447: How to (not) implement impersonation
Episode
37 min
Read time
2 min
Topics
Design & UX, Software Development, Psychology & Behavior
AI-Generated Summary
Key Takeaways
- ✓Impersonation as symptom: Requests for impersonation features often signal inadequate admin tooling. Instead of allowing admins to hijack user sessions, build dedicated admin interfaces where support staff can modify customer settings directly without identity switching.
- ✓Decouple from current_user: Design resources to accept user parameters rather than relying on global current_user state. Build standard resourceful routes with IDs, then layer vanity URLs as aliases. This enables admins to view any user's dashboard through authorization policies without impersonation.
- ✓Audit trail corruption: True impersonation breaks observability and analytics. When admins become users, exception logs lose context about who triggered errors, audit trails misattribute actions, and security teams cannot track admin behavior. Maintain admin identity while rendering user-specific views instead.
- ✓Authorization over identity switching: Implement view-as functionality that preserves admin identity while displaying user perspectives. This approach maintains proper logging, enables differentiated permission sets between admins and users, and prevents security vulnerabilities from session hijacking without sacrificing debugging capabilities.
What It Covers
Stephanie and Joelle examine impersonation features in web applications, exploring why developers should question implementation requests, consider security implications, and design admin tooling that solves core problems without hijacking user identities.
Key Questions Answered
- •Impersonation as symptom: Requests for impersonation features often signal inadequate admin tooling. Instead of allowing admins to hijack user sessions, build dedicated admin interfaces where support staff can modify customer settings directly without identity switching.
- •Decouple from current_user: Design resources to accept user parameters rather than relying on global current_user state. Build standard resourceful routes with IDs, then layer vanity URLs as aliases. This enables admins to view any user's dashboard through authorization policies without impersonation.
- •Audit trail corruption: True impersonation breaks observability and analytics. When admins become users, exception logs lose context about who triggered errors, audit trails misattribute actions, and security teams cannot track admin behavior. Maintain admin identity while rendering user-specific views instead.
- •Authorization over identity switching: Implement view-as functionality that preserves admin identity while displaying user perspectives. This approach maintains proper logging, enables differentiated permission sets between admins and users, and prevents security vulnerabilities from session hijacking without sacrificing debugging capabilities.
Notable Moment
One developer described receiving confusing exception notifications from inactive accounts, only to discover admins impersonating users triggered the errors. Without knowing which admin caused the issue, the team could neither help nor fix the underlying problem.
Episode Transcript
This episode is brought to you by WorkOS. If you're building a b two b ass app, at some point, your customers will start asking for enterprise features like single sign on, skim, provisioning, role based access control, and audit trails. That's where WorkOS comes in. With ease to use and flexible APIs that help you ship enterprise features on day one without slowing down your core product development. Today, some of the hottest startups in the world are already powered by WorkOS, including ones you probably know, like Perplexity, Vercel, Jasper, and Webflow. WorkOS also provides a generous free tier of up to 1,000,000 monthly active users for its user management solution, making it the perfect authentication and authorization solution for growing companies. It comes standard with rich features like social logins, bot protection, MFA, roles and permissions, and more. If you're currently looking to build SSO for your first enterprise customer, you should consider using WorkOS. Integrate in minutes and start shipping enterprise plans today. Check it all out at workos.com. That's workos.com. Hello, and welcome to another episode of the Bike Shed, a weekly podcast from your friends at Thoughtbot about developing great software. I'm Joelle Kinville. And I'm Stephanie Minh. And together, we're here to share a bit of what we've learned along the way. So, Stephanie, what's new in your world? So I have a new little software productivity, quality of life thing to share, which is Notion calendar for managing multiple calendars. Specifically, I oftentimes have like a client calendar on a client Google account, for example, in addition to my thoughtbot calendar. And it has been such a pain to negotiate having both calendars and forgetting to block stuff off on each of them, and then getting calendar invitations for meetings during times that don't actually work for me. But other people didn't know that because I failed to do the tedium of syncing both of them. So I finally did something nice for myself, and I'm trying out Notion calendar, which I had heard is very useful for managing multiple calendars. Specifically, it has a really great auto block function where you can choose either, like, events in a series or just your entire calendar, and and it will automatically block that time off across multiple calendars for you. So I'm really happy that I finally got that installed. Actually, not even installed. I mostly just use the web version of it. And I also wanted to add that you don't really even need to be a Notion user to use Notion calendar. It's like a whole separate little product. Because you don't use Notion as your main note taking platform. Yeah, that's right. I have heard that it does play well with if you do use Notion, those things integrate pretty nicely. But I've been very happy just using it separately. And it has pretty much replaced my Google Calendar tab on my browser. It even lets you see your teammates' …
Get the full transcript (6,274 words) + summary by email — free
One-time email with the complete transcript and AI summary of this episode. No account needed.
One email, no spam. We’ll also show you what SignalCast does.
You just read a 3-minute summary of a 34-minute episode.
Get The Bike Shed summarized like this every Monday — plus up to 2 more podcasts, free.
Pick Your Podcasts — FreeKeep Reading
More from The Bike Shed
We summarize every new episode. Want them in your inbox?
Similar Episodes
Related episodes from other podcasts
The Ezra Klein Show
Feb 10
George Saunders on Anger, Ambition and Sin
The Changelog
Jan 30
Natural born SaaS killers (Friends)
The Intelligence (Economist)
Jan 30
Democracy on ICE? The mood turns in America
We Study Billionaires
Dec 19
TIP777: The 1999 Dot-Com Bubble w/ Clay Finck
The Jordan Harbinger Show
Nov 30
1249: Rehab and Recovery | Skeptical Sunday
Explore Related Topics
This podcast is featured in Best Cybersecurity Podcasts (2026) — ranked and reviewed with AI summaries.
Read this week's Software Engineering Podcast Insights — cross-podcast analysis updated weekly.
You're clearly into The Bike Shed.
Every Monday, we deliver AI summaries of the latest episodes from The Bike Shed and 192+ other podcasts. Free for one show.
Start My Monday DigestNo credit card · Unsubscribe anytime