SUPPORT SESSION ACCOUNTABILITY
Impersonation Events
Trace approved support access and Login-as-Provider sessions.
Audit records may contain workforce identities, Provider identifiers, Individual references, IP addresses, device details, routes, request metadata, support-session identifiers, and before-and-after values. Screenshots in this public guide use redacted or demonstration information. Production access must remain Provider-scoped, role-based, purpose-limited, and restricted to authorized personnel.
True Care System records audit evidence to support accountability, privacy review, security investigation, operational integrity, and Provider governance. These capabilities support—but do not replace—the Provider's policies, workforce training, risk analysis, legal obligations, incident response, and retention program.
Purpose
Impersonation events document when an authorized platform support user temporarily enters a Provider context to investigate an approved ticket. The audit trail should preserve who initiated the session, which Provider and target account were used, the related support ticket, the session start and end, and actions performed during the session.
Expected Evidence
| Field | Function |
|---|---|
| Support ticket ID | Connects the session to the Provider's request. |
| Access approval | Shows whether the Provider approved support access. |
| Expiration | Defines when approval becomes invalid. |
| Actor user | Identifies the platform support person. |
| Target user or Provider | Identifies the account or tenant being accessed. |
| Impersonation session ID | Correlates all actions performed in the same session. |
| Start and end events | Establishes the session duration. |
| Actions during session | Links views, updates, exports, or other activities to the impersonation session. |
Security Expectations
- No support access without a valid business purpose and authorization.
- Provider scope must remain enforced throughout the session.
- All material actions must remain attributable to the real actor.
- Expired approvals must not permit new access.
- Session termination must be recorded.
