> ## Documentation Index
> Fetch the complete documentation index at: https://docs.imaracare.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How support accesses your account

> What ImaraCare support staff can see, what they can never see, and how every support action is logged.

ImaraCare has a small internal support team that helps facilities with
technical and account issues. This page explains exactly what that team can
and cannot do.

## Who is on the support team

Support staff are ImaraCare employees or contractors with individual accounts
on our internal Support Portal. There are two roles:

* **Support Agent** — handles tickets, account lookups, and subscription help
* **Support Admin** — additionally manages the support team itself, email
  templates, and compliance operations

Every support account requires multi-factor authentication, is reviewed
quarterly, and is deactivated with full session revocation the moment a team
member leaves.

## What support staff can see

To resolve tickets, support staff can look up:

* Your facility's account record (name, license number, subscription status)
* Which users belong to your facility and their roles
* Support tickets you have filed and their conversation history
* Delivery status of system emails sent to you

## What support staff can never see

* **Passwords** — stored hashed; support will never ask for your password
* **MFA codes** — never ask anyone for a code; we will never request one
* **Resident records in bulk** — support tools do not include a browse of
  clinical data; troubleshooting access to specific records happens only with
  your facility's involvement and is logged
* **Payment card numbers or bank details** — handled by Stripe; we never see
  or store full numbers

<Warning>
  ImaraCare support will **never** email or call you asking for your password,
  MFA code, or API keys. If you receive such a request, do not respond — report
  it to [support@imaracare.com](mailto:support@imaracare.com) immediately.
</Warning>

## Every action is logged

All support-portal activity is written to a tamper-evident audit log
(SHA-256 hash-chained, verified daily). Role changes on the support team,
report exports, and access to compliance evidence each produce audit records
that are reviewed on a schedule.

## Questions about a support interaction

If something about a support interaction seems off — an unexpected change, an
email you don't recognize — contact [support@imaracare.com](mailto:support@imaracare.com)
with the ticket number. Facility Administrators can also review account
activity under **Settings → Activity Logs**.
