Support access
client.support, the Support namespace, lets an Owner give a customer operator access to the tenant for a bounded window. Use it for troubleshooting that needs a person on the Seald Healthcare side to see what the tenant’s people see. Every operator entry and view under a grant is an access event that the tenant’s Owners can see. A grant hides nothing that an operator looked at.
The calls
The samples use the allowed helper from Access decisions.
const grants = await client.support.grants();// [{ grantId, reason, from, until, grantedBy, endedAt, uses }, ...]
// the caller holds the Owner role and has a fresh multi-factor sign-inconst grant = await allowed( await client.support.grant({ reason: 'Investigate slow search on the imaging dataset', until: sevenDaysFromNow }),);
await allowed(await client.support.end(grant!.grantId));let grants = try await client.support.grants()
let grant = try await allowed(client.support.grant(reason: "Investigate slow search on the imaging dataset", until: sevenDaysFromNow))
_ = try await allowed(client.support.end(grant!.grantId))val grants = client.support.grants()
val grant = allowed(client.support.grant(reason = "Investigate slow search on the imaging dataset", until = sevenDaysFromNow))
allowed(client.support.end(grant!!.grantId))Each SupportGrant carries:
reasonfromanduntil: the window it runsgrantedByendedAt: set once the grant has endeduses: the number of access events it has produced so far
What the SDK does for you
- Refuses
grantunless the caller’s multi-factor sign-in is fresh anduntilis at most seven days away. - Ends every operator session in the tenant at once when you call
end, even before theuntiltime. - Records every operator action under a grant as its own access event, tagged with the grant.
usesand the tenant’s audit trail always agree.
Decisions and errors you may see
Outcome or ErrorCode | When | What to do |
|---|---|---|
deny on grant | The caller does not hold the Owner role, or asked for more than seven days. | Ask an Owner, or shorten the window and try again. |
challenge on grant | The caller’s multi-factor sign-in is no longer fresh. | Call stepUp(), or use the allowed helper. |
deny on end | The caller does not hold the Owner role. | Ask an Owner to end the grant. |