Impersonate a staff member or role group/s
Kirby
There are often issues with staff not being able to access or complete a task and unlike the ability to impersonate a student or parent/carer, you'd have to sit next to the staff member to see what they see. It'd be great to impersonate a staff member OR select the relevant permission groups that the staff member has.
We've created a local staff account where we can add permission groups to somewhat impersonate. I can understand the potential issues surrounding the ability to impersonate a staff member, i.e., creating chronicles and writing anything; however, is there an option to create a detailed audit log as well?
A
Andrew Donovan
This is a useful feature when troubleshooting issues from staff or for testing and setup purposes. While some schools may be against this features . there are ways that this can be controlled, managed and audited. Schools that don't want this feature, can simply not have it enabled. Schools that would like to have this feature can ask Compass to have it enabled. it would be a permission based, Any time a staff member is impersonated, there is an audit of this happening and ideally what they access.
C
Craig Friend
Very Useful feature could be turned on per Compass Instance if requested, in read-only mode and audited.
Christopher Ruming (CENET)
I agree completely with Riki but I can also see benefits to this and the restrictions without it. I don't think it should be possible to impersonate another staff member, and I definitely would not support this either. I also think there are issues with creating the local account too, if multiple people can use/access it, give it any god-mode permission, there is no auditable tracking who used the account to do anything. It's also a nightmare from a cyber security perspective if it's a simple generic password. There needs to be a better way for staff in schools to do this in a way that isn't a legal dispute waiting to happen.
I would support the alternative suggestion of this idea though, for staff with certain permissions to "select the relevant permission groups that the staff member has." Something that works like impersonate, but what it does is keeps you logged in still but restricts permissions of your own existing profile as though it was the permission group or groups you've selected. You can then see what others at that level are able to see to help troubleshooting, but anything you do is still in your account. Then when you're done like when impersonating, logging out and back in resets permissions back to the original, or maybe there's a button to review back, kinda like how some other programs have a "preview". It also needs to be tested properly to ensure someone can't use it to get sponsors, principals or another escalated permission when they were originally much lower than this.
Kirby
Thanks Christopher Ruming (CENET)! I think there are benefits from somehow implementing this feature while preventing the potential 'legal dispute'!
Our local account is currently only accessible by me and our IT team, who all have CompassSponsor access anyway.
It's been great to have perspectives shared. I was 100% certain the issue around security etc. would be raised. I'm just not sure if Compass will review it or how a detailed audit log and further security tools could be implemented.
Riki Wood (DLCS)
Our Diocese would not be supportive of this. Not even in a restricted or read only view. This is a huge security and privacy issue.
If a staff member is having a technical issue, then you should arrange to sit with them or zoom/video meet with them to be able to see what they see.
Kirby
Riki Wood (DLCS) I can understand these points. I think for me the main benefit of this is understanding the potential flow-on effect when changing permissions within groups i.e. removing a specific permission from a group, will it affect something a staff member should usually be able to do.
It doesn't necessarily need to be impersonating a specific staff member's account, instead the selected role group/s. Additionally, it might be a permission group controlled via a request to Compass or built into just the CompassSponsors role group.
Riki Wood (DLCS)
Kirby We have stand alone test portals that we use to test these things - so that we can make changes and test the impacts in a test environment without impacting Live Production data
Kirby
Riki Wood (DLCS) Oh, that would help! We're a Vic Government school and don't have access to a test portal. We only have our school Compass portal, hence why we can't test these changes without affecting users and so forth. :)
L
Luke Compston
I would suggest a read only version, but limit chronicle entries to what the user with Impersonation rights could normally see.
i.e. If this was granted to CompassTechnician - but that role only had Chroncile Level 2, then restrict them to that.