Delegated sessions
Your staff are never members of a client organization. To work inside a client, an operator opens a delegated session: a window of at most a few hours, scoped to one client, with a stated reason, ending on its own. The platform checks the session, not a membership, on every read and write the operator makes, so when the session ends the access is gone with it.
Starting one
Three ways in, all leading to the same dialog:
- Act as Client on a client's page.
- Jump to a client in the top bar, then any client under Recent or All Clients.
- A client listed under Active Sessions in that same menu, which skips the dialog and takes you straight in, since a session is already open.
The Act as Client dialog asks for:
- Reason: routine service delivery, evidence review, compliance assessment, incident response, client onboarding or setup, QBR preparation, report generation, client-requested support, billing review, client offboarding, or other.
- Details: at least ten characters of your own words. The button stays off until you have written them.
- Duration: 15 or 30 minutes, or 1, 2, 4 or 8 hours. Your partner may set a lower maximum, in which case the request is capped to it.
- Access level: full access, or read only. Read only wins over whatever your role would allow.
The dialog says what happens next, and it is true: the session is logged with your identity, reason and every action performed, and the client's own administrators can review that log.
What decides what you can do inside
Three things, applied together at the moment the session starts:
- Your role at the partner sets the ceiling. Administrators can read, create, update and delete; compliance managers, vCISOs, analysts and most other roles can read, create and update; auditors and read-only executives can read.
- Team assignment. Everyone except the two administrator roles must be assigned to the client through a team, or the session is refused with that reason. A team assigned at a read-only or advisory level caps the session at read.
- Module access set for your team on this client, if any has been set, restricts you to those modules.
Other refusals you can meet: the organization is not managed by your partner, it has been archived, or you already have a live session there (use it from Active Sessions instead).
Inside the client
You land in the client's normal workspace. A banner across the top reads DELEGATED SESSION with the reason and a countdown; it turns red in the last five minutes. The organization switcher shows "via MSP Session" under the client's name instead of a role. The session is also counted on the partner dashboard's active sessions figure and listed under Active Sessions in the client menu, with its minutes remaining, for as long as it runs.
Ending
- End Session in the banner asks for an optional note ("Work completed, review finished") and returns you to the client list.
- When the countdown reaches zero the session expires and you are returned to the client list. Nothing you did is lost; you have simply left.
- A partner administrator can revoke a live session from Sessions, with a reason. The operator's access ends within about half a minute.
The record
Sessions lists the most recent sessions across the partner: operator, client, reason, scope, status (active, ended, expired, revoked), start time and duration. Search by operator, client or the reason text. Administrators revoke from here.
Audit Trail (under Settings) lists every action by every operator across every client, with the action, the object it touched, and how the operator got there: actions taken inside a delegated session carry the session's reason. Filter by action name, or show delegated-session actions only.
Everything in both lists is also written to the client organization's own audit log, where the client's administrators see it under their own name for the record, not yours.