Users
Users are individuals who have accounts to access the Medallia Experience Cloud. Each user requires a unique account, and each is assigned one or more roles that determine their access permissions. Some roles allow the user to manage other user accounts.
Manage user accounts with the Users screen. To access the screen, your primary role needs permission to access accounts. Contact your Medallia expert to identify the role used to grant that feature access at your company. For additional information, see Access Organization features.
Watch this video to learn about users:
Users screen
The Users screen lists all users you have permission to see, including their roles. Users are sorted by the last modified date and can be filtered by Role and Status. Use the search bar at the top of the list to search for a particular user.
- Details pane
- Details pane menu
- Roles and data access summary
- Filters
- Search bar
Details pane
Click a user to reveal its details pane, which shows the following:
- Status
- Status of the user, which can be Active or Inactive. See Deactivate user below for more information.
- Roles
- Role(s) assigned to a user.
- Last login in
- Date where the user last log in.
- Created
- Date the user was created.
- Last modified
- Date and user that last modified the user.
Details pane menu
Click the details pane menu to:
- Impersonate user
- Open Medallia Web reporting as if you were that user. This enables you to validate whether the user has access to the reports and data they need. When you are done viewing reports as that user, click
Impersonate at the top of Web reporting to switch back to your own account and open the Users list screen.
If the user you are impersonating has access to Users screen, you can manually open the screen and view users as if you were the user you are impersonating. If you do this, a banner in Users screen gives you the option of switching back to your own account.
Important: To use this, feature your role or user needs the Impersonate users Administrative permission. Additionally, your role or user must have the ability to edit the role to which you want to switch. If you lack the required permissions, you see reports only as defined for your role. For more information about configuring permissions for roles, see Roles.Note: If you impersonate a user that uses translations different than for your user, report options (such as control panel selections) might not appear as expected. This behavior ensures that the language used by your own user is not disrupted. - Reset password via email
- Initiates resetting the user's password by sending an email to the user's email address.
- Reset password via recovery code
- Initiates resetting the user's password by generating a code if the user does not have an email address.
Copy the code that appears on the screen, click OK, and enter/paste the password recovery code on the Recovery Code screen.
- Click Reset multi-factor authentication
- Only if multi-factor authentication is enabled for both the customer and the specific user. Disables multi-factor authentication for the user, after which the option is no longer in the details pane menu.
- Deactivate user
- Sets the user's status to Inactive. When you deactivate a user, any sessions in use by that account (whether in Web reporting or Medallia Mobile) end. Additionally, a disabled user cannot be authenticated.
- Delete user
-
Removes the user from Experience Cloud.Note: When a user is deleted, it cannot be recovered; however, that username can be reused for another account.
- Duplicate roles and settings
- Creates a new user by copying the information of an existing user. Settings that are copied include language, advanced settings (except for Exclude user metrics from activity reports, Don't allow file uploads to automatically update user settings, and Block user from login form), primary and secondary roles, data access organization, and segments for each role and data view. Note: Administrators can only copy users with roles within the scope of the administrator user's manage users scope. If an administrator tries to copy a user that has assigned roles outside of that scope, an error will appear.
- View changelog
- Redirects you to Change Log.
Create and manage users
Complete these steps to create a new user:
-
From Users screen, click New User.
-
Configure your user properties. For more information, see User editor.
-
Click Save.
Manage users
To manage a user, click Edit to modify its information. To delete a user, click Delete in the details pane menu.
Duplicate users
To create a new user by copying the information of an existing user, select the user to duplicate and, from its details pane menu, click Create new user with same roles and settings. Enter a username, first name, and last name for the new user and, optionally, edit any other settings. See Create new user with same roles and settings for more information.
Import users
To import a list of users, select Import users from the New User dropdown.
Download users
To download user information, select Download users from the New User dropdown. The downloaded user file contains the following information for each user:
- Username
- First name
- Last name
- Phone
- Company account ID
- No automatic updates
- Primary role
- Roles
- Role and corresponding data access
- Block user from using the login formRestriction: This feature is inactive by default. Ask your Medallia expert to file a Feature activation request with Medallia Support.
- Exclude user's metrics from user activity reportsRestriction: This feature is inactive by default. Ask your Medallia expert to file a Feature activation request with Medallia Support.
For more information, see Manual Imports.
User editor
The User editor is the building area to configure a user account. Navigate through the User editor as desired, without the need of following a specific path, by clicking through using the left navigation pane.
The User editor includes three sections:
-
Basic information — Includes key and required properties for the user to work. For more information, see Basic user information.
-
Activity — Only available after the user has been created. Provides summary information about the creation and modification of the user account. For more information, see Activity .
-
Roles and data access — Roles and data access lists all of the user's roles as well as the data access configured for each role. For more information, see Roles and data access.
Basic user information
Basic information contains key and required properties for the User to work, such as name, contact information, and language preference.
- Username
- Unique name required to identify a user. The first character must be a letter, number, dash (-), period (.), or commercial at sign (@). After the first character, it can contain only letters, numbers, dashes, periods, and underscore characters (_).
- First name
- User's first name.
- Last name
- User's last name.
- User's email account, in which they receive Experience Cloud emails such as New user, Reset password, Lost username, etc.
- Phone
- User's phone number
- Language
-
Language the user sees in reports and Experience Cloud emails. It also serves as a default locale for alert names and descriptions visible in Medallia Mobile. You must have a corresponding translation configured to use a language other than English. For more information, see Translations.
Note: Language is automatically updated if a different language is selected for a user in User settings, which is accessed by clicking a user's name in the upper-right corner of Experience Cloud and selecting Language - Unit
- Unit the user belongs to.
Advanced settings
Additionally, configure these advanced settings:
- Exclude user's metrics from user activity reports
- When on, the user account is not included in user activity reports. For more information, see User activity and Health Check.
- User settings can only be updated with the user interface
- When on, the user account is not updated automatically when importing user account changes, and only manual updates on the User Details editor are available.
- Block user from using login form
-
Experience Cloud blocks users from using the manual login form by default, whether they are created through Auto Importer, Importers, Manual Imports or Experience Cloud RESTful APIs. The sign-in process for blocked users requires Single sign-on (SSO).
To allow users to sign in manually (username and password), deselect this option.
Warning: Medallia recommends enabling Multi-factor authentication for users who sign-in with username and password. After 31 January 2027, MFA will be required for all users that still use the manual login form. - Company Account ID
- When using SSO, this is an alternative lookup key to include after or instead of the username. Include this value when importing user account information. Warning: Do not change this value for user accounts. Change this value only for Templates Accounts, as defined on the Users Admin screen in Setup. For more information, see Users admin.
Activity
Activity provides summary information about the creation and modification of the user account. It also shows basic information about that user's activity in Experience Cloud.
Changing any of these fields — either manually or automatically — updates the Last Updated date and time:
- Block reason
- Block user from using the login form
- Company Account ID
- Exclude user's metrics from user activity reports
- First Name
- Language
- Last Name
- User settings can only be updated from the user interface
- Password changed
- Password last emailed to user
- Phone
- Role (User Group, Primary)
- Salutation (deprecated field)
- Status (Active or Inactive)
- Username
Roles and data access
Roles and data access lists all of the user's roles as well as the data access configured for each role.
Roles
Roles are a set of permissions defining access to reports and administrative abilities. A user can have one or more roles. To add a new roles, click Add role and select the role to assign. For more information, Roles
The Primary role is listed first. To make another role primary, click the role menu and select Make Primary.
To remove a role from a user, click the role menu and select Remove role.
Data access
Data access control which subset of records a user can see, determined by the units, unit groups, and segments defined for that data view. For more information, see Data access permissions. A user's data access for each role are listed under the role.
- Data access must be explicitly set for each new user's primary role default permission context. Each new user must have access to at least one unit or unit group as well as to one organizational or segment category. In situations where a role's data view has at least one segment granted and no organizations granted, the All units data access is granted in Reporting only (that is, the All units check box will not be selected in the bottom right corner of the data access screen).
- Roles with Do anything capability (such as Internal Admin or Partner) automatically see all users regardless of their level of data access.
Click information next to a data access to see a list of reports the user can see use per that data view:
Click a data access to open it for editing. Configure the user's data access by units and unit groups in the Organization tab and by segments in the Segments tab.
Data access granted needs to be equal or less than the data access the admin has. When only a segment is granted to the admin, it's required for that segment to be granted when creating new users. When only a organization is granted to the admin, that segment must be granted to new users that the admin creates.
Within a data view, the Units count at the top-right of the screen shows the records visible through that data view. It reflects the combined settings in the Organization and Segments tabs and is updated dynamically if you add or remove units, unit groups, or segments.
To add all available units to the data view, select the Access to all Units property.
Organization tab
The Organization tab lists units and unit groups alphabetically in each unit category, with higher-priority categories listed first. For example, the following image shows that the user can only see records associated with the specific districts.
Segments tab
The Segments tab lists the field-level access for a data view. For example, the following image shows that the user can see only records in the QA phase of the development cycle.
