Declares a time-boxed, revocable authorisation for the PLATFORM_SUPER_ADMIN
role to impersonate this tenant. While the authorisation is live — and ONLY while it
is live — the standing SaaS refusal is lifted.
The window is fixed at declaration. Default 8 hours (one support
shift), hard ceiling 24. A request above the ceiling is refused with 400 and
no row is written; it is never silently reduced, because the governance value
of a declaration is that its stated terms are its terms.
At most one authorisation per tenant. A second declaration while
one is LIVE is refused 409 — an authorisation is never replaced, so a repeated request
cannot silently extend the window it was granted for. A LAPSED authorisation is
cleared and the declaration proceeds; refusing on a lapsed row would leave the tenant
with nothing to withdraw and no way to re-declare.
The reason is recorded for the tenant's own governance record. It is
never shown on the platform-wide list and never carried in an audit event.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||