📚ApexMentum Help
Sign in →

Letting support access your account

How the ApexMentum support team can sign in to your account to help — and how you control it.

Letting support access your account

When you reach out to support with a tricky problem, we sometimes need to see what you see — to reproduce a bug, walk you through a setup step, or fix a corrupted record. We've built support access carefully so we can help you fast without compromising your patient data.

The default: support cannot sign in

By default, the ApexMentum support team cannot sign in to your clinic. Even our platform engineers don't have backdoor access to patient charts. We only see your account if you explicitly grant access.

How to grant access

When support asks for access (or proactively, before opening a ticket):

  1. From your account menu in the top-right, open Account settings → Support access.
  2. Toggle Allow support access for 24 hours.
  3. (Optional) Add a short note describing what we should look at.

The toggle expires automatically after 24 hours. You can shorten the window or revoke it instantly at any time from the same page.

What support can do while access is granted

  • Sign in to your clinic as if they were a clinic admin
  • View patient records, settings, billing, financial data
  • Reproduce the issue you're reporting
  • Make fixes you've explicitly asked for

Every action a support agent takes is logged in your Audit Log — including the timestamp, the action, and the agent's identifier — so you can review exactly what they did.

What support cannot do while access is granted

  • Access another clinic's data
  • Change your password
  • Disable your 2FA without going through you
  • Delete patients (deletion always requires explicit clinic admin confirmation)

The "break glass" scenario

For genuine emergencies — for example, your account is locked out and you can't grant access — support can use a documented break-glass procedure to access your account without your toggle. This requires:

  • A verified support-team admin
  • A documented reason
  • Real-time alerting to multiple stakeholders (including a Telegram notification to our security team)

Break-glass access is rare. When it happens, you'll see a prominent banner in your account the next time you sign in, with full details of what happened and why.

Reviewing support access history

From Audit Log → Filter: Support access, you can see every time support signed in to your account:

  • Which agent
  • What time
  • How long the session lasted
  • What actions they took
  • Whether you granted it or it was break-glass

When you might want to grant access

  • A bug we can only reproduce with your data
  • A migration step (especially if you're importing from another EHR)
  • Account recovery after a lost-credentials situation
  • Custom setup that needs a configuration our admin tools support but the regular UI doesn't expose yet

When you should NOT grant access

  • Someone claiming to be from support contacts you out of the blue and asks for it. We won't ever cold-ask for access. If you're not sure, email support@apexmentum.com and verify through the email channel before granting.
Was this article helpful?
See something wrong? Edit this article on GitHub