Impersonation and audit
When someone acts on a loan officer’s behalf, they declare how they are acting, state a real reason, and every action is recorded under their own name, not the loan officer’s. A short blocklist protects money, identity, and the voice clone even then.
What it is
In the mortgage industry, loan officers routinely ask their marketing team to work on their behalf: run their social calendar, update their bio, produce their content, keep their site current. That is the normal way lenders operate, not a workaround.
TrueTone supports it directly through a feature often called “acting on behalf.” A person with the right permission can step into a loan officer’s account and work as them. The difference is that TrueTone treats that as a deliberate, recorded act rather than a free-for-all.
The idea underneath it is simple. Delegation is legitimate. Forgery is not. Marketing posting on a loan officer’s behalf is normal and expected. A record that claims the loan officer posted it, when marketing did, is not. Those two things are the same action, and only the record tells them apart. So the whole feature exists to keep the record honest.
The gap it closed
Earlier, stepping into an account was effectively unbounded and recorded almost nothing. For a company whose enterprise promise is governed content, that is the worst kind of gap. A trail that can be made to attest to things that never happened is more dangerous than no trail at all, because people believe it. That is fixed. The trail is now complete and it names the person who actually acted.
Who it is for
- Org admins, acting for the loan officers inside their own organization. This is the marketing lead running an account on a loan officer’s behalf.
- TrueTone staff, supporting customers across organizations when something needs a closer look.
How it works
Four rules work together every time someone acts on a loan officer’s behalf. The first two set the terms before any work happens. The last two govern what is recorded and what stays off-limits once it does.
The mode is declared up front
When someone opens an account, they choose how they are entering it:
- View only lets them see exactly what the loan officer sees and change nothing.
- Act on behalf lets them make changes.
Acting as someone is a choice made on the way in, never an accident of being in the session. Support diagnosing an empty seed list opens View only and cannot nudge anything onto a live site. Marketing running a social calendar opens Act on behalf and works normally.
The reason has to be real
A purpose is required, and there is no canned default to fall back on. A reason that every session gives, like “troubleshooting,” is not a reason. The purpose is written fresh for the session it belongs to.
Every action is attributed to the real person
Each action taken while acting on behalf is recorded under the acting person’s own name, together with whose account it touched, when, and why. The record reads like marketing@lender.com, acting as jane@lender.com, on July 14, because: publishing the Q3 rate-drop campaign. It never reads simply “Jane.”
The blocklist holds
A few things are off-limits even in Act on behalf mode, described below.
What can never be done through someone else’s account
These are not blocked because delegation is suspect. They are blocked because they have no legitimate on-behalf story and their failure mode cannot be undone after the fact.
| Blocked area | What it covers | Why it is off-limits |
|---|---|---|
| Money | Invoice top-ups, the billing portal, buying credit packs, and subscription changes | An admin can already do these as themselves. Routing spend through a borrowed identity adds nothing and creates a charge attributed to someone who never authorized it |
| Identity and security | Passwords, multi-factor settings, roles, user management, and platform administration | Altering an account while wearing its owner’s identity is a takeover, and no later log entry undoes it |
| The voice clone | Re-recording, retraining, retuning, or deleting the loan officer’s cloned voice | The voice may be used to make an audiogram or a video voiceover, because that is the job. It may not be altered. A loan officer should never discover that someone else re-cut the voice that speaks in their name |
There is no elevated mode that lifts the blocklist. It holds in every mode, for staff and org admins alike.
The voice line is worth pausing on. A loan officer’s cloned voice is closer to their identity than a password is, so the rule is deliberate: acting on behalf may generate audio, audiograms, and video voiceover with the voice, but only the loan officer may create, re-record, retrain, retune, or delete it.
Why it matters for enterprise
The enterprise promise is governed content, and this is what “governed” means at the operational level. The customer’s marketing team gets the real workflow it needs, acting for its loan officers day to day. The compliance side gets a record that is trustworthy about who actually did what. That includes one guarantee that carries real weight: the trail cannot be used to forge a loan officer’s own compliance sign-off, because it always names the person who acted.
Good to know
The doctrine, stated plainly. Org admins act only within their own organization. TrueTone staff can act across organizations to support customers. No one impersonates another staff member. This hierarchy is fixed.
- The record survives the person. If a user is later deleted, the audit trail of what was done on their behalf carries its own record of who was involved and remains intact. Deleting an account does not erase its history.
- Refusals are recorded too. When the blocklist stops an action, that attempt is part of the trail, because what someone tried to do is exactly the kind of thing an audit needs to show.
- Tenant data stays isolated. Acting on behalf never reaches across into another organization’s data. Isolation between customers is enforced and audited, independent of who is acting.
The audit record is maintained continuously today. Your TrueTone contact can pull the trail for your organization on request, and a self-serve view for org admins to review it directly is planned.