Using JWT Auth, I've impersonated some admin users and that worked well.
However, I could not impersonate anyone with just the role "co-admin" (which is the most you can do creating new users through the Box API).
Just wanted to confirm then, if the user is just a co-admin, can they still be impersonated (i.e. not have any of additional admin privileges assigned to them).

Also, is it possible to add any of these admin permissions through the Box API?