Skip to content

Support access to your data

A support agent can only see your data through a time-boxed, read-only session that you approve — and every view is audited.

Most software support can read your account whenever it likes. Earmarkr doesn't work that way.

A support agent can only view your data through a session that is:

  • Requested explicitly, with a stated reason
  • Approved by you, from your profile
  • Read-only — nothing can be changed on your behalf
  • Time-boxed — it expires on its own
  • Audited — every view is recorded
  • Revocable — you can end it at any time

Manage it under Support access on your profile.

Approving a request

When an agent requests access, a card appears on your profile showing who asked and why. Choose Approve or Deny.

Denying is always fine. It may mean slower help on a problem that needs seeing your data, but you're never obliged, and you'll never be pressured to approve.

Revoking

Active sessions are listed with their expiry. Revoke ends one immediately.

You don't need to wait for a reason. If a session is open and you'd rather it wasn't, close it — sessions expire on their own anyway, so revoking early costs nothing.

Break-glass access

There's one exception: a genuine emergency — active data loss, a security incident — can be flagged as break-glass and proceed without waiting for approval.

It is not a quiet back door:

  • It's logged as break-glass, distinctly from a consented session.
  • It's still read-only and still time-boxed.
  • It appears in your support access list, so you can see it happened.
  • You can revoke it like any other session.

It exists so nobody has to wait for an offline customer while their data is actively at risk. It's visible after the fact by design.

What agents can never do

Even with an approved session, support cannot:

  • Change your budget, transactions, or accounts
  • Move money or touch your bank connections
  • See your password (stored hashed — nobody can read it)
  • See your two-factor secret or your bank credentials
  • Access your data after the session expires

The audit log

Every support view is written to an append-only audit log, along with your own sensitive account actions. It can't be edited or deleted, including by us.

If you want to know what was accessed and when, contact support and ask.