Users

Users are individuals who have accounts to access the Medallia Experience Cloud. Each user requires a unique account, and each is assigned one or more roles that determine their access permissions. Some roles allow the user to manage other user accounts.

Important: Accounts should never be shared. For example, a retail store location should not have a single user account shared by all employees in the store. In that situation, password security is difficult to maintain, and usage tracking is less useful at a store-level compared to the employee level.

Manage user accounts with the Users screen. To access the screen, your primary role needs permission to access accounts. Contact your Medallia expert to identify the role used to grant that feature access at your company. For additional information, see Access Organization features.

Watch this video to learn about users:

Tip: Consider creating and updating users and their roles automatically with an Importer. Update user accounts manually for exceptions, troubleshooting, and correcting sign-in issues. For more information, see Importers.

Users screen

The Users screen lists all users you have permission to see, including their roles. Users are sorted by the last modified date and can be filtered by Role and Status. Use the search bar at the top of the list to search for a particular user.

Layer 1 1 2 3 4 5

  1. Details pane
  2. Details pane menu
  3. Roles and data access summary
  4. Filters
  5. Search bar

Details pane

Click a user to reveal its details pane, which shows the following:

Status
Status of the user, which can be Active or Inactive. See Deactivate user below for more information.
Roles
Role(s) assigned to a user.
Last login in
Date where the user last log in.
Created
Date the user was created.
Last modified
Date and user that last modified the user.

Details pane menu

Click the More vertical icon. details pane menu to:

Impersonate user
Open Medallia Web reporting as if you were that user. This enables you to validate whether the user has access to the reports and data they need. When you are done viewing reports as that user, click Impersonate icon. Impersonate at the top of Web reporting to switch back to your own account and open the Users list screen.

If the user you are impersonating has access to Users screen, you can manually open the screen and view users as if you were the user you are impersonating. If you do this, a banner in Users screen gives you the option of switching back to your own account.

Important: To use this, feature your role or user needs the Impersonate users Administrative permission. Additionally, your role or user must have the ability to edit the role to which you want to switch. If you lack the required permissions, you see reports only as defined for your role. For more information about configuring permissions for roles, see Roles.
Note: If you impersonate a user that uses translations different than for your user, report options (such as control panel selections) might not appear as expected. This behavior ensures that the language used by your own user is not disrupted.
Reset password via email
Initiates resetting the user's password by sending an email to the user's email address.
Reset password via recovery code
Initiates resetting the user's password by generating a code if the user does not have an email address.

Copy the code that appears on the screen, click OK, and enter/paste the password recovery code on the Recovery Code screen.

Click Reset multi-factor authentication
Only if multi-factor authentication is enabled for both the customer and the specific user. Disables multi-factor authentication for the user, after which the option is no longer in the details pane menu.
Deactivate user
Sets the user's status to Inactive. When you deactivate a user, any sessions in use by that account (whether in Web reporting or Medallia Mobile) end. Additionally, a disabled user cannot be authenticated.
Delete user
Removes the user from Experience Cloud.
Note: When a user is deleted, it cannot be recovered; however, that username can be reused for another account.
Duplicate roles and settings
Creates a new user by copying the information of an existing user. Settings that are copied include language, advanced settings (except for Exclude user metrics from activity reports, Don't allow file uploads to automatically update user settings, and Block user from login form), primary and secondary roles, data access organization, and segments for each role and data view.
Note: Administrators can only copy users with roles within the scope of the administrator user's manage users scope. If an administrator tries to copy a user that has assigned roles outside of that scope, an error will appear.
View changelog
Redirects you to Change Log.

Create and manage users

Complete these steps to create a new user:

  1. From Users screen, click New User.

  2. Configure your user properties. For more information, see User editor.

  3. Click Save.

New user John Doe with Basic information created.

Manage users

To manage a user, click Edit to modify its information. To delete a user, click Delete in More vertical icon the details pane menu.

Duplicate users

To create a new user by copying the information of an existing user, select the user to duplicate and, from its details pane menu, click Create new user with same roles and settings. Enter a username, first name, and last name for the new user and, optionally, edit any other settings. See Create new user with same roles and settings for more information.

Import users

To import a list of users, select Import users from the New User Arrow down icon. dropdown.

Download users

To download user information, select Download users from the New User Arrow down icon. dropdown. The downloaded user file contains the following information for each user:

  • Username
  • First name
  • Last name
  • Email
  • Phone
  • Company account ID
  • No automatic updates
  • Primary role
  • Roles
  • Role and corresponding data access
  • Block user from using the login form
    Restriction: This feature is inactive by default. Ask your Medallia expert to file a Feature activation request with Medallia Support.
  • Exclude user's metrics from user activity reports
    Restriction: This feature is inactive by default. Ask your Medallia expert to file a Feature activation request with Medallia Support.
Restriction: When creating a user, you cannot select both, Block user from login form and Email user the password, simultaneously.

For more information, see Manual Imports.

Import and download options.

User editor

The User editor is the building area to configure a user account. Navigate through the User editor as desired, without the need of following a specific path, by clicking through using the left navigation pane.

The User editor includes three sections:

  • Basic information — Includes key and required properties for the user to work. For more information, see Basic user information.

  • Activity — Only available after the user has been created. Provides summary information about the creation and modification of the user account. For more information, see Activity .

  • Roles and data access — Roles and data access lists all of the user's roles as well as the data access configured for each role. For more information, see Roles and data access.

User editor for ContactCenter Admin.

Basic user information

Basic information contains key and required properties for the User to work, such as name, contact information, and language preference.

Basic information for a user account

Username
Unique name required to identify a user. The first character must be a letter, number, dash (-), period (.), or commercial at sign (@). After the first character, it can contain only letters, numbers, dashes, periods, and underscore characters (_).
First name
User's first name.
Last name
User's last name.
Email
User's email account, in which they receive Experience Cloud emails such as New user, Reset password, Lost username, etc.
Phone
User's phone number
Language

Language the user sees in reports and Experience Cloud emails. It also serves as a default locale for alert names and descriptions visible in Medallia Mobile. You must have a corresponding translation configured to use a language other than English. For more information, see Translations.

Note: Language is automatically updated if a different language is selected for a user in User settings, which is accessed by clicking a user's name in the upper-right corner of Experience Cloud and selecting Language
Unit
Unit the user belongs to.

Advanced settings

Additionally, configure these advanced settings:

Exclude user's metrics from user activity reports
When on, the user account is not included in user activity reports. For more information, see User activity and Health Check.
User settings can only be updated with the user interface
When on, the user account is not updated automatically when importing user account changes, and only manual updates on the User Details editor are available.
Block user from using login form

Experience Cloud blocks users from using the manual login form by default, whether they are created through Auto Importer, Importers, Manual Imports or Experience Cloud RESTful APIs. The sign-in process for blocked users requires Single sign-on (SSO).

To allow users to sign in manually (username and password), deselect this option.

Warning: Medallia recommends enabling Multi-factor authentication for users who sign-in with username and password. After 31 January 2027, MFA will be required for all users that still use the manual login form.
Company Account ID
When using SSO, this is an alternative lookup key to include after or instead of the username. Include this value when importing user account information.
Warning: Do not change this value for user accounts. Change this value only for Templates Accounts, as defined on the Users Admin screen in Setup. For more information, see Users admin.

Activity

Activity provides summary information about the creation and modification of the user account. It also shows basic information about that user's activity in Experience Cloud.

Activity section shows information about the user's Last updated, Created, Login, and Password.

Changing any of these fields — either manually or automatically — updates the Last Updated date and time:

  • Block reason
  • Block user from using the login form
  • Company Account ID
  • Email
  • Exclude user's metrics from user activity reports
  • First Name
  • Language
  • Last Name
  • User settings can only be updated from the user interface
  • Password changed
  • Password last emailed to user
  • Phone
  • Role (User Group, Primary)
  • Salutation (deprecated field)
  • Status (Active or Inactive)
  • Username

Roles and data access

Roles and data access lists all of the user's roles as well as the data access configured for each role.

Roles

Roles are a set of permissions defining access to reports and administrative abilities. A user can have one or more roles. To add a new roles, click Add icon Add role and select the role to assign. For more information, Roles

The Primary role is listed first. To make another role primary, click More vertical icon the role menu and select Make Primary.

Select Make Primary to make that role Primary for the user.

Restriction: If a role is designated as Primary - Fixed, it must remain the Primary role. When a user has a Primary - Fixed role, you cannot make another role Primary for that user.

To remove a role from a user, click More vertical icon the role menu and select Remove role.

Data access

Data access control which subset of records a user can see, determined by the units, unit groups, and segments defined for that data view. For more information, see Data access permissions. A user's data access for each role are listed under the role.

Important:
  • Data access must be explicitly set for each new user's primary role default permission context. Each new user must have access to at least one unit or unit group as well as to one organizational or segment category. In situations where a role's data view has at least one segment granted and no organizations granted, the All units data access is granted in Reporting only (that is, the All units check box will not be selected in the bottom right corner of the data access screen).
  • Roles with Do anything capability (such as Internal Admin or Partner) automatically see all users regardless of their level of data access.

Click Information icon information next to a data access to see a list of reports the user can see use per that data view:

List of reports the user can see per that data view

Click a data access to open it for editing. Configure the user's data access by units and unit groups in the Organization tab and by segments in the Segments tab.

Data access granted needs to be equal or less than the data access the admin has. When only a segment is granted to the admin, it's required for that segment to be granted when creating new users. When only a organization is granted to the admin, that segment must be granted to new users that the admin creates.

Within a data view, the Units count at the top-right of the screen shows the records visible through that data view. It reflects the combined settings in the Organization and Segments tabs and is updated dynamically if you add or remove units, unit groups, or segments.

Edit User screen showing number of units the user can access.

To add all available units to the data view, select the Access to all Units property.

Access to all Units check box.

Organization tab

The Organization tab lists units and unit groups alphabetically in each unit category, with higher-priority categories listed first. For example, the following image shows that the user can only see records associated with the specific districts.

Units and unit groups within a category

Segments tab

The Segments tab lists the field-level access for a data view. For example, the following image shows that the user can see only records in the QA phase of the development cycle.

Segment-level access for a data view

Important: Setting a data permission option for all users via Permission by segment in Medallia Setup is not supported in Medallia Admin Suite. While the fields associated with the specific permission by segment can be viewed and edited in other areas of Experience Cloud, these fields do not appear in the Data access section in Admin Suite. Apply the data permission options individually to each role in as a workaround.