Understanding the Token Issued Audit Event

Understanding the Token Issued Audit Event explains the current QCUI 1.0.03 behavior and how it affects a Super User who needs to inspect the Joomla frontend as an eligible user.

Recorded event

QCUI writes issued when a valid one-time handoff was created after target validation. The row includes administrator/target IDs when known, UTC time, source IP, browser user-agent, and a short details message.

How to interpret it

An issued row proves QCUI accepted the issuer/target at start time and created a handoff; it does not prove the frontend later consumed that token.

Current UI boundary

There is no built-in audit viewer; if you need to inspect issuance evidence, protect direct database/export access because rows contain user IDs, IP and browser data.

Privacy boundary

For Understanding the Token Issued Audit Event, QCUI’s audit/session evidence should be handled as support/security data. Store or share only what your organization actually needs, keep raw handoff secrets out of tickets, and avoid copying unrelated customer information simply because the impersonated account can display it.


Community Discussion

Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.