Skip to content
Current/ Help Center

"Enter as this user": support sessions explained

7 min read · Updated Jul 17, 2026

A support session ("Enter as this user") lets a super admin see Current as another person sees it — same workspace, same role, same personal surfaces — for up to two hours, with a pink banner on screen the whole time and a start and end entry written to the audit log. It is a troubleshooting and QA tool. It is not a password: no one learns or resets anyone's sign-in credentials, and nothing you do inside a session is recorded as if the other person did it.

Only super admins can start one, and super-admin status can only be held by a member of the primary ITPartners+ workspace. A Tenant Admin, Project Manager, Engineer, Account Executive, or partner cannot start a session at all — the buttons don't appear for them, and the underlying request is refused by the database layer even if it is called directly.

The three modes

ModeWhat you seeStarted from
Enter tenantAnother workspace, still with your super-admin powers. You switch context; you are not downgraded.Admin → Tenants & Billing → Workspaces → Enter tenant
Enter as… (a role)That workspace as a Partner (read-only), Account Executive, Engineer, or Project Manager. Your role is masked down to that role for the session — but no specific person is chosen, so anything that keys off ownership still resolves to you.Admin → Tenants & Billing → Workspaces → Enter as…
Enter as this userThe workspace as one specific person — their role and their personal surfaces (My Work, My Day, their insights, their CRM book).Admin → Users & roles → ⋯ on their row

The distinction matters. "Enter tenant" is a workspace switch — useful when a Tenant Admin says "my Autotask sync looks wrong" and you need to look at their settings. "Enter as…" and "Enter as this user" are downgrades: they restrict what you can see to what that role or person can see, which is the whole point when someone reports "I can't find the deal" or you want to check what a partner is actually looking at.

Note
The mask restricts — it is not a byte-perfect replica
Masking is designed to restrict, not grant: your role, tenant and personal surfaces all resolve to the person you entered as. A few ownership checks still key off your real account (your own CRM deals in that workspace stay visible, and CRM access is not stripped from a super admin). Treat the view as "what they see, plus what you already owned" rather than a pixel-exact replica.

The demo workspace

Super admins may also keep a demo workspace — a tenant badged "Demo" in Admin → Tenants & Billing (ours is "Pebkac MSP") that is filled with entirely fictional companies, projects, tickets, emails, and deals for product demos and for QA-ing exactly what a real workspace sees after a change. A demo workspace is deliberately inert: it never syncs with Autotask or Microsoft 365, never sends email, and never calls any outside service — its integrations only look connected. The Seed / Reset button on that screen rebuilds its sample data from scratch, and Refresh timestamps makes everything look recently active before a demo. Demo data is invisible to every real workspace, exactly like any other tenant's data.

Start a session

  1. 1
    To see another workspace, go to Admin → Tenants & Billing → Workspaces
    Each tenant row has an Enter tenant button (hidden for your own workspace — there's nothing to enter) and an Enter as… dropdown labelled "View this workspace as", offering Partner (read-only), Account Executive, Engineer, and Project Manager.
  2. 2
    To see it as one person, go to Admin → Users & roles
    Open the ⋯ menu at the end of that member's row and choose Enter as this user. The option only appears for super admins, and never on your own row.
  3. 3
    Let the app reload
    Current clears its cached data and does a full page load so nothing from your own identity paints on the new view. Entering as a partner drops you into the partner portal; every other role lands in the staff app.
  4. 4
    Check the banner
    A pink bar sits across the top of every page: "Viewing Northwind Dental as Alex — Project Manager" (or "as super admin" for a plain tenant switch). It follows you into the partner portal too, so you can never be lost inside someone else's view.
  5. 5
    Exit when you're done
    Press Exit on the banner. Current ends the session, clears the cache again, and reloads you back into your own identity and workspace.
Note
Sessions expire on their own — after 2 hours
Every session is stamped with a two-hour expiry. The moment it lapses, the server is back to your real identity whether or not you clicked Exit; the banner checks about once a minute and clears itself. Starting a new session automatically ends any session you already had open — you can only ever be inside one at a time.

You see as them — but you write as you

Heads up
Nothing you do is attributed to the other person
Impersonation changes what you can READ. It does not change who writes. A time entry, comment, or notification preference saved during a session is recorded against your real super-admin account, not theirs. There is no way to create billable time, a comment, or an approval in someone else's name — deliberately, so timesheets and billing records stay honest.

Super-admin grants and cross-tenant moves are checked against your real account (an un-maskable check on the true signed-in principal), so a masked session can never spoof that authority — and Exit is checked the same way, meaning you can always get back to yourself. Ordinary role changes still go through the normal tenant-admin gate, which a role-masked session switches off. Note that a plain "Enter tenant" session keeps your super-admin powers, so you can administer that workspace's members while inside it — that is the point of the mode, and it is audit-logged.

The paper trail

  • Starting a session writes an impersonation_start entry to the audit log of the workspace you entered, tagged with your real account's email (and user id), the workspace name, the role you're acting as, and the id of the person (if any) you entered as. The Audit log shows the actor's email, not a display name.
  • Exiting writes a matching impersonation_end entry.
  • Both land in that workspace's own audit log — its Tenant Admins can read them at Admin → Audit log, and the audit log is append-only, so nobody (including a super admin) can edit or delete the record.
  • Anything you do that IS audit-logged (projects, profiles, time entries, deals, connectors, campaigns and the other audited tables) is recorded under your real identity — never the person you're viewing as. Actions on non-audited surfaces (for example tasks and comments) still save as YOU, but do not produce their own audit-log line.

That combination is what you point a security reviewer at when they ask "can your staff log into my account?" The honest answer: a named super admin at ITPartners+ can start a time-boxed session to see what you see, they cannot act as you, and both ends of that session are recorded in your audit log, which they cannot alter. See "The audit log: what's recorded and who can read it".

Edge cases and gotchas

SituationWhat happens
You try to enter your own workspace with no roleRefused — there's nothing to switch to. Pick a role from Enter as… instead if you want to QA a role inside your own workspace.
You enter as a Partner (read-only)You are routed to the partner portal, and you see only what that partner sees — no financial data. See "What partners can see — and what they never can".
"Enter as this user" → an AECompany and deal reads scope to that AE's book, the same rows they'd see signed in themselves — though your own deals in that workspace remain visible too.
"Enter as…" → Account Executive (role only)No specific AE is chosen, so ownership scopes to YOUR book plus the unowned-prospect pool. It shows you the AE chrome and role restrictions, not a particular AE's book.
The banner is missing but data looks wrongYou are not in a session. Reload; the banner appears on every page whenever a session is live.
You closed the tab without exitingThe session stays open until its two-hour expiry, then reverts on its own. Sign back in and press Exit if you want it closed sooner.
Tip
Use it to test a role change before you make it
Before you move someone from Engineer to Project Manager, use Enter as… to look at the role you're about to give them. It's the fastest way to confirm the permission model matches what you expect — and if you need that person's exact view, use Enter as this user instead. See "Roles & permissions: who sees what".
Was this helpful?