Skip to content

Support impersonation ​

Who this is for: Platform operators
What you'll achieve: Open a time-boxed portal session as a school user for troubleshooting

Before you begin ​

  • Operator access to /operator with the operator.impersonate permission (platform_admin or support via SSO, or the API token)
  • A legitimate support reason (password, permissions, or workflow issue you cannot resolve from audit logs alone)

How it works ​

  1. Open /operator and sign in (SSO or API token).
  2. Open Support access.
  3. Choose a school → Choose user → Impersonate on an active account.
  4. A new browser tab opens on the school's tenant host with a one-hour session as that user.
  5. A banner in the portal shows that the session is impersonated; MFA setup and tenant access gates are skipped for that session only.
  6. Every impersonation is written to the audit log with the operator id and email. Review history under Audit log.

Support only

Impersonation is for diagnosing school-reported issues. Do not use it for routine admin work on behalf of schools.

Limitations ​

RestrictionReason
Cannot impersonate platform operator accountsPrevents privilege escalation
Inactive users are disabledSession must reflect a real active login
1 hour session lifetimeTime-boxed access
Opens on the tenant subdomainCookies are scoped correctly per school

Ending a session ​

The school user (or operator) can sign out from the sidebar, the focused setup header, Account, or Admin, or wait for the session to expire. Operators can also call the impersonation end API if needed during an active support call.

What happens next ​

SchoolRota documentation. Every slot covered, every day.