Permission by Segment

Company > Users > Roles > Permission by Segment

Permissions by Segment identifies the survey-record fields and segments used in access control, and in which contexts they can be applied.

Note: Several options that used to be on this Setup page moved to Company > Users > Roles > User and Org Hierarchy Settings.

This screen identifies the fields and segments that can be used for access control. Each Role can have a different set of fields, called a data view, and a default view can be assigned to the company. Once the fields and segments are defined, specific access is determined by the permissions granted to the user account via the user's active Role.

Permission contexts supplement and override the account permissions, but only in the specific context in which they are applied. Unlike other areas of access control that combine to restrict access, this is a place where permissions can be granted beyond what the user would normally be allowed to see.

Permissions listed in grey on the Permission by Segment screen are inherited by a permission context for that role, granting targeted additional permissions for the role, as configured by the MemberPermissionContexts property on the Company > Users > Roles > Roles screen. For more information about permission contexts, see Permission contexts.

Note: For a complete discussion of access control and permission contexts, see Roles, permissions, and capabilities.
Important: Setting a data permission option for all accounts via permission by segment in Classic is not supported in Medallia Admin Suite. While the fields associated with the specific permission by segment can be viewed and edited in other areas of Experience Cloud, these fields will not appear in the Data Access section of the user editor screen in Medallia Admin Suite. Apply the data permission options individually to each role in Medallia Admin Suite as a workaround (see Users screen for additional information).

Properties

Permission Fields

Identifies the fields that may be used for access control. The set of permission fields is called a Data View. Use this section to pick the default fields available to all Roles, and the specific fields available to specific Roles and contexts.

There is one default set of permissions for the company, and then there is one additional set for each of the defined Permission contexts.

  • The default set includes all of the company's Roles; you can assign permission fields for each Role.
  • Each Permission Context shows the permission segments assigned to to the entire company, for each Role that has this context. Assign a context to a Role on the Roles screen.

Click the Edit button to choose the segments and fields to be used for permissions. When using the editor:

  • The All Company <Units> role is a global set for all roles in the company.

  • The All Individual Units option is a special-case that includes records with empty or null values. All other options exclude null values.
  • Assign segments to limit the role to that specific segment value, like a filter.
  • Assign segment groups, parent Unit Groups, and Unit fields to use the User's specific permissions for those selections. Use the User's Data Access settings on the Users screen to set the values (or import the permissions with Auto Importer).
  • Parent Unit Groups are only available when a specific Org Hierarchy is selected for the Role.

  • Only invitation and survey fields available are available, and the fields must be enumerated fields or auto-indexed text fields.

For a complete discussion, see Roles, permissions, and capabilities. In particular, see the "Roles as data access filters" and "Contexts" sections for a discussion of permissions by segment.

Note: Use the Export and Import options to copy a configuration between instances, such as from a sandbox to a production instance. Click Export, copy the encoded string, and then in the target instance click Import and paste the string.
Auto-configure Permission by Segment fields
Automatically analyzes the permissions of all active accounts in the system and add the permission fields to the Roles in Permission by Segment. This action only adds fields; it never remove fields from the Roles.