User Impersonation
The Impersonate User feature lets a Site Administrator temporarily inspect the web app from a specific user's perspective. Use it to understand what a user sees, check their access, or verify their configuration.
Impersonation is read-only. While impersonating, the Site Administrator sees the interface, file listings, and configuration available to the selected user, which makes it easier to help that user without changing anything on their behalf.
When to Impersonate a User
Common cases include confirming configuration and access for a newly onboarded user, reviewing a specific user's experience in real time, validating permissions for an internal team, and confirming that an external vendor is set up correctly.
If all you need to confirm is a user's, group's, or partner's folder permissions rather than their full experience, use the Check Access feature, found on that folder's Permissions tab, instead of starting a full impersonation session.
Starting an Impersonation Session
A Site Administrator can impersonate any user from the Impersonate User option on that user's details page. Starting the session replaces the Site Administrator's current session with the selected user's session. A banner appears at the top of every page to indicate that impersonation is active.
To end the session, log out and sign back in with the Site Administrator account. That is the only way to return to the original session.
All impersonation activity is recorded in the API Logs under the Site Administrator's identity for audit purposes.
Actions Restricted During Impersonation
Impersonation is intended to validate configuration, permissions, and how the site appears to a user. It does not extend to reading file contents or performing actions on that user's behalf. This is why even opening, previewing, and downloading files are unavailable in a read-only impersonation session.
Restricted actions include opening or previewing files, downloading, uploading, deleting, moving, or copying files, and creating share links. Modifying site settings or configuration, and running automations, triggers, or sync operations are also not permitted.
The Site Administrator can view folders, permissions, and configuration visible to the impersonated user.
To investigate the contents of a file, end impersonation and download it using your own administrator account. The file contents do not depend on which account downloads it. If the problem involves how that specific user opens, previews, or downloads the file, contact Files.com Support for help investigating it.