Impersonation Request Workflow
Impersonation allows authorized users to access a NiCE CXone tenant
High-level organizational grouping used to manage technical support, billing, and global settings for your NiCE CXone system. to help with troubleshooting, support, or configuration.
This request-based impersonation model has three steps: the Tenant Management (TM) Admin submits a request, a business unit
High-level organizational grouping used to manage technical support, billing, and global settings for your NiCE CXone system. administrator reviews and grants or rejects this request, and access is only available once approved.
This restricts access to tenants to pre-approved administrators only. The audit trail is visible to Tenant Management (TM) admins.
Roles and Permissions
Required role: TM Admin or Implementation Partner TM Admin
These roles should come with the following permissions: Create, View, Edit, Respond.
Roles are granted by a Business or Master Admin. The Admin turns on the required permissions for a role, and assigns that role to users who need to send or approve impersonation requests.
This is done In Security Settings>Roles & Permissions.
To create a new impersonation request, a user needs the Create permission for Role Impersonation. To later view or edit that request, they also need View and Edit permission.
On the receiving side, the user requires View to see the request and Respond to approve the request.
Workflow
Step 2: Managing received requests
Step 3: Perform the Impersonation
Step 1: Create a request
The Tenant Management (TM) Admin can create a request to impersonate a tenant on the Outbound Requests page. This only applies to tenants that are voluntarily participating in the new framework.
To create a request:
-
Log in to your Tenant Management (TM) account.
-
Ensure that the correct Roles and Permissions are toggled on.
-
Navigate to Admin>Employees>Security Settings>Outbound Requests.
-
Click Create new request.
There should only be one request associated with each role in order to minimize the number of requests that are made.
-
In the Basic Request Information tab:
-
In the Request Name field, fill in the name to help you identify the request. This name is not visible to the tenant admin who reviews the request. Use letters and numbers only, with no spaces.
-
(Optional) In the Request Role field, select Impersonation Role from the dropdown menu.
-
In the Impersonation Confirmation Message field, write a short message that will be received by the manager of the Business Unit (BU) which will receive the request. For example, I want to impersonate XXX business unit in order to provide support.
-
-
In the Tenant-User Associations tab, click New Association.
A Tenant-User Association connects the users who need access to the tenants they're allowed to access. You can create multiple associations within a single request to tie different users to different tenants.
-
In the Create / Edit Tenant-User Association window, open the Users tab and click Assign Employees.
-
The Add Users window opens.
-
From the list, select all users that you want to add to this association.
Only 100 users are displayed. Type the name, user name or email in the search box to find the user you want to add.
-
Click Add.
-
-
Open the Tenants tab and click Assign Tenants.
-
From the list, select all tenants that you want to add to this association.
Only 100 tenants are displayed. Type the tenant name in the search box to find the tenant you want to add.
-
Click Add.
-
- Click Save to save your Tenant-User Association.
- An automatic message is sent to each BU or tenant to request approval.
You can update a saved outbound request at any time. You can add or remove users or tenants to an existing association, create a new association, delete an association when access is no longer needed, and view the status and history of each outbound request.
To edit or view an existing request:
-
Navigate to Admin>Employees>Security Settings>Outbound Requests and select the request from the list.
-
In the Tenant Approval tab, you can see the status of each request (granted, pending, rejected). Click on a user name for more information.
-
Open the Change history tab to show who created the request and when.
-
If you are editing or updating a request or a tenant-user association, click Save when you are finished.
Step 2: Managing received requests
Received requests are managed by the business unit administrator. This administrator must have an Impersonation Management role that allows them to manage impersonation requests.
-
Log into your NiCE CXone account.
-
Navigate to Admin>Employees.
-
From the left menu under Security settings, select Incoming Requests.
-
The Manage Approvals window opens. This window shows a list of requests, one for each role. For each request, you can see the status Granted, Pending or Rejected. Click Manage to manage a request.
-
The Impersonation Request window opens.
-
Under Response, select Grant or Reject.
-
If you are granting the request, in the Expiration Date field, select a date when this impersonation will expire.
-
In the Response Message field, type a response (For example: Request granted.).
-
Click Grant or Request to update the status of the request.
For more information, see Manage Approvals.
Step 3: Perform the Impersonation
After you have created an outbound request, and this request has been granted by the Business Unit Admin, you can perform the impersonation.
Impersonation is performed by NiCE CXone Services and support personnel with the TM Admin permission.
To begin impersonation:
-
Navigate to My Zone>My Profile and open the Impersonation tab.
This tab shows a list of all tenants who you have the authority to impersonate. You can hover over the tenant to see the administrator in the Business Unit who granted you permission to do the impersonation.
If the permission has expired, you see the status Granted and the expiration date.
Rejected requests show on the list for historical data value only.
-
Select a tenant from the list.
-
Click Begin Impersonation.
-
A banner appears at the top of the screen showing the tenant name and a Stop control. You can now navigate and work within the impersonated tenant, including admin areas.
-
Your impersonation session refreshes automatically in the background, so you won't be logged out partway through if you're actively working in the tenant.
To stop impersonation:
-
Click Stop in the impersonation banner at the top of the screen.
-
You are returned to your own account.
-
If you log out instead of clicking Stop, your impersonation session ends immediately and you're redirected to the login page.