User Impersonation allows authorized users to access another user's account view — without requiring password sharing or credential handoff. It's designed to support troubleshooting, experience validation, and account-level review across your franchise hierarchy.
Note: This feature is off by default. To enable it, email helpdesk@franconnect.com. Configurable options include impersonation access scope, impersonation alerts, and same-level (lateral) impersonation.
What you can do:
- Troubleshoot user issues directly from their perspective
- Validate the user experience at lower hierarchy levels
- Review account-specific behavior
- Maintain a full audit trail — all sessions are logged
Topics Covered
- Who Can Impersonate Whom
- Automated vs. Manual Access
- Automated Impersonation Mapping
- Manual Impersonation Access
- Email Notifications
- Audit & Login Logs
Who Can Impersonate Whom
Impersonation follows your organizational hierarchy. A user can only impersonate accounts at their level or below, and only within their assigned area.
Hierarchy Table
| User Type | Can Impersonate |
|---|---|
| Corporate | Any Divisional, Regional and Franchise user |
| Divisional | Franchise users within the same division/area and Regional (Training & Development Integrated Systems only) |
| Regional | Franchise users within the same area/region |
| Franchise | Franchise employees within the same location |
Lateral (same-level) impersonation is off by default and must be explicitly enabled during feature setup.
Worked Example
Jane is a Divisional user in Division A.
She can impersonate:
- Franchise users within Division A
- Regional users assigned to Division A (if Training & Development Integration is active)
She cannot impersonate:
- Corporate users
- Divisional users in Division B
- Another Divisional user in Division A (unless lateral impersonation is enabled)
Automated vs. Manual Access
Your account runs one of these two methods, chosen when User Impersonation is set up. Use the table below to work out which one applies to you and where to go from there.
| Automated (by role) | Manual (per user) | |
|---|---|---|
| How access is granted | Inherited from the role’s impersonation privilege | Assigned to each user individually |
| Where you configure it | Admin > Access Control > Roles > Action > Modify Privileges | Admin > Users > [user type] > Action > Manage Impersonate User |
| Who it covers | Every current and future holder of the role | Users individually assigned by a Corporate user |
| How access is removed | Clear the privilege on the role | Corporate user can remove the user from the mapping list |
To switch your account from one method to the other, contact helpdesk@franconnect.com.
Note: Mobile impersonation is not supported.
Automated Impersonation Mapping
Automated impersonation mapping removes the per-user mapping step entirely. Instead of listing permitted accounts for each user by hand, you grant the impersonation privilege to a role, and every user who holds that role is mapped automatically, both the users assigned to it today and anyone assigned to it later.
In most systems the Corporate and Divisional roles already carry the impersonation privilege, so users in those roles are covered as soon as automated mapping is active. For every other user type, enable the privilege on their role first and mapping then follows on its own.
Note: Automated and manual mapping are mutually exclusive. A system uses one method or the other, decided when the feature is set up for your account; they cannot run at the same time. With automated mapping active, the per-user Manage Impersonate User step does not apply.
How Automated Mapping Works
Mapping is driven entirely by role privileges. Once a role carries the impersonation privilege, FranConnect keeps the impersonation list in step with role membership:
- Users already assigned the role are granted impersonation access immediately.
- Users assigned the role later are granted access at the point of assignment.
- Access always stays inside the hierarchy rules described in Who Can Impersonate Whom
- No per-user mapping is maintained anywhere
Grant Impersonation Access by Role
Required role: Corporate Admin
Navigation: Admin > Access Control > Roles > [Select role] > Action > Modify Privileges
-
Go to Admin > Access Control and click Roles.
- Locate the role you want to make impersonation-eligible.
-
Click the Action button for that role and select Modify Privileges.
-
Under Can Manage Administer > Can Administer Users, select the Can Manage Impersonation Access checkbox. Its description reads “Grants access to impersonate users within hierarchy”. Click Save.
Result: Every user currently assigned that role is granted impersonation access immediately and appears in the impersonation list, with no action needed in Manage Impersonate User. Any user assigned that role afterwards is granted access at the point of assignment.
Note: The privilege is available on configurable roles. Default roles marked with an asterisk on the Roles page cannot be modified.
Impersonate a Mapped User
Available to: Any user whose role carries the impersonation privilege
Because mapping is automatic, an authorized user can start a session straight from the user list, there is no mapping step to complete first.
Navigation:
- In the top-right corner, click the dropdown icon next to your username.
-
Select Impersonate User. A side drawer opens showing users you are authorized to impersonate.
Note: You can also start and end a session from the dropdown next to your username, as described in Start an Impersonation Session and End an Impersonation Session below.
Manual Impersonation Access
The steps below apply to systems where automated mapping is not in use. Here access is granted user by user rather than by role, and no role privilege is involved. If automated mapping is active for your account, use Automated Impersonation Mapping above instead — the two methods cannot be combined.
Assign Impersonation Access
Required role: Corporate Admin
Impersonation access is configured per user. Each user must be explicitly granted a list of accounts they are permitted to impersonate.
Navigation: Admin > Users > [Select user type] > Action menu > Manage Impersonate User
- Go to Admin > Users and select the user type: Corporate, Divisional, Regional, or Franchise.
- Locate the user you want to configure.
- Click the Action button for that user → select Manage Impersonate User. A side drawer opens.
- Use the multi-select dropdown to choose which users this person is allowed to impersonate. Users are grouped by type: Corporate, Regional, Divisional, Franchise.
- Click Save.
Result: The selected users will now appear in that user's Impersonate User menu when they initiate a session.
Start an Impersonation Session
Available to: All authorized users (impersonation access must be pre-assigned by an Admin)
- In the top-right corner, click the dropdown icon next to your username.
- Select Impersonate User. A side drawer opens showing users you are authorized to impersonate.
- Select the user you want to impersonate. The session starts immediately.
- A banner appears at the top-right: "You are impersonating [username]"
If No Users Are Available
If you haven't been granted any impersonation access, the drawer displays:
"No impersonate access available. You do not have permission to impersonate any users at this time. Please contact your administrator to request access."
End an Impersonation Session
Available to: Any user in an active impersonation session
- Click the dropdown icon next to the username in the top-right corner.
- Select End Impersonation.
You are immediately returned to your own user session.
Email Notifications
Users can receive email alerts when impersonation access is assigned to them, and when an active session begins.
Navigation to configure: Options > Integration > Notifications > User Impersonation Email Notifications (checkbox)
| Trigger | Condition for Email |
|---|---|
| Impersonation access assigned to user | Checkbox is enabled |
| Impersonation session starts | Checkbox is enabled |
Audit & Login Logs
Required role: Admin or Corporate Admin with Login Log access
All impersonation sessions are recorded. Use this to audit who impersonated which account and when.
Navigation: Admin > Access Control > Login Logs > User Logged In tab
- Navigate to Admin > Access Control > Login Logs.
- Select the User Logged In tab.
- Locate the relevant user and click the value in the Login(s) column.
- Review the Impersonated By Name column to identify who initiated the session.