Switch As (cross-shop support)
Actor | Targets |
|---|---|
Platform root (not impersonating) | Platform workspace members (if any) + admins of other shops (search/list) |
After Switch As into a shop | That shop’s members only |
Shop admin / manager | Own shop only (see users_and_team) |
Rules:
Cannot Switch As into another
platform administratoraccount.While Switch As: you are not a platform root actor — Tenants, Roles, Plans catalog, Knowgle admin, etc. drop away.
Exit with Back to platform root (or equivalent) when finished.
Root can reach suspended shops for support; ordinary shop staff cannot sign in while suspended.
/users as platform root
Shop admin | Platform root actor |
|---|---|
Own tenant only | All shop staff across tenants (including admins) + own root row |
Cannot delete peer / last admin | Can delete shop users including the last admin — the empty shop may be removed from Tenants |
— | Extra Print shop column |
— | Cannot delete/deactivate/change other root accounts |
Prefer deactivate over delete for support. Last-admin deletion is destructive for the shop record.
/roles — global catalog
Create/edit roles and permission matrices at
/roles,/roles/new,/roles/[id]/edit.Requires platform root actor.
Shops only assign existing roles on
/users— they never edit this catalog.
See shop documentation: users_and_team/03-roles-permissions-groups.md.
Directories (root)
Route | Purpose |
|---|---|
| Cross-tenant company directory |
| Cross-tenant member profiles |
Prefer Switch As and plan assignment over editing live customer data unless support asks.