Admin User Impersonation

Short Description Hive9 admins can log in as another user to troubleshoot — but only with that user's explicit permission. This article explains the impersonation flow on both sides.

What this article answers

  • How impersonation works.
  • The user-side opt-in.
  • What admins can and can't do while impersonating.

Why impersonation exists

Some user-reported issues only manifest from the user's perspective — their permissions, their filters, their custom views, their browser. An admin can't always reproduce the issue from their own login. Impersonation lets an admin temporarily log in as the user to see exactly what they see and troubleshoot from their context.

User-side opt-in

Impersonation requires the user's explicit permission. They control it from their My Account page:

The privacy settings

  • Allow Admins to access my account — OFF by default. The user turns it ON when they want to be impersonable.
  • Allow access for:
    • 24 hours — temporary opt-in (default after enabling).
    • Always — continuous until the user turns OFF.

Users can revoke at any time by toggling OFF.

Admin-side procedure

Once a user has enabled access:

  1. Go to Settings → Users.
  2. Find the user. Their profile will show that impersonation is enabled.
  3. Click Login as user.
  4. Hive9 redirects — you now see the application exactly as the user does.
  5. A banner indicates you're in impersonation mode.

What admins CAN do while impersonating

  • See every screen the user sees (within their role and team permissions).
  • View their saved views, filters, custom dashboards.
  • Reproduce the user-reported issue from their context.
  • Test edits if needed (use caution — see below).

What admins CANNOT do

  • Access the impersonated user's My Account settings.
  • Sign out the impersonated user.
  • Change their password.
  • Access another user's settings to enable impersonation on their behalf.

Audit logging

Every action taken during impersonation is logged with the admin's identity, not the impersonated user's. Audit entries include:

  • Admin ID.
  • Impersonated user ID.
  • Timestamp.
  • Actions taken.

This preserves accountability — even though the admin sees Hive9 as the user, all changes trace back to the admin.
 

Exiting impersonation

Click Back to Admin View in the header. The impersonation session ends and your admin session is restored.

Cross-admin restrictions

  • Admins cannot impersonate other admins.
  • Impersonation does not work across organizations — only within the same instance.
  • Regular (non-admin) users cannot impersonate anyone.

Best practices

  • Avoid making edits while impersonating unless you're explicitly testing an edit. Most troubleshooting is read-only.
  • Document your investigation — note what you found during impersonation in the user's support ticket or notes.
  • Ask before enabling permanent access — if a user keeps Always-on impersonation, that's a higher trust commitment. Make sure they understand they can revoke any time.
  • Turn off when done — encourage users to set 24-hour access rather than Always, so impersonation defaults closed.

Common questions

Can I impersonate without the user's permission? No — Hive9 enforces the opt-in. Without it, the "Login as user" action isn't available.

Will the user be notified when I impersonate them? They'll know they've granted access. Some instances notify each impersonation event; check with your CSM if you need to be sure.

What if the impersonated user logs in during my session? Sessions are typically separate — your impersonation runs in your browser session, theirs in theirs. They may or may not see real-time effects of your actions depending on configuration.

Can I impersonate from a different browser than I usually use? Yes — impersonation works in any browser you're signed into as admin. The impersonation context is per-tab/per-session.
 

Related articles

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.