Act as (User impersonation)
ThoughtSpot allows authorized administrators to start a session as another user, referred to as Act as user. While in this mode, the administrator sees ThoughtSpot exactly as the target user does, with the same data access, role-based permissions, Org context, content visibility, and theme. Every action taken during the session is recorded in the audit log under the administrator’s identity.
Use Act as user to:
-
Reproduce permission-related issues without creating shadow accounts or requesting screen shares.
-
Verify that row-level security, column-level security, and sharing rules apply correctly before rolling out changes.
-
Provide support by seeing and resolving issues in the user’s exact context.
Prerequisites
Act as user is available for ThoughtSpot Analytics customers with the new Admin Portal enabled. A cluster administrator must turn on the feature from Admin > Feature Management > Early Access.
Who can use this feature
Administrators
| Administrator role | Can impersonate |
|---|---|
Cluster Admin |
Regular users and Org Admins across all Orgs |
Org Admin |
Regular users in their own Org only |
Neither Cluster Admins nor Org Admins can impersonate themselves or another Cluster Admin.
Target users (consent)
Each user controls whether administrators can impersonate their account. In Act as setting on the user’s profile, the Allow admins to act as you preference is set to Don’t allow by default. Before an administrator can start a session as that user, the user must grant access for one of the following periods:
-
Allow for 6 hours
-
Allow for 24 hours
-
Allow for 3 days
Access expires automatically at the end of the selected period, and the setting returns to Don’t allow.
The user receives an email at the start and end of an impersonation session. For more information, see Allow administrators to act as you.
Session behavior
What the administrator can do
During an impersonation session, the administrator has full access to the platform as the target user. The following actions are permanently blocked:
| Action blocked during impersonation |
|---|
Change password, MFA settings, or email |
Issue or revoke API tokens |
Modify role or group membership |
Accept or change EULA settings |
Transfer object ownership |
Delete the user account |
Export large data sets or send data to external integrations |
|
Third-party and agentic capabilities, such as Spotter, AgentSpot, and Analyst Studio, are unavailable during an impersonation session by default. |
Session limits and expiry
Sessions end when any of the following conditions are met first:
-
The administrator selects Exit session in the impersonation banner.
-
The session reaches the cluster’s standard idle timeout.
-
The session reaches the 60-minute hard cap from when impersonation started. This limit cannot be extended and applies regardless of activity.
Closing a browser tab does not end the session. All browser tabs share the same impersonation session. An administrator can have only one active impersonation session at a time.
What happens when a session ends
When a session ends, the administrator is signed out of ThoughtSpot. On clusters that use SSO with automatic redirect, the identity provider re-authenticates the administrator as themselves automatically.
|
On IAM v2 clusters with Okta SSO, the system clears the Okta SSO session on impersonation start to keep ThoughtSpot’s session and the IdP session in sync. On non-auto-redirect SSO clusters, the external IdP session remains active after impersonation ends, and the administrator is re-authenticated as themselves by the IdP. |
Start an impersonation session
Before you can act as a user, the user must grant access in Act as setting on their profile.
-
Navigate to Admin settings > User management.
-
Locate the user you want to act as.
-
Click the Act as user option from the user’s action menu.
The Act as user option is visible only if the target user is an
Activeuser.A colored impersonation border appears around the perimeter of the screen. You are now viewing ThoughtSpot as the target user.
-
To end the session before it expires, click Exit session.
ThoughtSpot ends the session and signs you out. On SSO clusters with auto-redirect, you are automatically re-authenticated as yourself.
Limitations
-
The support is currently only through the ThoughtSpot UI.
-
An administrator cannot impersonate themselves.
-
Only one active impersonation session is allowed per administrator at a time.
-
The session cannot be extended past 60 minutes.