Masked fields screen

Reporting > Report Helpers > Fields > Masked Fields

Sensitive fields are ones whose values are masked or hidden from users who do not have authorization to see them. Use this screen to select fields to mask. When an unauthorized user looks at a report or screen that contains sensitive fields, the values in those fields are either masked with two asterisks (**) for string fields or empty (for non-string fields). For more information, see Mask field data.

Masked fields can only be included in searches by users that have permission to see sensitive data. This is happens even for fields configured specifically as searchable in the Searchable Fields standard report module.

Restriction: This screen is disabled by default. Enable this only if you intend to use this feature, which makes the field list available on this screen.
Warning: Before enabling data masking, grant Access unmasked data to roles that should have access to see personal data, close the loop, or have access to read and update the note log. Otherwise, users are not being to perform those actions. Additionally, if any roles need access to Feedback responses, assign those roles the Send Followup Email with Data Masking (only compatible with Medallia Alchemy Experience Reporting) permission.

Sensitive fields

To mask sensitive fields, select them on this screen and click Save. All non-authorized users see masked or hidden data for these fields after they next sign in.

To create detailed rules for masking sensitive data in Medallia Admin Suite. For more information, see Sensitive data.

Important: All personal data fields should be marked as sensitive, including but not limited to name, address, phone number, email address, IDs, date and place of birth, biometrics, etc.
Restriction: When an administrator who has permission to see this screen switches accounts to impersonate another user, the administrator no longer can see this screen, and sensitive fields are masked. Additionally, this screen remains hidden after switching back to the administrator user from the impersonated account, and sensitive fields remain masked. This restriction continues until the administrator signs out and signs back in.