This is the full behaviour behind Viewing the platform as somebody else. Read it before you let anybody use View as, because the interesting part is not how to start a session. It is what the person can do once they are in one, and what everybody else can find out afterwards.
The model
Section titled “The model”You borrow somebody’s eyes, not their hands.
Reading is not restricted at all. Seeing what the other person sees is the entire point, so every query runs exactly as it would for them.
Writing is refused by default. An action is allowed only if it has been named as allowed, so anything not on that list is blocked — including everything added to the product after the list was written.
That direction matters more than any individual rule below. A permission system that allows by default leaks every time somebody builds something new and forgets. This one goes quiet instead, and the person in the session is told the action is unavailable rather than left wondering.
What you can still do
Section titled “What you can still do”Ordinary authoring and configuration: courses, media, categories, groups, departments, skills, reports and dashboards. The test applied is whether the change is reversible, is not evidence, and has no effect outside Learnient.
What is refused
Section titled “What is refused”Three groups, for three different reasons.
Anything that could let you back in later. Passwords, passkeys, two-factor, recovery codes, tokens, API keys and sign-on settings. Somebody who has been in another person’s session must not be able to leave a route in behind them.
Anything that changes who they are. Their email address and their profile. The profile is on this list for a second reason worth knowing: it is where support access is consented to, so allowing it would let somebody widen their own access from inside a session.
Anything that produces evidence in their name. Completing a course, answering an assessment, signing an attestation, downloading a certificate, recording attendance, writing a review, giving peer feedback or setting a goal. Nobody should be able to create a compliance record on somebody else’s behalf, and a training record is worth nothing if they could.
This is the group people are surprised by, because it blocks the obvious way to test a course. You cannot check that an assessment marks correctly by sitting it as a learner. Use a test user of your own.
The session ends whether you are finished or not
Section titled “The session ends whether you are finished or not”A View as session lasts an hour, and ends after fifteen minutes of inactivity, whichever comes first. The hour is not left to guess at: the banner across the top of every page in the session counts it down, opening at ends in 59m.
Support access is the same machinery with different limits — eight hours, and thirty minutes idle — because a Learnient engineer is working a case rather than answering one question.
What the record keeps
Section titled “What the record keeps”Every session is written down: who started it, who they viewed, the reason they typed, when it began and ended, how it ended, and the address and browser they used.
Both email addresses and both role names are copied onto the record itself rather than looked up later. That is deliberate. It means the record still reads correctly after somebody is renamed, changes role, is archived or is purged — an audit trail that stops making sense once the people in it leave is not an audit trail.
Nothing edits a record and nothing deletes one. Finished sessions are removed 24 months after they end, and that is the only way one leaves.
Where the record lives
Section titled “Where the record lives”Every session is written to Audit logs, as it starts, as it ends, and again if it is revoked or times out — four separate events rather than one row edited in place.
Each entry carries both people and the circumstances. A support session is written into your account’s log rather than Learnient’s, so it is visible to you rather than only to them.
The list names both people. Who is the person who ran the session and Did what names the person who was viewed, each with their work ID, so “who was looked at, and by whom” can be answered from the list itself. Filter Record types to impersonation sessions to see them on their own.
Opening an entry shows the rest: the reason given, word for word, the ticket reference for tying the session to a support case, the session type (View as or support access) and its status. A revoked session also says why it was revoked, which is how a session that was cut off reads differently from one that was stopped or that ran out. Context carries the IP address it was run from.
Audit logs is the one place to look. There is no separate impersonation screen, and there was briefly a second one — it was removed precisely because two surfaces showing one record cannot be kept in step.
What it looks like from inside
Section titled “What it looks like from inside”The session is never ambiguous. You land on that person’s own view rather than the admin area, the administration navigation is not there, and a banner sits above everything naming both people — Viewing as their name, started by your email address — with the time remaining and an Exit button. The promise that the session is recorded is made on screen, in front of the person making it, for its whole duration.
Leaving returns you to the screen you started from, signed in as yourself, with any filter still applied.
How a session ends
Section titled “How a session ends”Leaving ends it. So does either time limit. Beyond that, the control you have is over support access rather than over individual sessions: turning Enable support access off ends every Learnient session in your account at once and withdraws consent for new ones.
That is broader than ending one session and more honest than a list of buttons, because it is the consent itself you are withdrawing.
What this means for your account
Section titled “What this means for your account”Give View as to the small number of people who genuinely answer “it is not working for me”. Then make sure somebody actually reads Audit logs — the recording is what makes the feature accountable, and a record nobody opens is not oversight.
Then decide about support access on its own terms. It is a different consent with longer limits, and the log is where you check whether it has been used.

