ArchitectureA supervised JVM-class runtime — OLTP on seven engines, OLAP on three. AI-native, MCP-native, observable as plain SQL.Read the architecture
Está viendo la edición Perú. Está viendo la edición Colombia. You're viewing the Pakistan edition. Cambiar a la edición global →Cambiar a la edición global →Switch to the global edition →

Acting as another user, with the session marked and the loan bounded

A user may act as another and borrow that user's roles, databases and menu. The session shows an Alias or Admin tab, a delegation merges or supplants, and the admin login, MCP and the chat assistant serve the caller.

Support staff, auditors and administrators regularly need to see the system as another user sees it. This release makes that a declared delegation in the configuration database rather than a shared password: one user may act as one other user, the alias, and what is borrowed is bounded and visible.

What is borrowed

  • Roles, databases and menu The alias's roles and databases merge into the delegating user's, alias first, and the alias's group menu is served ahead of the user's own.
  • Only what the alias holds An alias lends what it holds itself, never what it borrows. Delegation does not chain.
  • Identity stays the user's Name, code, photo and every group-scoped setting remain the delegating user's own.
  • A blocked or expired alias lends nothing The refusal takes effect on the user's next call without a reload, and the configuration database refuses a reverse delegation for an overlapping period.

Two modes

  • Merge The default: the user's own grants plus the alias's.
  • Supplant The alias's roles, databases and menu replace the user's own, and the session identity becomes the alias alone. If the alias is blocked, the user acts as themselves.

Visible, and bounded

  • A marked session The toolbar hangs a tab from a coloured stripe reading Admin for an elevated session or Alias with the alias's code, the way a cloud console marks an assumed role. The hover text says what is inherited.
  • Administrator mode The user menu gains a switch, offered to users who may use the administration login, which closes the session and signs in again. The administration login page is recognisable: a shield, a notice, a dedicated button and no external identity providers.
  • The administration login refuses the loan An administrator signing in through /admin acts as themselves. No delegation lends roles, databases or a menu to that session, whether it merges or supplants.
  • MCP and the chat assistant refuse it too An agent is admitted, judged and connected on the caller's own rows. The merge had leaked into MCP: a developer with a bounded ceiling on one database was served no tool at all, because the acted-as user held that database without AI access. One resolver now names the caller for every gate, provider and tool.

The list of users a user may act as is served by the same resolver that performs the merge, so the toolbar and the grant cannot disagree.