Impersonate the tenant's earliest user
Requires onboarding_admin + CSRF. Returns 409 if the tenant is not lifecycle_state == "live", and 409 if the tenant has no active tenant user to impersonate. Mints a real cl_tenant_session for the tenant’s earliest-created active user — a genuine access grant into customer data, not a read-only preview — and unconditionally writes a control.audit_log row (employee_impersonation) recording the impersonating employee and the impersonated user’s email. Sets both cl_tenant_session and a fresh cl_csrf cookie on the response, distinct from the caller’s own staff CSRF cookie.
Path Parameters
Response
Successful Response
The response is of type Response Impersonate Admin Tenants Tenant Id Impersonate Post · object.