Ethics & Impersonation: Alternatives?
impersonation
Solution
The best solution is Michael's above (have a way to dump/report the settings for the user)
Another great solution is ablity to CLONE settings of an account into a brand new account. Then you can experiment on clone.
Alternately, make sure that the user is actively aware that you have such impersonation capability, signs off on being OK with it, AND signs off explicitly on every usage of it,
Problem
Have you ever troubleshoot for your customer and ask (or really want to) their credentials to check their settings if the fault is there? Our solution to this is to implement impersonation feature to login as any users and have access to everything users do. In this case, a mail application. Although we don't need the password to impersonate, I however feel concerned about user's privacy. Mainly 2 things: Their mails and POP3/IMAP settings (which impersonator can get user's gmail/yahoo/etc user and password. What are other good alternatives/suggestions around this? Some suggested logs. Of course, it's essential component but you can't possibly log everything. Especially because there are so many things to log already not related to user's settings.