Remove the collaborator from Matomo
Use this process when the collaborator should no longer access your Matomo instance.
Removal Steps
- Go to Administration → System → Users and find the collaborator’s account.
- Click Delete to remove the user entirely, or downgrade the global role to No Access and clear all site permissions if you must retain the record.
- Revoke any
token_auth
keys or API credentials associated with the account. - If SSO/LDAP is enabled, remove the user from the associated identity groups.
- Save changes and confirm the account no longer appears in the user list.
Evidence & Communication
- Export the updated user list or capture a screenshot showing removal.
- Archive the Audit Log entries documenting the change.
- Notify the collaborator’s engagement lead that access has been revoked.
Additional Clean-Up
- Reassign scheduled reports, alerts, or tag manager configurations owned by the collaborator’s account.
- Rotate database credentials or SSH keys if the collaborator previously managed the infrastructure.
- Update your IAM tracker and contract file with the removal date and reference ticket.