Skip to main content
WORKING FOR CLIENTS

Their workspace, your hands, no shared password.

Click View as client and the full Actionist interface loads, scoped to one client’s workspace. You see what they see, within the permissions they granted. No second login, no credentials handed over, no screenshare.

The mechanism

What a delegated session is.

It is not an impersonation of the client’s account and it is not a copy of their data. It is a short-lived, scoped credential that travels with every request you make while the session is open.

You click View as clientActionist asks the server for a session against that one client relationship.
Scopes are resolvedThe server reads the client’s current grants and stamps them onto the session.
Your cache is clearedAnything held from your own workspace is dropped so the two never mix.
You land somewhere usefulThe app opens the first area your scopes actually unlock, never a locked page.
One hour, then it stops. Sessions are deliberately short-lived. When one lapses you simply start another.
Scoped at the source. Permissions are resolved when the session is created and enforced on the server, not hidden in the interface.
Everything is recorded. Each action taken in a delegated session writes an audit row on the server.
Your own account never changes. You stay signed in as yourself the entire time, which is exactly why a bug report filed during a session goes to your account rather than the client’s.
Try it

Reading the Reseller mode banner.

A purple stripe sits at the top of the screen the whole time a session is open. It is your one reliable answer to “whose workspace am I in?”. Toggle the permissions below to see how it changes.

Toggle granted permissions to update the banner
Currently managingHalo StudioReseller mode
Permissions:PromptsToolsSkillsMemoriesFilesCalendarChat HistoryBilling
Exit to Reseller Dashboard ESC
The standard Actionist interface loads here, scoped to Halo Studio’s workspace. Anything the banner does not list is locked.
Credentials & API keys
Never listed, whatever else is granted
HARD LIMIT

The banner uses short labels. Prompts is Prompts and Instructions, Tools is Apps and MCP, Memories is Agent Memories, and Calendar is Calendar and Schedules. The locked-panel messages you meet inside the workspace use the longer names, so do not be thrown by the difference.

Step by step

Opening a client workspace.

Find the client

Go to Clients in the reseller sub-navigation, or use the Most recent clients panel on Overview. Search needs at least three characters. See Managing clients.

Check the button is live

View as client is active only when the relationship allows management. A client can show as Active and still not be manageable while their workspace is finishing setup. Hover a greyed-out button to see the reason.

Click View as client

The button shows a spinner while the session is created. Your own cached workspace data is cleared at this point, deliberately.

Land and check the banner

You arrive at the first area your permissions unlock. Read the Permissions list in the banner before you start work so you know what is available.

Do the work

Use the app normally. Anything the client did not grant shows a lock rather than failing silently.

Exit properly

Click Exit to Reseller Dashboard or press Escape. This is not optional housekeeping, see below.
If session creation fails you get a toast reading “Client manager is currently unavailable. Please try again.” Retry once. If it keeps failing on the same client, check they are not in the Historical filter, which would mean the relationship has ended.

Nice touch

You never land on a locked page.

Rather than dropping you on Home and letting you discover it is locked, the app walks the navigation in order and opens the first area your permissions actually unlock.

That last row is a useful diagnostic. If a session drops you straight into Marketplace, the client has not granted anything that opens a workspace area yet. Ask them to check their Manage Reseller panel.
Inside the workspace

Locks you will meet, and what they mean.

A locked area shows a shield and two lines: “Access restricted”, then “The client hasn’t granted access to permission in this delegated session.” Two areas use a different message because no permission unlocks them at all.

Unlocked by a permission
Home, Agents, Onboarding and Impact open with Prompts and Instructions.
Apps opens with either Apps and MCP or Skills.
Calendar, Memory, Files and Skills each open with their matching permission.
Settings opens with Billing summary.
Marketplace, Learn and Support are always open. Browsing needs no permission.
Locked no matter what
The Reseller section. You cannot manage your own reseller account from inside a client workspace.
Projects, the planning surface, which has no delegated permission defined yet.
The Credentials Vault panel in Settings, which does not render at all during a delegated session.
Every app Connect, Reconnect, Install and Disconnect control, regardless of permissions.
Those last two are worth internalising early. The Credentials Vault is absent rather than disabled, and app connection controls are locked for every delegated session with no permission that changes it. See Credentials and API keys and Apps, tools and integrations.
Deeper than the interface

The agent inherits your permissions too.

Permissions do not stop at the buttons. If you ask a client’s agent to do something during a delegated session, the agent’s own toolset is filtered by the same scopes.

When an agent hits one of these it says so rather than failing quietly: “Permission denied: reseller delegated session does not include permission access.” If you see that mid-conversation, the fix is a permission, not a prompt.

Terminal access is the one case that needs two permissions at once. An agent can only run terminal commands when both Files and Apps and MCP are granted.
The clock

One hour, and a refresh button.

Refresh permissions

The circular arrow in the banner picks up the client’s current grants without losing your place. Use it right after asking a client to enable something. It shows a spinner, then a tick for a couple of seconds.If it fails it does so quietly and the banner simply stays as it was. Click it again. If it never confirms, see Troubleshooting.

Expiry

A session lasts about an hour. When it lapses, the next request you make ends the session and returns you to your own reseller dashboard.This happens without a message. If you are suddenly looking at your own dashboard mid-task, that is almost always what happened. Start a new session and carry on.
Because expiry is silent, save or apply work as you go rather than leaving a long edit half-finished. A long unsaved edit is the one thing an expiry can actually cost you.

A revoked permission behaves differently and more gently. It locks the affected area and leaves the rest of your session running, because losing one permission is not a reason to throw away the whole session.

Do this properly

Always exit with the button or Escape.

Exiting is what clears the client’s data out of your app. Navigating away, closing a tab or switching windows does not.

You exitClick Exit to Reseller Dashboard, or press Escape from anywhere.
Session endsThe delegated credential is deleted on the server.
Cache is clearedEverything loaded from that client’s workspace is dropped.
Back to your dashboardYou return to your own reseller view, ready for the next client.
This is the habit that keeps clients separate. Exit one client fully before opening the next, and you will never wonder whose workspace a stale panel belongs to.
In practice

How agencies actually use sessions.

Agency owner
New client accepted. Opens a delegated session, drops in three starter agents, wires the tools that need no login, writes the instructions, then sends one message listing the four apps the client has to connect themselves.
live in an afternoon
Support engineer
Client reports an agent misbehaving. Opens View as client, reads the run history, corrects the instructions, and replies with what changed. No screenshare, no request for screenshots.
usually under 15 min
Account manager
Monthly review. Opens each client in turn, checks what the agents actually did, adjusts a schedule or two, and exits properly between clients so nothing carries over.
one pass, no mix-ups
Quick reference

States and controls.


Delegated sessions

Real access without a shared login.

One click into a client workspace, one hour of scoped access, and one key that never leaves their vault.

Scoped when the session starts, enforced on the server, audited on every action.
One hour per session · Exit clears everything · Credentials never included.

Keep going

Next steps.

Client permissions and access

The eight toggles behind every lock you will meet, and what each one opens.

Agents, prompts and instructions

The work you will do most often once you are inside a client workspace.

Apps, tools and integrations

What you can configure, and the connection step that always belongs to the client.

Troubleshooting

Every message you can hit in a session, what it means, and whose problem it is.