# Look after customers in the staff console

> Find a customer, read their account, change their details, adjust credit and act on their behalf from the staff console.

Source: https://docs.coritan.com/organizations/staff-console/customers/

The Customers page of the staff console, `/staff/customers`, lists every account on your storefront, and each customer's page gathers their services, invoices, tickets, notes and history in one place. From there your team corrects an account, adds credit, helps the customer sign in, and opens a *support session* to see your storefront as the customer sees it.

## Before you begin

Any member can open the list and a customer's page. What else each task needs:

| Task | Lowest role | Step-up |
| --- | --- | --- |
| Add a note to the account | Tier 1 support | No |
| Correct the profile, resend the verification email, tag the account, create an account, end sessions, mute in chat, suspend orders in bulk | Tier 3 support | No |
| Read the timeline, emails, sessions, credit history and related accounts | Tier 3 support | No |
| Reset the customer's password | Tier 3 support | Yes |
| Open a read-only support session | Tier 3 support | No |
| Add or take away credit | Billing | Yes |
| See saved payment methods, and export the list | Billing | No |
| Change the currency, and mark an email verified | Admin | No |
| Change the account's status, reset its two-factor authentication, close it or export its data | Admin | Yes |
| Open a support session that can make changes | Admin | Yes |
| Terminate orders or ban accounts in bulk, or schedule a deletion | Admin | Yes |

A *step-up* is a fresh password or authenticator code, which lasts 10 minutes; [Sign in to the staff console](/organizations/staff-console/sign-in/#confirm-it-is-you) explains it.

## Find a customer

1. Open `/staff/customers`.
2. Search by email, first or last name, username, company or customer ID. A `*` matches anything, so `j*@example.com` finds every address at that domain that starts with j.
3. Narrow the list by status (`active`, `suspended`, `banned` or `closed`), to accounts that never verified their email, to sign-ups from the last 7 days, to paying or free customers, or to one of your tags.

Paying customers come first: those with at least one service that is not on your free tier. The counts above the list always cover the whole directory, so a search or a filter narrows only the list.

## Read a customer's account

The customer's page shows the account's status and the reason given for it, whether the email is verified, the credit balance, currency and country, when they last signed in, their sign-up IP address and social sign-ins, and your tags. It adds what they have paid and had refunded over the account's life, their first order, open payment disputes, and whether the account belongs to someone on your team. Below come their services, invoices, latest tickets and your team's notes.

More loads when you open it:

- The timeline: what your team did to the account and its services, sign-ins and support sessions, invoices raised and paid, credit and refunds, and tickets opened and closed, newest first.
- The emails your brand sent the customer, with whether each one was sent.
- Saved payment methods, as the customer sees them: a label, the card brand, the last four digits and the expiry.
- Sessions, credit history, and other accounts that share the sign-up IP address, the sign-up browser, the phone number or a recent session address. A shared address is a signal to weigh, since a household shares one too.

## Change a customer's details

- Correct the email, name, company or phone. A new email address is unverified until the customer confirms it: we send a verification link to the new address, and tell the old one about the change.
- Resend the verification email, or, as an admin, mark the email verified when the customer proved it another way.
- Tag the account for your team. An account takes up to 12 tags of up to 30 letters, digits, spaces, `-` and `_`, and the directory filters by them.
- Add a note for your team, up to 8,000 characters.

## Add or take away credit

1. On the customer's page, enter an amount and a description. A negative amount takes credit away.
2. Confirm it is you if the console asks.

The description appears in the customer's credit history, and the customer gets an email when you add credit. The balance cannot go below zero. Each member may change credit 30 times an hour.

## Help a customer sign in

- Reset their password: set a new one of at least 8 characters, with a lowercase letter, an uppercase letter, a digit and a special character. It ends every session the customer has, and we email them that your team changed it.
- As an admin, reset their two-factor authentication when they lost their phone. It removes the second factor and ends their sessions; they sign in with the password and, if your brand requires it, set it up again.
- End one of their sessions, or all of them. Each session shows its kind: a sign-in, an app they authorised, a support session or a team member's own account.

## See the storefront as the customer

A support session signs you in to your storefront as the customer, for 30 minutes, and cannot be extended. It opens only on an `active` account, and each member may open 20 an hour. Choose how far it may go:

- Read only: look without changing anything. Tier 3 support can open one without a step-up.
- Servers: also change the customer's servers and snapshots. It needs an admin and a step-up.
- Full: do anything the customer could, except change their password, email, sign-in methods or sessions, or close the account. It needs an admin, a step-up and a reason of a few words, which goes on the record.

Everything a session that can make changes does is recorded against you in the [audit log](/organizations/audit-log/), and the customer's own session list shows the support session.

## Suspend, ban or close an account

- As an admin, change the account's status to `suspended` or `banned`, with a reason, or back to `active`. Leaving `active` ends every session the customer has, cancels invitations they hold to share other customers' servers, and disconnects their open server consoles.
- As an admin, close the account for good. Closing anonymises it and cannot be undone. It needs a reason of 3–500 characters, and it is refused while the customer has active services or unpaid invoices.
- To act on many accounts at once, select up to 100 in the list and choose an action. Suspending their orders, or lifting that suspension, is Tier 3 work. Terminating their orders, banning the accounts, or suspending with a deletion date 1–90 days out needs an admin and a step-up. A ban also terminates everything the account runs.

Every bulk action but lifting a suspension opens one high-priority ticket per customer with a notice for them, keeps your reason as an internal note, and assigns the ticket to you. Turn that off if you will contact them another way.

## Export customers

- A billing member can download the list as CSV, filtered as it is on screen, up to 20,000 customers.
- For a privacy request, an admin can download everything held about one customer as a JSON file. It includes your team's notes and the internal notes on their tickets, so review it before you send it. Passwords, session tokens, two-factor secrets, payment tokens and the files on their servers are not in it.

Exports count towards a limit of 12 an hour for each member.

## Create a customer

Tier 3 support can create an account for someone who ordered by phone or email: enter the email and, if you like, a name, company, phone and currency. We email the customer a link to choose a password, so nobody on your team knows it. The account counts towards your organization's customer limit.

## Result

The customer's account shows your change at once, and every change is in the [audit log](/organizations/audit-log/) with who made it.

## Troubleshooting

`Customer limit reached (100/100)`
: Your organization holds as many customers as Coritan allows. [Contact support](https://www.coritan.com/dashboard/support) to raise the limit.

`A customer with that email already exists`
: Search for the address: the customer already has an account.

`Another customer already uses that email`
: The new email belongs to another account on your storefront. Emails are unique within an organization.

`Changing a customer's status or currency needs an org admin`
: Ask an owner or admin to make the change.

`Ending orders or accounts needs an org admin; support can suspend without a deletion date`
: Support can suspend orders in bulk only without a deletion date. Ask an admin to terminate, ban or schedule a deletion.

`Close the account through the close route; it also anonymises it`
: You tried to set the status to `closed`. Use the close action instead.

`A closed account cannot be reopened`
: A closed account is anonymised. The customer can register again.

Closing is refused with `active_services` or `unpaid_invoices`
: Cancel the customer's services, or settle or cancel their unpaid invoices, then close the account.

`This customer is suspended and cannot be impersonated.`
: Support sessions open only on active accounts. Reactivate the account first, or read it from the customer's page.

`Say why a full-access session is needed (at least a few words); it goes on the record.`
: A full-access session needs a reason of at least 5 characters.

`The wallet holds 5.0000; it cannot go below zero.`
: You tried to take away more credit than the customer has.

`A verification mail went out recently; try again in 45 seconds`
: We sent a verification email a short time ago. Wait the number of seconds it gives.

`Customer not found`
: No customer with that ID belongs to your organization.

## Related

- [Manage customers](/organizations/customers/) from the dashboard's **Customers** tab
- [Handle billing in the staff console](/organizations/staff-console/billing/)
- [Sign customers in to your storefront](/organizations/storefront/customer-sign-in/)

## With the API

These routes live under `https://api.coritan.com/api/v1/orgs/{org_slug}/staff/customers`, and take a console session or a member's access token as [The staff console](/organizations/staff-console/#with-the-api) explains. The reference lists them all under [Customers in the staff console](/api/reference/organizations/customers/staff/).

### List customers

```bash
curl "https://api.coritan.com/api/v1/orgs/acme/staff/customers?q=alex&status_filter=active&audience=paid&limit=50" \
  -H "Authorization: Bearer $STAFF_TOKEN"
```

`q` takes up to 200 characters, `tag` one tag, `limit` 1–200 (50 by default) and `offset`. `status_filter` is an account status, or `unverified`, `new_7d`, `paying` or `free`. The answer has `total`, the `customers` on this page, and `counts` for the whole directory: `all`, one per status and one per bucket. Each customer carries its `services_total`, `services_active`, `unpaid_invoices`, `open_tickets`, `tags` and `is_free`.

`GET /staff/customers/export.csv` takes the same filters. `GET /staff/customers/tags` lists every tag in use with its `count`.

### Read one customer

```bash
curl https://api.coritan.com/api/v1/orgs/acme/staff/customers/812 \
  -H "Authorization: Bearer $STAFF_TOKEN"
```

The answer has `customer`, with the account and its `lifetime_paid`, `lifetime_refunded`, `first_order_at`, `open_disputes` and `staff_member`, and up to 50 `services`, 50 `invoices`, 20 `tickets` and 50 `notes`. The rest of the account has its own routes:

| Route | What it answers |
| --- | --- |
| `GET /{customer_id}/activity` | The timeline in `events`, newest first. `limit` takes 1–300 and defaults to 100. |
| `GET /{customer_id}/emails` | The emails sent, each with `template_slug`, `subject`, `status`, `error` and `sent_at`. `limit` takes 1–200. |
| `GET /{customer_id}/payment-methods` | Saved payment methods, with `brand`, `last4`, the expiry and `expired`. |
| `GET /{customer_id}/sessions` | Live sessions, newest first and at most 50, each with its `kind`: `login`, `oauth`, `support` or `staff`. |
| `GET /{customer_id}/credit-ledger` | The `balance`, `currency` and credit `entries`, newest first. |
| `GET /{customer_id}/related` | Other accounts in `matches`, each with the `signals` that link it: `signup_ip`, `signup_fingerprint`, `phone` or `session_ip`. |
| `GET /{customer_id}/notes` | The notes, newest first. `POST` with `body` adds one and answers `201`. |

### Change the account

```bash
curl -X PATCH https://api.coritan.com/api/v1/orgs/acme/staff/customers/812 \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"email": "alex@example.com", "phone": "+44 20 7946 0000"}'
```

Send any of `email`, `first_name`, `last_name`, `company` and `phone`. An admin may also send `currency`, or `status` with a `reason` of up to 500 characters. The answer has the `customer`, what `changed`, whether a `verification_sent`, and how many `sessions_ended`. A request that changes nothing answers `400 Nothing to change`.

The other account actions are `POST` routes on the customer:

| Route | Body | What it does |
| --- | --- | --- |
| `/resend-verification` | None | Sends a new verification email. |
| `/mark-verified` | None | Marks the email verified. |
| `/reset-password` | `password` | Sets the password, ends the sessions and answers `sessions_ended` and `notified`. |
| `/reset-mfa` | None | Removes the second factor and answers `had_mfa` and `sessions_ended`. |
| `/revoke-sessions` | `token_id`, or nothing for every session | Ends sessions and answers how many in `revoked`. |
| `/chat-mute` | `minutes`, up to 525600, and `reason` | Mutes the customer in community chat and the forum. `0` lifts the mute. |
| `/close` | `reason` | Closes and anonymises the account. A refusal answers `409` with a `code`. |

`PUT /{customer_id}/tags` with `{"tags": ["reseller", "vip"]}` replaces the tags. `GET /{customer_id}/data-export` downloads the privacy export.

### Add credit

```bash
curl -X POST https://api.coritan.com/api/v1/orgs/acme/staff/customers/812/credit \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"amount": "10.00", "description": "Goodwill credit for the outage"}'
```

`amount` is in the customer's currency and must not be zero; a negative amount takes credit away. `description` takes up to 500 characters and defaults to `Manual credit`. The answer is the new `credit_balance`.

### Open a support session

```bash
curl -X POST https://api.coritan.com/api/v1/orgs/acme/staff/customers/812/impersonate \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"mode": "read_only", "next": "/billing"}'
```

`mode` is `read_only` (the default), `servers` or `full`, and `full` needs a `reason`. `next` is a path on your storefront to open once signed in. The answer has a customer `access_token` that lasts 1800 seconds, the `mode`, and a `portal_url` on your custom domain:

```text
https://example.com/auth/callback#access_token=...&impersonated=1&customer=812&next=/billing
```

A storefront you build receives the session on the same `/auth/callback` page as social sign-in, which [Sign customers in to your storefront](/organizations/storefront/customer-sign-in/) describes. `impersonated=1` marks a support session, and `mode` is `servers` or `full` for one that can make changes, so show the person that they are acting as the customer.

### Act on many customers

```bash
curl -X POST https://api.coritan.com/api/v1/orgs/acme/staff/customers/bulk \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"customer_ids": [812, 813], "action": "suspend", "reason": "Chargebacks on every order"}'
```

`action` is `suspend`, `unsuspend`, `terminate` or `ban`, and `reason` takes 3–500 characters. `delete_after_days` (1–90) schedules a deletion with a suspension, `open_ticket` defaults to `true`, and `notify_customer` sends the cancellation email with `terminate`. The answer lists the `applied` customers, the `skipped` ones with a `reason`, and each customer's `orders`, `changed` and `ticket_id`. Each member may run 12 bulk actions an hour, shared with bulk actions on servers.

### Create an account

```bash
curl -X POST https://api.coritan.com/api/v1/orgs/acme/staff/customers \
  -H "Authorization: Bearer $STAFF_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"email": "alex@example.com", "first_name": "Alex", "currency": "EUR"}'
```

It answers `201` with the `customer` and `setup_email_sent`. Send `"send_setup_email": false` to hand the account over another way. A `currency` the platform has not enabled answers `400` and names it.

## API

- `GET /api/v1/orgs/{org_slug}/staff/customers`: Directory for this brand, separate from the mixed desk search (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers)
- `POST /api/v1/orgs/{org_slug}/staff/customers`: An account for someone who ordered by phone or email (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers)
- `POST /api/v1/orgs/{org_slug}/staff/customers/bulk`: Staff customers bulk (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-bulk)
- `GET /api/v1/orgs/{org_slug}/staff/customers/export.csv`: The directory as it is filtered, as a CSV (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-export-csv)
- `GET /api/v1/orgs/{org_slug}/staff/customers/tags`: Every label in use on this brand, with how many customers carry it (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-tags)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}`: Staff customer hub (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id)
- `PATCH /api/v1/orgs/{org_slug}/staff/customers/{customer_id}`: Fix the profile (support), or change the account's standing (admin) (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-patch-api-v1-orgs-org-slug-staff-customers-customer-id)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/activity`: Staff customer activity (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-activity)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/chat-mute`: Silence a handle in community chat and the forum for a while, or lift it (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-chat-mute)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/close`: Staff close customer (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-close)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/credit`: Staff add credit (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-credit)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/credit-ledger`: Staff credit ledger (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-credit-ledger)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/data-export`: Everything held about the customer, as one JSON file, for a privacy request (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-data-export)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/emails`: Staff customer emails (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-emails)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/impersonate`: Staff impersonate customer (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-impersonate)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/mark-verified`: Vouch for an address the customer proved another way (a call, a ticket from that inbox) (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-mark-verified)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/notes`: List customer notes (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-notes)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/notes`: Add customer note (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-notes)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/payment-methods`: Staff customer payment methods (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-payment-methods)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/related`: Staff customer related (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-related)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/resend-verification`: Staff resend verification (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-resend-verification)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/reset-mfa`: For a customer who lost their phone: remove their second factor and end their sessions (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-reset-mfa)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/reset-password`: Staff reset customer password (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-reset-password)
- `POST /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/revoke-sessions`: Staff revoke customer sessions (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-post-api-v1-orgs-org-slug-staff-customers-customer-id-revoke-sessions)
- `GET /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/sessions`: Staff customer sessions (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-get-api-v1-orgs-org-slug-staff-customers-customer-id-sessions)
- `PUT /api/v1/orgs/{org_slug}/staff/customers/{customer_id}/tags`: Staff set customer tags (https://docs.coritan.com/api/reference/organizations/customers/staff/#op-put-api-v1-orgs-org-slug-staff-customers-customer-id-tags)
