import { Aside, Steps } from '@astrojs/starlight/components';

Staff access controls whether Checktiv staff can open your workspace and see the console the way your team sees it. The setting belongs to the organization, so one answer covers every member.

Staff access is **on** until someone turns it off. An organization that has never answered the question is treated as allowing it, and the switch described below shows that as the current position, so the first time you open the card you will find it already on. Turning it off is what records your decision to refuse.

## Why support may ask for it

Some questions cannot be answered from the outside. A workflow template that behaves differently than you expect, an applicant who stops part way through a verification, or a setting that is not where you expect it to be: in each case the fastest answer comes from looking at the same screens you see, against your own data.

With staff access off, our team works only from what you describe. Expect more back and forth on those requests, and expect a small number that cannot be resolved at all.

## Turn staff access on or off

You must be an organization **Owner** or **Admin**.

<Steps>

1. Open **Settings → Organization**.
2. Go to the **Staff access** card.
3. Set **Allow access to Checktiv staff** on or off. The card states what the position you picked means before you save it.
4. Select **Save staff access setting**.

</Steps>

The new setting applies immediately. It also applies to a staff session that was approved but not opened: with staff access off, that session can no longer be opened.

Members with any other role see this card and the links on it, but not the current position, and they cannot change the setting. Ask an Owner or an Admin.

A staff session is read-only, so nothing can be changed from inside one, and this setting is no exception: a staff member cannot turn staff access back on while acting as you. If you open the card during a staff session, end the session from the banner first. See [What staff can and cannot do](#what-staff-can-and-cannot-do).

<Aside type="note">
  Turning staff access off does not close a staff session that is already open. To close one
  immediately, use **End session** in the banner. See [While a staff session is
  active](#while-a-staff-session-is-active).
</Aside>

## While a staff session is active

Every console page shows a banner at the top. The banner names the staff member, says when the session started, and shows how much time is left. It stays in step across every browser tab you have open.

The banner gives you two controls:

- **Learn more** opens your [Staff actions](/guides/activity/staff-actions) page.
- **End session** closes the session immediately. You do not have to give a reason, and you do not have to contact us first.

Staff sessions are time-boxed. A session you do not end closes by itself when its time runs out.

## What staff can and cannot do

A staff session is read-only. The staff member can look at your workspace, but the platform blocks every action that would change your saved data. That includes edits to workflow templates, reviewer decisions on an applicant, changes to API keys, webhooks, billing, branding, or your organization settings, and any request to erase or purge your data. A blocked attempt is recorded in the same way as any other action.

A staff member can move their own view between test data and live data during a session. That choice applies to their view only. It never changes the mode your own account is set to.

Staff access decides one thing: whether your workspace can be opened at all. Other staff actions, such as reading an applicant's personal data, carry their own approvals and are described on the [Staff actions](/guides/activity/staff-actions) page. Turning staff access off does not replace those separate controls, and it does not stop us from operating the platform itself.

## What is recorded

- The start and the end of every staff session appear on your **Staff actions** page, which every member of the organization can open.
- By default, the person whose account is used also gets an email when a session starts.
- Turning staff access on or off is recorded in your [audit log](/guides/activity/activity-log).
- What a staff member looks at inside your workspace is recorded in our internal audit log. Those reads are not listed row by row on your Staff actions page.

If you see a staff session you do not recognize, end it from the banner, then copy the timestamp from your Staff actions page and open a support request. See [Raising a concern](/guides/activity/staff-actions#raising-a-concern).

## Related

- [Staff actions](/guides/activity/staff-actions): the log of what our staff did, and the approvals behind it.
- [Manage access](/guides/organizations/manage-access): the roles, and which of them can change this setting.
- [Compliance settings](/guides/organizations/compliance): data residency and sub-processors.