"Enter as this user": support sessions explained
A support session ("Enter as this user") lets a super admin see Current as another person sees it — same workspace, same role, same personal surfaces — for up to two hours, with a pink banner on screen the whole time and a start and end entry written to the audit log. It is a troubleshooting and QA tool. It is not a password: no one learns or resets anyone's sign-in credentials, and nothing you do inside a session is recorded as if the other person did it.
Only super admins can start one, and super-admin status can only be held by a member of the primary ITPartners+ workspace. A Tenant Admin, Project Manager, Engineer, Account Executive, or partner cannot start a session at all — the buttons don't appear for them, and the underlying request is refused by the database layer even if it is called directly.
The three modes
| Mode | What you see | Started from |
|---|---|---|
| Enter tenant | Another workspace, still with your super-admin powers. You switch context; you are not downgraded. | Admin → Tenants & Billing → Workspaces → Enter tenant |
| Enter as… (a role) | That workspace as a Partner (read-only), Account Executive, Engineer, or Project Manager. Your role is masked down to that role for the session — but no specific person is chosen, so anything that keys off ownership still resolves to you. | Admin → Tenants & Billing → Workspaces → Enter as… |
| Enter as this user | The workspace as one specific person — their role and their personal surfaces (My Work, My Day, their insights, their CRM book). | Admin → Users & roles → ⋯ on their row |
The distinction matters. "Enter tenant" is a workspace switch — useful when a Tenant Admin says "my Autotask sync looks wrong" and you need to look at their settings. "Enter as…" and "Enter as this user" are downgrades: they restrict what you can see to what that role or person can see, which is the whole point when someone reports "I can't find the deal" or you want to check what a partner is actually looking at.
The demo workspace
Super admins may also keep a demo workspace — a tenant badged "Demo" in Admin → Tenants & Billing (ours is "Pebkac MSP") that is filled with entirely fictional companies, projects, tickets, emails, and deals for product demos and for QA-ing exactly what a real workspace sees after a change. A demo workspace is deliberately inert: it never syncs with Autotask or Microsoft 365, never sends email, and never calls any outside service — its integrations only look connected. The Seed / Reset button on that screen rebuilds its sample data from scratch, and Refresh timestamps makes everything look recently active before a demo. Demo data is invisible to every real workspace, exactly like any other tenant's data.
Start a session
- 1To see another workspace, go to Admin → Tenants & Billing → WorkspacesEach tenant row has an Enter tenant button (hidden for your own workspace — there's nothing to enter) and an Enter as… dropdown labelled "View this workspace as", offering Partner (read-only), Account Executive, Engineer, and Project Manager.
- 2To see it as one person, go to Admin → Users & rolesOpen the ⋯ menu at the end of that member's row and choose Enter as this user. The option only appears for super admins, and never on your own row.
- 3Let the app reloadCurrent clears its cached data and does a full page load so nothing from your own identity paints on the new view. Entering as a partner drops you into the partner portal; every other role lands in the staff app.
- 4Check the bannerA pink bar sits across the top of every page: "Viewing Northwind Dental as Alex — Project Manager" (or "as super admin" for a plain tenant switch). It follows you into the partner portal too, so you can never be lost inside someone else's view.
- 5Exit when you're donePress Exit on the banner. Current ends the session, clears the cache again, and reloads you back into your own identity and workspace.
You see as them — but you write as you
Super-admin grants and cross-tenant moves are checked against your real account (an un-maskable check on the true signed-in principal), so a masked session can never spoof that authority — and Exit is checked the same way, meaning you can always get back to yourself. Ordinary role changes still go through the normal tenant-admin gate, which a role-masked session switches off. Note that a plain "Enter tenant" session keeps your super-admin powers, so you can administer that workspace's members while inside it — that is the point of the mode, and it is audit-logged.
The paper trail
- +Starting a session writes an impersonation_start entry to the audit log of the workspace you entered, tagged with your real account's email (and user id), the workspace name, the role you're acting as, and the id of the person (if any) you entered as. The Audit log shows the actor's email, not a display name.
- +Exiting writes a matching impersonation_end entry.
- +Both land in that workspace's own audit log — its Tenant Admins can read them at Admin → Audit log, and the audit log is append-only, so nobody (including a super admin) can edit or delete the record.
- +Anything you do that IS audit-logged (projects, profiles, time entries, deals, connectors, campaigns and the other audited tables) is recorded under your real identity — never the person you're viewing as. Actions on non-audited surfaces (for example tasks and comments) still save as YOU, but do not produce their own audit-log line.
That combination is what you point a security reviewer at when they ask "can your staff log into my account?" The honest answer: a named super admin at ITPartners+ can start a time-boxed session to see what you see, they cannot act as you, and both ends of that session are recorded in your audit log, which they cannot alter. See "The audit log: what's recorded and who can read it".
Edge cases and gotchas
| Situation | What happens |
|---|---|
| You try to enter your own workspace with no role | Refused — there's nothing to switch to. Pick a role from Enter as… instead if you want to QA a role inside your own workspace. |
| You enter as a Partner (read-only) | You are routed to the partner portal, and you see only what that partner sees — no financial data. See "What partners can see — and what they never can". |
| "Enter as this user" → an AE | Company and deal reads scope to that AE's book, the same rows they'd see signed in themselves — though your own deals in that workspace remain visible too. |
| "Enter as…" → Account Executive (role only) | No specific AE is chosen, so ownership scopes to YOUR book plus the unowned-prospect pool. It shows you the AE chrome and role restrictions, not a particular AE's book. |
| The banner is missing but data looks wrong | You are not in a session. Reload; the banner appears on every page whenever a session is live. |
| You closed the tab without exiting | The session stays open until its two-hour expiry, then reverts on its own. Sign back in and press Exit if you want it closed sooner. |
