# Allow specific users to impersonate defined users

**URL:** <https://meta.discourse.org/t/allow-specific-users-to-impersonate-defined-users/110340>\
**Category:** Development\
**Tags:** impersonate\
**Created:** [February 28, 2019, 12:37pm UTC](https://meta.discourse.org/t/allow-specific-users-to-impersonate-defined-users/110340 "2019-02-28T12:37:20Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![merefield](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/merefield/32/176214_2.png) [@merefield](https://meta.discourse.org/u/merefield)\
**Post date:** [March 4, 2019, 5:27pm UTC](https://meta.discourse.org/t/allow-specific-users-to-impersonate-defined-users/110340/5 "2019-03-04T17:27:23Z")

</div>

Also, forgive me for asking, but why would you want to do this in Production at all?

The only person(s) that should have this capability are surely the Admins and then sparingly.

Impersonation is useful for checking out an update but it also has impacts such as updating their ‘last seen’ stats.

From a legal perspective, the admin is probably an agent or the owner of the company running the website. They have licence to view the data as part of their role. Giving people without such licence the ability to see people’s private information is almost certainly a GDPR issue? I think for some jurisdictions this would be a non-starter.

---

_[View the full topic](https://meta.discourse.org/t/allow-specific-users-to-impersonate-defined-users/110340)._
