# Discourse Staff Alias

**URL:** https://meta.discourse.org/t/discourse-staff-alias/156202
**Category:** Plugin
**Tags:** official, staff-alias
**Created:** [June 29, 2020, 1:37am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202 "2020-06-29T01:37:01Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Discourse](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/discourse/32/148734_2.png) [@Discourse](https://meta.discourse.org/u/Discourse)
#### Post date: [June 29, 2020, 1:37am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/1 "2020-06-29T01:37:01Z")

</div>

| | | |
| --- | --- | --- |
| :discourse2: | **Summary** | **Discourse Staff Alias** allows set groups to create topics and posts, as well as make edits, as an alias user. |
| :hammer_and_wrench: | **Repository Link** | [https://github.com/discourse/discourse-staff-alias](https://github.com/discourse/discourse-staff-alias) |
| :open_book: | **Install Guide** | [How to install plugins in Discourse](https://meta.discourse.org/t/install-plugins-in-discourse/19157) |

> [@](#):
>
> :discourse2: As this is an #official plugin maintained by the Discourse team, #Support, #Contribute > Bug, #Contribute > UX, and #Contribute > Feature requests can be made in the respective categories here on Meta, and tagged with the appropriate plugin tag. Click on a link below to get one started. :+1:
> 
> [:question:&nbsp; **Support**](https://meta.discourse.org/new-topic?category_id=6&body=%3E%20Before%20asking,%20did%20you%20search%20first%3F%20Press%20%F0%9F%94%8D%20at%20the%20upper%20right%20to%20search.&tags=staff-alias "Ask for support on configuring and using Discourse Staff Alias") [:bug:&nbsp; **Bug**](https://meta.discourse.org/new-topic?category_id=1&tags=staff-alias "A bug report means something is broken, preventing normal/typical use of the plugin") [:eyes:&nbsp; **UX**](https://meta.discourse.org/new-topic?category_id=9&tags=staff-alias "Discussion about the user interface of Discourse Staff Alias, and how features are presented (including language and UI elements)") [:bulb:&nbsp; **Feature**](https://meta.discourse.org/new-topic?category_id=2&tags=staff-alias "Discussion about how existing Discourse Staff Alias features can be improved or enhanced, and how proposed new features could work")

  

The [Discourse Staff Alias](https://meta.discourse.org/t/discourse-staff-alias/156202/1) plugin allows certain groups to create topics and posts, as well as make edits, as an alias user. This can be useful in situations where staff members need to respond to queries or make announcements without revealing their personal usernames.

### Enabling Staff Alias

Once installed, the Staff Alias plugin can be enabled from its settings, accessed from your `admin/plugins` page:

 ![admin/plugins](https://global.discourse-cdn.com/meta/original/4X/3/a/2/3a269355a30b940dadaa1f09f7daa59895d00e25.png)

This plugin is default disabled, and before enabling a new username for the alias must be added to the `staff alias username` admin setting:

 ![staff alias username](https://global.discourse-cdn.com/meta/original/4X/1/3/9/1396aa3f6b0c86c7e860612ab2d0f118fe00991f.png)

Once the plugin is enabled, a user with that username will be created.

* * *
  

### Using the Alias

Once enabled, the staff alias can be toggled on using the composer’s actions drop-down, and users in the allowed groups can then choose to create topics and posts, as well as make edits, using the staff alias:

 ![create new staff alias topic](https://global.discourse-cdn.com/meta/original/4X/1/c/1/1c1bb421f14c9ff89e35a02ad98622c500f13c5e.png)

 ![reply as staff alias](https://global.discourse-cdn.com/meta/original/4X/e/e/5/ee5bb4c065faddda4c816cf6f42e40179dee7c6e.png)

 ![make a post edit as staff alias](https://global.discourse-cdn.com/meta/original/4X/6/c/5/6c54d38e84e9d761a2f3004108a404e837809b8f.png)

The topic/post/edit will then appear as if created by the staff alias:

 ![topic created using the alias](https://global.discourse-cdn.com/meta/original/4X/3/b/c/3bcd8bd29c58327b1832d64aef6661b8288fcddb.png)

  

* * *

### Keeping track of who used the Alias

If you are in one of the allowed groups you will also see a note of who created the topic or post, or made the edit:

 ![who used the alias - topic](https://global.discourse-cdn.com/meta/original/4X/5/b/3/5b31713dd633db0807826c2948ed22daa9f5b487.png)

 ![who used the alias - edit](https://global.discourse-cdn.com/meta/original/4X/a/7/7/a773d67c4d8e0461f0cdca0fe298fed467de0b7f.png)

* * *
  

### Settings

| Name | Description |
| --- | --- |
| staff alias enabled | Enable discourse-staff-alias plugin |
| staff alias username | Username of the alias user |
| staff alias allowed groups | Groups that are allowed to post as staff alias user |

> :discourse2: Hosted by us? This plugin is available on our Enterprise tier.

> Last edited by @Bas 2024-08-12T14:12:55Z
> 
> > **Check document**
> >
> > Perform check on document:

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [June 10, 2023, 7:02pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/16 "2023-06-10T19:02:00Z")

</div>

2 posts were split to a new topic: [Can the Staff Alias also be used for replies?](https://meta.discourse.org/t/can-the-staff-alias-also-be-used-for-replies/267906)

---

<div class="post-metadata">

### Author: ![sok777](https://avatars.discourse-cdn.com/v4/letter/s/82dd89/32.png) [@sok777](https://meta.discourse.org/u/sok777)
#### Post date: [September 12, 2023, 11:19am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/17 "2023-09-12T11:19:08Z")

</div>

> [@Discourse](#):
>
> You can use either an existing user account, or enter a new name for one to be created:

It seems we can’t add an existing user account. Why is that?  
 ![Screenshot 2023-09-12 at 12.17.48](https://global.discourse-cdn.com/meta/original/4X/7/2/f/72fccc037551529fcfed0fbe60ab24be6aab5ac6.png)

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [September 12, 2023, 11:29am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/18 "2023-09-12T11:29:16Z")

</div>

There’s a chance I made a mistake when writing up the instructions. :slight_smile:

I also can’t get an existing user to be a staff alias now I test it again, which makes sense when I think about it. I’m not sure what led me to believe it was possible. :thinking: I’ll update the instructions. :+1:

---

<div class="post-metadata">

### Author: ![sok777](https://avatars.discourse-cdn.com/v4/letter/s/82dd89/32.png) [@sok777](https://meta.discourse.org/u/sok777)
#### Post date: [September 12, 2023, 11:40am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/19 "2023-09-12T11:40:34Z")

</div>

Thanks! It’s a shame because I think it makes it unified when all staff members can use the site name or like a ‘master’ account that already exists. For example @Discourse

---

<div class="post-metadata">

### Author: ![barto\_95](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/barto_95/32/199996_2.png) [@barto\_95](https://meta.discourse.org/u/barto_95)
#### Post date: [January 12, 2024, 10:49am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/20 "2024-01-12T10:49:29Z")

</div>

when i test to create subject, i received the error message :frowning:

 ![CleanShot 2024-01-12 at 11.49.05@2x](https://global.discourse-cdn.com/meta/original/4X/0/e/4/0e44202eed0925357972b89d3ef3b5b431a23073.png)

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [January 12, 2024, 10:58am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/21 "2024-01-12T10:58:42Z")

</div>

Does your staff alias user have the right permissions to create a topic in that category? (do they have staff permissions)

---

<div class="post-metadata">

### Author: ![barto\_95](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/barto_95/32/199996_2.png) [@barto\_95](https://meta.discourse.org/u/barto_95)
#### Post date: [January 12, 2024, 11:17am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/22 "2024-01-12T11:17:24Z")

</div>

Yes this is the problem … :man_facepalming:

thank you :slight_smile:

---

<div class="post-metadata">

### Author: ![barto\_95](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/barto_95/32/199996_2.png) [@barto\_95](https://meta.discourse.org/u/barto_95)
#### Post date: [January 22, 2024, 1:17pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/23 "2024-01-22T13:17:58Z")

</div>

Its not possible to response on message replay on user with option staff alias i receive the error same above but if i use staff aliase to respond on message subject is ok

---

<div class="post-metadata">

### Author: ![jordan-violet](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jordan-violet/32/281428_2.png) [@jordan-violet](https://meta.discourse.org/u/jordan-violet)
#### Post date: [May 15, 2024, 6:27am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/24 "2024-05-15T06:27:13Z")

</div>

What are the chances this could be extended to be a dynamic “post as another user” tool?

We have a use case where we have a product communications manager who needs to create new topics as other product managers in our organization. This tool seems like most of the functionality is there, but would require the ability to set the user being posted as dynamically.

---

<div class="post-metadata">

### Author: ![fokx](https://avatars.discourse-cdn.com/v4/letter/f/958977/32.png) [@fokx](https://meta.discourse.org/u/fokx)
#### Post date: [May 24, 2024, 9:06am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/25 "2024-05-24T09:06:35Z")

</div>

I meet the same error every time I reply to some post that is **not** OP:

> An error occurred: You are not permitted to view the requested resource.

After digging into this a little bit, I find the culprit lies at:

> <https://github.com/discourse/discourse-staff-alias/blob/5e1855a2321c32a8fd4c78988954fa57f29b9cb9/lib/discourse_staff_alias/posts_controller_extension.rb#L17>

The problem is:

`params[:whisper]` is `"false"`, which is a String, so simply change this line to:

```ruby
if !DiscourseStaffAlias.user_allowed?(existing_user) || params[:whisper] == "true"

```

…will solve the issue.

I made a simple PR: [FIX: InvalidAccess when replying to non-original post by fokx · Pull Request #67 · discourse/discourse-staff-alias · GitHub](https://github.com/discourse/discourse-staff-alias/pull/67)

---

<div class="post-metadata">

### Author: ![Heliosurge](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/heliosurge/32/571810_2.png) [@Heliosurge](https://meta.discourse.org/u/Heliosurge)
#### Post date: [August 1, 2024, 4:10pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/26 "2024-08-01T16:10:51Z")

</div>

Hi Jordan,

I can think of a couple of options.

If your product manager is a full site mod they can use the wrench on the post to “change ownership” no plugins required

---

<div class="post-metadata">

### Author: ![Bas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bas/32/294929_2.png) [@Bas](https://meta.discourse.org/u/Bas)
#### Post date: [August 12, 2024, 2:15pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/27 "2024-08-12T14:15:46Z")

</div>

Wanted to note that I just spent a fair amount of minutes trying to figure out why a mystery moderator was created on a site.

This user had a random hash as email, it looked fairly suspect.

I think it would be good to leave a staff-note, log the “grant moderation” in the staff log, or give some other indication that this user was created by a plugin :slight_smile:

---

<div class="post-metadata">

### Author: ![Heliosurge](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/heliosurge/32/571810_2.png) [@Heliosurge](https://meta.discourse.org/u/Heliosurge)
#### Post date: [August 14, 2024, 3:13am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/28 "2024-08-14T03:13:35Z")

</div>

If your self Hosted or the plan supports it. The #Customization > Plugin User Notes is very handy

> [@Discourse User Notes](https://meta.discourse.org/t/discourse-user-notes/41026):
>
> discourse2Summary Share private notes with other staff about a user that normal users cannot see.open_bookInstall Guide This plugin is bundled with Discourse core. There is no need to install the plugin separately. Configuration The User Notes plugin can be enabled either by the toggle or from its settings, both accessible from your /admin/plugins page: Features Sometimes staff members want to share notes about…

---

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 16, 2024, 10:06am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/29 "2024-08-16T10:06:15Z")

</div>

I’m trying this out, and wondering: what is the expected behavior with regard to notifications and emails for the _staff\_alias_ user?

The _staff\_alias_ user gets a random string in place of an email address—so emails that would normally be sent are skipped.

I can’t give the staff alias a real email address, as Discourse tries to send a confirmation email to the random string.

Is _staff\_alias_ is a one-way street? Maybe I’m missing something. Is there—or should there be—a way to have it act as a “front” for a real account, like admin, that receives communications as usual?

---

<div class="post-metadata">

### Author: ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)
#### Post date: [August 16, 2024, 6:09pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/30 "2024-08-16T18:09:45Z")

</div>

> [@ToddZ](#):
>
> Is _staff\_alias_ is a one-way street

Yes.

In managing larger communities, identity can be quite tricky. When you allow many ”staff” to post as the “staff alias”, the actual moderator account who used the staff alias to post is also shown to staff as seen in the screenshot

> [@Discourse](#):
>
> ![who used the alias - topic](https://global.discourse-cdn.com/meta/original/4X/5/b/3/5b31713dd633db0807826c2948ed22daa9f5b487.png)
> 
> ![who used the alias - edit](https://global.discourse-cdn.com/meta/original/4X/a/7/7/a773d67c4d8e0461f0cdca0fe298fed467de0b7f.png)

If you put a “real account” behind the staff alias, there are then many other user options that are exposed which makes it difficult to vet which staff did what changes to the account.

What kind of “communication” are you expecting to receive? I feel like there’s another way to get to what you hope to achieve.

---

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 16, 2024, 9:44pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/31 "2024-08-16T21:44:12Z")

</div>

Thanks for responding, @nat. I simply figured that if I post with _staff\_alias_, users may respond, and I wouldn’t want to overlook them.

I feared nobody would see such notifications – but I’ve since found that I _do_ get these emails and notifications at the staff account that _used_ the alias. So, that’s cool.

Couple of remaining questions:

- The email Skipped log includes failures trying to send to the _staff\_alias_ bogus string. I’m guessing I can turn off all email settings for _staff\_alias_, and emails will still be triggered and sent to the “parent” staff account..?

- I can only see personal messages to _staff\_alias_ by digging into its profile via admin. Maybe it’s sensible to just disable personal messaging to _staff\_alias_?

Thanks for any advice there. :arrow_up:

I feel closer to understanding things after more experimenting… but the plugin topic could benefit from a mention of how notifications are routed, and some guidance around other relevant account settings.

---

<div class="post-metadata">

### Author: ![nat](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/nat/32/235063_2.png) [@nat](https://meta.discourse.org/u/nat)
#### Post date: [August 21, 2024, 6:27am UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/32 "2024-08-21T06:27:09Z")

</div>

> [@ToddZ](#):
>
> The email Skipped log includes failures trying to send to the _staff\_alias_ bogus string.

Ah, that should have been accounted for within the plugin itself. It is a lack of consideration when we built it so we should get that fixed.

> [@ToddZ](#):
>
> disable personal messaging to _staff\_alias_

This makes sense as a default. Let me check with my product team.

---

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 21, 2024, 5:39pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/37 "2024-08-21T17:39:44Z")

</div>

Hi @nat – it does seem the plugin could use some fine tuning:

> [@ToddZ](#):
>
> I’m guessing I can turn off all email settings for _staff\_alias_, and emails will still be triggered and sent to the “parent” staff account…?
> 
> (…)
> 
> Maybe it’s sensible to just disable personal messaging to _staff\_alias_ ?

a.) I’ve tried turning off email for _staff\_alias_, and it becomes a bit of a black hole. Emails & notifications to the “parent” account are not triggered. So I’ll re-enable email & ignore the skipped email notices for now.

b.) Disabling personal messaging to _staff\_alias_ doesn’t keep privileged accounts like admins and mods from messaging it – and those Messages are only seen if dug for. Maybe those could also be routed to the relevant “parent” account?

These things aren’t a huge concern for me yet, but I can imagine issues for sites with more staff and heavier activity. I’ll watch for any news… thanks!

---

<div class="post-metadata">

### Author: ![ToddZ](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/toddz/32/328350_2.png) [@ToddZ](https://meta.discourse.org/u/ToddZ)
#### Post date: [August 31, 2024, 5:21pm UTC](https://meta.discourse.org/t/discourse-staff-alias/156202/38 "2024-08-31T17:21:08Z")

</div>

I just ran into this issue myself. Looks like that PR is still awaiting a review…

[Next page](https://meta.discourse.org/t/discourse-staff-alias/156202.md?page=2)
