Impersonation is for diagnosing school-reported issues. Do not use it for routine admin work on behalf of schools.
Limitations
| Restriction | Reason |
|---|---|
| Cannot impersonate platform operator accounts | Prevents privilege escalation |
| Inactive users are disabled | Session must reflect a real active login |
| 1 hour session lifetime | Time-boxed access |
| Opens on the tenant subdomain | Cookies are scoped correctly per school |
Ending a session
The school user (or operator) can sign out from the sidebar, the focused setup header, Account, or Admin, or wait for the session to expire. Operators can also call the impersonation end API if needed during an active support call.

