Summary
This guide explains how platform support staff use the support console on skillSYMS to assist users safely. You’ll learn how to search for users, start an audited impersonation session, use tenant shadow mode for setup work, and review the history of both.
Who This Guide Is For
- Platform support and platform owner staff
- Administrators resolving user-reported issues
- Compliance staff reviewing impersonation audit history
Prerequisites
Before you begin, ensure you have:
- Platform support or platform owner credentials
- A legitimate, documented reason for any impersonation
- The affected user’s email, name, or user ID, or the relevant tenant
Step 1: Open the Support Console
Navigate to Admin → Support → Console.
The console warns you at the top if you already have an active impersonation session — you must end it before starting another.
Tip: All impersonation and tenant-access actions are logged and audited. Only act with a genuine, recorded reason.
Step 2: Find a User
In the Find User to Impersonate panel, search by email, name, or user ID. You can narrow results by Tenant and Role.
Results are paginated; use the filters to quickly locate the right account from a support ticket.
Step 3: Start an Impersonation Session
For the target user, click Impersonate to open the confirmation modal.
Complete the required fields:
- Reason Category — e.g. Support Ticket, Bug Investigation, User Assistance
- Details — at least 10 characters explaining why (required)
- Support Ticket ID — optional but recommended for traceability
Confirm to start the session. You’ll be redirected into the user’s dashboard for their role.
Tip: Impersonation sessions expire automatically after 15 minutes. Capture what you need promptly, then end the session.
Step 4: End an Active Session
If the active-session warning is showing, click End Current Session to close it immediately. Always end sessions as soon as your task is complete rather than waiting for the timeout.
Step 5: Use Tenant Access (Shadow Mode)
In the Tenant Access (Shadow Mode) panel, select a tenant and click Access Tenant.
Shadow mode enters the tenant’s context with owner-level permissions for setup work, subject to a 60-minute hard cap and full auditing. Use it when a tenant needs hands-on configuration help.
Tip: Prefer tenant shadow mode over impersonating a specific user when doing setup work — it scopes you to the tenant rather than a single person’s identity.
Step 6: Review Session History
The console lists Recent Impersonation Sessions and Recent Tenant-Access Sessions, showing the actor, target, reason, start time, status, and request count.
Use these tables for self-review and to support compliance audits of who accessed what and why.
Common Mistakes to Avoid
- Vague reasons: A weak reason undermines the audit trail — be specific
- Leaving sessions open: End impersonation immediately after the task, don’t wait for expiry
- Impersonating for setup work: Use tenant shadow mode instead when configuring a tenant
- Skipping the ticket ID: Linking a ticket makes the audit trail far easier to follow
Verification Checklist
After a support session, verify:
- A clear reason category and detail were recorded
- A support ticket ID was attached where applicable
- The session was ended (not left to time out)
- The action appears correctly in the session history
- No leftover active session blocks the next task
Next Steps
- User Management & RBAC — Resolve role and access issues directly
- API Keys & Security — Investigate suspicious access alongside impersonation logs
- Ops & Monitoring — Correlate support sessions with platform activity