Skip to main content

Impersonate an end user

Impersonate lets you use the portal as a specific customer so you can see exactly what they see. This is different from Preview as. Preview as uses a disposable test user for a role. Impersonate uses the real person. You must be an app owner or admin. The person must be active, with a project membership, and not a platform (synthetic) user.

How to start

  1. Open End-Users and select the person, or use Impersonate on the list.
  2. Confirm that anything you do is real for their account (messages, records, settings).
  3. Enter a fresh code from your authenticator app.
  4. Work in their portal. The banner shows who you are impersonating.
  5. Choose Stop impersonating when you are done. That ends the impersonation session immediately, including any copied token. Portal Sign out and idle timeout also end it. Starting Impersonate again (on this person or someone else) ends your previous impersonation session. The customer’s own logins stay signed in.
While you are impersonating, you cannot change that person’s password or authenticator, accept legal terms or privacy notices for them, hand the session off to another host, or manage their device notifications. If they still need to accept a notice, you will see the prompt but cannot accept it in their place. Clicks and jobs you do while impersonating are saved, but they do not change Usage charts, first jobs, or unused-page Signals. Those stay about real customer use. Impersonate always serves the Published blueprint. There is no role picker, Draft switch, or Reset. Reset would wipe a real person’s data.

Authenticator

Impersonate always asks for a fresh authenticator code. It does not turn on authenticator-at-sign-in for every builder. Set up an authenticator app on Profile when you are ready. A reminder can appear until you enroll or dismiss it. Platform admins and builders on HIPAA-enabled apps already need an authenticator to use the dashboard. If you have not enrolled yet, Impersonate sends you to Profile first. After you scan the QR code, start Impersonate again.

Activity trail

Each person’s page has Impersonation activity. It lists every start, stop, and request made while someone impersonated them. Each start shows who began it, when it started, and when it ended (or when it is still active). If GenieForge staff were helping through your builder account, that row shows a GenieForge support badge. Staff names and emails are not shown.