> ## Documentation Index
> Fetch the complete documentation index at: https://docs.genieforge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Impersonate an end user

> See the portal as a real person. Changes are live. Preview as stays the role sandbox.

# Impersonate an end user

**Impersonate** lets you use the portal as a specific customer so you can see exactly what they see. This is different from [Preview as](/users-and-access/preview-as). Preview as uses a disposable test user for a role. Impersonate uses the real person.

You must be an app **owner** or **admin**. The person must be active, with a project membership, and not a platform (synthetic) user.

## How to start

1. Open **End-Users** and select the person, or use **Impersonate** on the list.
2. Confirm that anything you do is real for their account (messages, records, settings).
3. Enter a fresh code from your authenticator app.
4. Work in their portal. The banner shows who you are impersonating.
5. Choose **Stop impersonating** when you are done. That ends the impersonation session immediately, including any copied token. Portal **Sign out** and idle timeout also end it. Starting Impersonate again (on this person or someone else) ends your previous impersonation session. The customer's own logins stay signed in.

While you are impersonating, you cannot change that person's password or authenticator, accept legal terms or privacy notices for them, hand the session off to another host, or manage their device notifications. If they still need to accept a notice, you will see the prompt but cannot accept it in their place.

Clicks and jobs you do while impersonating are saved, but they do not change **Usage** charts, first jobs, or unused-page Signals. Those stay about real customer use.

Impersonate always serves the **Published** blueprint. There is no role picker, Draft switch, or Reset. Reset would wipe a real person's data.

## Authenticator

Impersonate always asks for a fresh authenticator code. It does not turn on authenticator-at-sign-in for every builder.

Set up an authenticator app on **Profile** when you are ready. A reminder can appear until you enroll or dismiss it. Platform admins and builders on HIPAA-enabled apps already need an authenticator to use the dashboard.

If you have not enrolled yet, Impersonate sends you to **Profile** first. After you scan the QR code, start Impersonate again.

## Activity trail

Each person's page has **Impersonation activity**. It lists every start, stop, and request made while someone impersonated them. Each start shows who began it, when it started, and when it ended (or when it is still active). If GenieForge staff were helping through your builder account, that row shows a **GenieForge support** badge. Staff names and emails are not shown.

## Related

* [Preview as a role](/users-and-access/preview-as)
* [Inviting and managing end users](/users-and-access/inviting-end-users)
