This guide covers the process of removing user access from your Criteo account, including full account removal and partial access revocation.
When to Remove Access
Remove or restrict user access when:
- Employee leaves the company
- Contractor or agency engagement ends
- User changes roles and no longer needs access
- Security incident requires immediate access revocation
- User no longer works with specific advertisers
- Compliance audit requires access reduction
- User account is compromised
Prerequisites
Before removing access:
- Administrator permissions in Criteo Management Center
- User identification (email or name)
- Approval for access removal (if required)
- Transition plan for user's campaigns/assets
- Documentation requirements reviewed
Types of Access Removal
Complete Account Removal
Removes user entirely from organization:
- User loses all advertiser access
- Cannot log into Criteo Management Center
- All permissions revoked
- User removed from organization roster
Partial Access Removal
Removes access to specific advertisers:
- User retains access to other advertisers
- Can still log into account
- Permissions maintained for remaining advertisers
Temporary Suspension
Disables access temporarily:
- Account deactivated but not deleted
- Can be reactivated later
- Preserves user history and settings
Complete User Removal
Step 1: Access User Management
- Log in to Criteo Management Center
- Click your profile icon in the top-right corner
- Select Organization Settings
- Click Users & Permissions
Step 2: Locate User
- Search for user by name or email
- Or scroll through user list
- Click on user's name to open profile
Step 3: Transfer Ownership
Before removing, transfer ownership of:
Campaigns:
- Active campaigns user manages
- Scheduled campaigns
- Draft campaigns
Audiences:
- Custom audience segments
- Retargeting lists
API Credentials:
- API keys user owns
- Automated integrations
- Scheduled reports
Creative Assets:
- Ad templates
- Creative sets
- Product feeds
Step 4: Remove User
- In user profile, click More Actions (⋯)
- Select Remove User
- Review warning message about data/access loss
- Confirm removal by:
- Typing user's email address
- Checking confirmation box
- Click Remove User Permanently
Step 5: Verification
- User disappears from user list
- Check Audit Log for removal record
- Verify user cannot log in
- Confirm ownership transfers completed
Step 6: Documentation
Document the removal:
## User Removal Record
**User:** john.doe@company.com
**Removed:** 2024-10-20 14:30 UTC
**Removed By:** admin@company.com
**Reason:** Employment terminated
**Advertisers Affected:** A, B, C
**Campaigns Transferred To:** jane.smith@company.com
**API Credentials:** Revoked
**Approval:** HR Ticket #12345
Partial Access Removal
Remove Advertiser Access
Remove access to specific advertisers while keeping user active:
Step 1: Open User Profile
- Navigate to Users & Permissions
- Find and open user's profile
- Go to Advertiser Access section
Step 2: Remove Specific Advertisers
- Find advertiser(s) to remove
- Click X or Remove next to advertiser name
- Confirm removal
- Repeat for additional advertisers
Step 3: Verify Remaining Access
- Check user still has access to other advertisers
- Verify user can still log in
- Confirm permissions on remaining advertisers
Example:
Before:
- Advertiser A: Campaign Manager
- Advertiser B: Campaign Manager
- Advertiser C: Analyst
After (removed B):
- Advertiser A: Campaign Manager
- Advertiser C: Analyst
Downgrade to Read-Only
Revoke editing permissions while maintaining visibility:
- Open user profile
- Change role to Analyst for specific advertiser(s)
- Or change role globally across all advertisers
- User retains reporting access but cannot edit
Use Cases:
- User transitioning to different role
- Temporary restriction during investigation
- Contractor moving to advisory role
Temporary Suspension
Suspend User Account
Disable access temporarily:
- Open user profile
- Click Account Status
- Select Suspend Account
- Specify:
- Suspension reason
- Expected reactivation date (optional)
- Notification settings
- Click Suspend
During Suspension:
- User cannot log in
- All access frozen
- Data and settings preserved
- Can be reactivated anytime
Reactivate Suspended Account
To restore access:
- Navigate to Users & Permissions
- Filter by Suspended status
- Select user
- Click Reactivate Account
- Confirm reactivation
- User can log in immediately
Emergency Access Revocation
Immediate Removal for Security
For security incidents:
Quick Removal Process
Immediate Actions:
1. Navigate to user profile (30 seconds) 2. Click Remove User (10 seconds) 3. Confirm removal (5 seconds) 4. Total time: ~45 secondsVerify Removal:
- User logged out immediately
- Active sessions terminated
- API credentials revoked
- Access to all advertisers removed
Additional Security Steps:
- Change shared passwords user had access to
- Review recent user activity in audit log
- Check for unauthorized changes
- Revoke API keys user may have saved
- Alert security team
Post-Incident Checklist
After emergency removal:
- User access confirmed revoked
- Sessions terminated
- API credentials disabled
- Recent activity reviewed
- Unauthorized changes identified
- Security team notified
- Incident documented
- Management informed
- Recovery plan initiated
API Access Revocation
Revoke API Credentials
When removing user with API access:
- Before removing user, navigate to API Credentials
- Find credentials owned by user
- Click Revoke for each credential
- Document revoked credentials
- Update any integrations using those credentials
- Then proceed with user removal
Important:
- Revoke API access before removing user
- Update automated systems using those credentials
- Monitor for broken integrations
- Test replacement credentials
Transfer API Ownership
To preserve integrations:
- Create new API credentials under different user
- Update integrations with new credentials
- Test integrations work with new credentials
- Revoke old credentials
- Remove original user
Bulk User Removal
Remove Multiple Users
For offboarding multiple users:
Step 1: Prepare List
Create CSV of users to remove:
email,removal_date,reason
john.doe@company.com,2024-10-20,Termination
jane.smith@company.com,2024-10-20,Contract ended
bob.johnson@company.com,2024-10-20,Role change
Step 2: Bulk Remove
- Users & Permissions > Bulk Actions
- Select Remove Users
- Upload CSV or select multiple users
- Review users to be removed
- Confirm bulk removal
- Monitor progress
Step 3: Verification
- Check all users removed successfully
- Review audit log entries
- Verify ownership transfers
- Document bulk removal
Offboarding Process
Complete Offboarding Checklist
For employee departure:
Week Before Departure:
- Identify user's Criteo access
- List campaigns/assets user owns
- Assign transition owner
- Schedule knowledge transfer
- Document access removal plan
Last Day:
- Transfer campaign ownership
- Transfer audience ownership
- Revoke API credentials
- Download user's activity report
- Remove user access
- Verify removal successful
Post-Departure:
- Confirm no access remains
- Update team documentation
- Archive user records
- Update contact lists
- Close related service tickets
Knowledge Transfer
Before removal:
Document User's Work:
- Active campaigns and strategies
- Optimization approaches
- Custom audiences and segments
- Reporting templates
Transfer Ownership:
- Assign new campaign owner
- Share custom reports
- Transfer creative assets
- Update documentation
Train Replacement:
- Review campaign strategies
- Explain optimization logic
- Share access credentials
- Provide context
Compliance and Legal
Data Retention
When removing users:
What's Retained:
- Audit log of user actions
- Campaign history created by user
- User-generated reports (if saved)
- Attribution data
What's Removed:
- User login credentials
- Personal profile information
- Private settings
- Saved views/preferences
Legal Holds
If user under legal hold:
- Do NOT remove user account
- Suspend access instead
- Preserve all user data
- Contact legal department
- Document hold reason
- Set reminder for hold review
GDPR/Data Privacy
For data subject requests:
Right to Erasure:
- User requests data deletion
- Verify identity
- Remove account
- Delete personal data
- Retain business records (as required)
- Confirm deletion to user
Data Export: Before removal, user can request:
- Campaign data
- Performance reports
- Personal settings
- Activity history
Monitoring After Removal
Verify Removal Effectiveness
Immediate Checks (Day 1):
- User cannot log in
- Email notifications stopped
- API calls fail with authentication error
- User removed from all advertiser access lists
Follow-up Checks (Week 1):
- No unauthorized access attempts
- Transferred ownership functioning correctly
- No broken integrations
- Team aware of user removal
Long-term Monitoring (Month 1):
- Review audit logs for anomalies
- Confirm no orphaned assets
- Verify replacement user successful
- Update access documentation
Troubleshooting
Cannot Remove User
Error: User owns critical resources
Solution:
- Transfer campaign ownership first
- Reassign API credentials
- Move creative assets
- Then retry removal
Error: Insufficient permissions
Solution:
- Verify you have Administrator role
- Check organization-level permissions
- Contact another administrator
- Contact Criteo support if needed
User Still Has Access
Check:
- Browser cache (user should clear)
- Active sessions (may take minutes to expire)
- Removal was saved successfully
- Check audit log for confirmation
Solutions:
- Force user logout from admin panel
- Wait for session expiration (15 minutes)
- Have user clear cookies and try again
- Contact Criteo support
Removed User Can Still Access
Immediate Actions:
- Verify removal in user list
- Check audit log for removal record
- Force session termination
- Change account passwords if shared
- Contact Criteo support urgently
Best Practices
1. Regular Access Audits
Monthly:
- Review inactive users
- Check for unused accounts
- Verify all users still employed
- Remove departed users promptly
Quarterly:
- Comprehensive access review
- Remove stale accounts
- Verify appropriate permission levels
- Update documentation
2. Timely Removal
✓ Good: Remove access on last day of employment
✗ Bad: Delay removal for weeks/months
✓ Good: Immediate removal for security issues
✗ Bad: Wait for approval in emergencies
3. Documentation
Maintain removal log:
## User Removal Log 2024
### October 20: John Doe
- Reason: Termination
- Advertisers: A, B, C
- Transferred to: Jane Smith
- Removed by: admin@company.com
### October 22: Bob Johnson
- Reason: Contractor end
- Advertisers: D
- Removed by: admin@company.com
4. Communication
Notify Stakeholders:
- User's manager
- Team members
- Dependent teams
- Finance (for billing changes)
Email Template:
Subject: Criteo Access Removed - [User Name]
Team,
Criteo access has been removed for [User Name] effective [Date].
Campaigns transferred to: [New Owner]
API credentials: Revoked
Questions: Contact [Admin Name]
[Your Name]
5. Security Hygiene
After removal:
- Change shared passwords
- Rotate API keys if shared
- Review recent activity
- Check for suspicious changes
- Update security documentation
Getting Help
Common Questions
Q: Can I recover a removed user? A: No, removal is permanent. You must invite user again as new account.
Q: What happens to user's campaigns? A: Campaigns remain active. Transfer ownership before removal.
Q: Do removed users count against user limit? A: No, only active users count toward any limits.
Q: Can user's email be reused? A: Yes, after removal you can invite same email as new user.
Support Resources
- Criteo Help Center: https://help.criteo.com
- Support Ticket: Via Management Center
- Security Team: For emergency removals
- Account Manager: For policy questions
Next Steps
- Add User Access - Invite replacement users
- Update User Access - Modify existing users
- User Management Overview - Roles and permissions guide