Impersonation and transfer, with rails.
Impersonation and transfer (adopt) — the highest-trust administrative actions — with the guardrails that keep them accountable.
1. The most dangerous capabilities
Impersonation (acting as another user to support or investigate) and transfer or “adopt” (moving ownership of an entity) are powerful and necessary — and precisely the capabilities that do the most damage if abused or hijacked. They cannot simply be forbidden, so they must be tightly constrained, fully attributed, and never silent.
2. Guardrails that make power accountable
Done right, these actions are gated by elevated authorization, bounded in scope and time, and logged in a way that always preserves the real actor behind the impersonated identity. The audit trail must answer “who, acting as whom, did what” — so impersonation supports the user without becoming an untraceable master key.
3. How B5 Secure handles it
B5 Secure provides impersonation and transfer with the right guardrails — elevated authorization, scope limits, and auditable attribution — running through the same pipeline and suspension controls as everything else. The most trusted actions remain the most watched.