Xgenious/ docs

How It Works

Starting Impersonation

Step 1: Navigate to User

  1. Go to Admin > Users
  2. Find the user you want to impersonate
  3. Click to view user details

Step 2: Click Impersonate

  1. On the user details page, find the Impersonate button
  2. Click the button
  3. Confirm if prompted

Step 3: User View

  1. You are now logged in as the user
  2. See the platform from their perspective
  3. A banner appears at the top: "Impersonating [User Name] — Return to admin"

During Impersonation

What You Can Do

  • Browse the platform as the user
  • View their dashboard and settings
  • Test features and workflows
  • Verify user experience

What You Cannot Do

  • Access admin panel (unless you have admin permissions)
  • Make changes that affect other users
  • Access sensitive data not visible to the user

Return Banner

A fixed banner appears on every page:

┌─────────────────────────────────────────────┐
│ Impersonating John Doe — Return to admin    │
└─────────────────────────────────────────────┘

Stopping Impersonation

Method 1: Click Banner

  1. Click the "Return to admin" link in the banner
  2. You return to the admin panel

Method 2: Manual Return

  1. Navigate to /impersonate/stop
  2. You return to the admin panel

Session Handling

Admin Session

  • Preserved — Your admin session is kept
  • No re-login — Return without logging in again
  • State maintained — Admin tabs/windows remain open

User Session

  • Temporary — Only exists during impersonation
  • No changes — User data is not modified
  • Clean exit — Session destroyed when stopping

Security

Permissions

  • Requires impersonate-users permission
  • Only users with user_type 1 (client) or 2 (freelancer) can be impersonated
  • Admin must have explicit permission to use this feature

Activity Logging

All impersonation events are logged:

  • Start time — When impersonation began
  • End time — When impersonation stopped
  • Admin user — Who performed the impersonation
  • Target user — Who was impersonated

Audit Trail

Logs are available for:

  • Security audits
  • Compliance requirements
  • Troubleshooting

Best Practices

  1. Use for support — Help users with specific issues
  2. Test thoroughly — Verify features work correctly
  3. Log activities — Keep records of impersonation usage
  4. Limit access — Only grant permission to trusted admins
  5. Communicate — Inform users if impersonation is for support

Troubleshooting

Cannot See Impersonate Button

  • Verify you have impersonate-users permission
  • Check user type (client or freelancer only)
  • Clear browser cache
  • Check if impersonation is active
  • Verify JavaScript is enabled
  • Clear browser cache

Cannot Return to Admin

  • Navigate to /impersonate/stop directly
  • Clear browser cookies
  • Contact system administrator

Last updated: September 2026

Still stuck?
Our support team is ready to help you get set up.
Get support