Start here. This is the direct spoken answer to practice first.
Why this question matters
Support impersonation can solve real support problems, but it is a high-trust feature. The design needs strict boundaries so helpful access does not become invisible privileged access.
I would create a separate impersonation session rather than changing the support user's identity silently. The session records support actor, target user, account scope, reason, start time, expiry, and allowed capabilities. Every request made during impersonation carries both identities: the real actor and the effective user. The UI should show a visible impersonation banner and provide a clear exit.