LLMs.txt directory

Act as (User impersonation)

ThoughtSpot allows authorized administrators to start a session as another user, referred to as Act as user. While in this mode, the administrator sees ThoughtSpot exactly as the target user does, with the same data access, role-based permissions, Org context, content visibility, and theme. Every action taken during the session is recorded in the audit log under the administrator’s identity.

Use Act as user to:

  • Reproduce permission-related issues without creating shadow accounts or requesting screen shares.

  • Verify that row-level security, column-level security, and sharing rules apply correctly before rolling out changes.

  • Provide support by seeing and resolving issues in the user’s exact context.

Prerequisites

Act as user is available for ThoughtSpot Analytics customers with the new Admin Portal enabled. A cluster administrator must turn on the feature from Admin > Feature Management > Early Access.

Who can use this feature

Administrators

Administrator role Can impersonate

Cluster Admin

Regular users and Org Admins across all Orgs

Org Admin

Regular users in their own Org only

Neither Cluster Admins nor Org Admins can impersonate themselves or another Cluster Admin.

Each user controls whether administrators can impersonate their account. In Act as setting on the user’s profile, the Allow admins to act as you preference is set to Don’t allow by default. Before an administrator can start a session as that user, the user must grant access for one of the following periods:

  • Allow for 6 hours

  • Allow for 24 hours

  • Allow for 3 days

Act as setting on the user profile

Access expires automatically at the end of the selected period, and the setting returns to Don’t allow.

The user receives an email at the start and end of an impersonation session. For more information, see Allow administrators to act as you.

Session behavior

What the administrator can do

During an impersonation session, the administrator has full access to the platform as the target user. The following actions are permanently blocked:

Action blocked during impersonation

Change password, MFA settings, or email

Issue or revoke API tokens

Modify role or group membership

Accept or change EULA settings

Transfer object ownership

Delete the user account

Export large data sets or send data to external integrations

Third-party and agentic capabilities, such as Spotter, AgentSpot, and Analyst Studio, are unavailable during an impersonation session by default.

Session limits and expiry

Sessions end when any of the following conditions are met first:

  • The administrator selects Exit session in the impersonation banner.

  • The session reaches the cluster’s standard idle timeout.

  • The session reaches the 60-minute hard cap from when impersonation started. This limit cannot be extended and applies regardless of activity.

Closing a browser tab does not end the session. All browser tabs share the same impersonation session. An administrator can have only one active impersonation session at a time.

What happens when a session ends

When a session ends, the administrator is signed out of ThoughtSpot. On clusters that use SSO with automatic redirect, the identity provider re-authenticates the administrator as themselves automatically.

On IAM v2 clusters with Okta SSO, the system clears the Okta SSO session on impersonation start to keep ThoughtSpot’s session and the IdP session in sync. On non-auto-redirect SSO clusters, the external IdP session remains active after impersonation ends, and the administrator is re-authenticated as themselves by the IdP.

Start an impersonation session

Before you can act as a user, the user must grant access in Act as setting on their profile.

  1. Navigate to Admin settings > User management.

  2. Locate the user you want to act as.

  3. Click the Act as user option from the user’s action menu.

    Act as user

    The Act as user option is visible only if the target user is an Active user.

    A colored impersonation border appears around the perimeter of the screen. You are now viewing ThoughtSpot as the target user.

    Impersonation border around the ThoughtSpot interface
  4. To end the session before it expires, click Exit session.

    Exit session button in the impersonation banner

    ThoughtSpot ends the session and signs you out. On SSO clusters with auto-redirect, you are automatically re-authenticated as yourself.

Limitations

  • The support is currently only through the ThoughtSpot UI.

  • An administrator cannot impersonate themselves.

  • Only one active impersonation session is allowed per administrator at a time.

  • The session cannot be extended past 60 minutes.