Skip to content

Support access

client.support, the Support namespace, lets an Owner give a customer operator access to the tenant for a bounded window. Use it for troubleshooting that needs a person on the Seald Healthcare side to see what the tenant’s people see. Every operator entry and view under a grant is an access event that the tenant’s Owners can see. A grant hides nothing that an operator looked at.

The calls

The samples use the allowed helper from Access decisions.

const grants = await client.support.grants();
// [{ grantId, reason, from, until, grantedBy, endedAt, uses }, ...]
// the caller holds the Owner role and has a fresh multi-factor sign-in
const grant = await allowed(
await client.support.grant({ reason: 'Investigate slow search on the imaging dataset', until: sevenDaysFromNow }),
);
await allowed(await client.support.end(grant!.grantId));

Each SupportGrant carries:

  • reason
  • from and until: the window it runs
  • grantedBy
  • endedAt: set once the grant has ended
  • uses: the number of access events it has produced so far

What the SDK does for you

  • Refuses grant unless the caller’s multi-factor sign-in is fresh and until is at most seven days away.
  • Ends every operator session in the tenant at once when you call end, even before the until time.
  • Records every operator action under a grant as its own access event, tagged with the grant. uses and the tenant’s audit trail always agree.

Decisions and errors you may see

Outcome or ErrorCodeWhenWhat to do
deny on grantThe caller does not hold the Owner role, or asked for more than seven days.Ask an Owner, or shorten the window and try again.
challenge on grantThe caller’s multi-factor sign-in is no longer fresh.Call stepUp(), or use the allowed helper.
deny on endThe caller does not hold the Owner role.Ask an Owner to end the grant.

Next