View as a company
Do this
Section titled “Do this”- Open the company in Companies and press View as in the header. It is there only for
platform_supportandplatform_owner. - Write a reason of at least 8 characters, and choose how many minutes (1 to 30, default 30). Press Open the customer app.
- The customer app opens as that company’s admin, read-only. A banner at the top says You are viewing (company) read-only until (time); Why shows your reason.
- To leave, press Stop viewing in the banner, or Back to platform at the top of the sidebar. Either returns you to the company’s page. It also ends by itself when the time runs out.
Behind the screen: POST /tenants/{id}/view-as, DELETE /view-as. GET /api/auth/me shows an impersonating block with the company, start, expiry, reason and read_only: true, which is what the banner reads.
What the rules are
Section titled “What the rules are”- Read-only. Every request that is not a GET is refused with
403 impersonation_read_only. The list of allowed writes is empty. Only the platform’s own settings (PLATFORM_VIEW_AS_WRITE_ALLOW) could add one, and signing out always works. - 30 minutes at most. The database clock enforces expiry on every request, and the 30-minute limit is also a rule on the table.
- A reason is required. Under 8 characters is refused.
- Platform calls still work normally for your own role while you are viewing.
- Live media is not included. Joining a call’s audio needs a write, so it is not available in view as.
Everything is recorded twice
Section titled “Everything is recorded twice”Every request in the session, reads and refused writes alike, is written to the platform audit log and to the company’s own audit log with the actor platform:<your id>. If a request cannot be recorded, it is refused. So the company can always find out when support looked, who, why and what.
See audit and evidence for how a company reads its own log.