Delete PCI Merchant User
PCI Compliance Merchant user can remove sub-user accounts that are no longer needed, for example, when an employee leaves the organization. The feature is designed to automatically satisfy PCI ASV data-retention requirements, so removing a user never puts historical scan and audit records at risk.
PCI Merchant Point of Contact (POC) users can delete sub-user accounts directly from the PCI Merchant user interface. Deleted users immediately lose access to the platform, and the account is permanently removed once it is safe to do so under Qualys' PCI ASV data-retention policy.
Previously, unwanted user accounts could only be disabled and had to remain in the system indefinitely.
How to delete merchant sub-user
The following are the steps to delete a merchant sub-user:
- In the PCI Compliance, login as a Merchant POC user.
- In the PCI Merchant UI, navigate to the Accounts > Users tab.
- Locate the sub-user you want to delete.
- Click Edit. The Edit User window opens.
- Select the Delete User checkbox. A confirmation message is displayed. The Delete User checkbox is not visible for the merchant sub-users' account.
- Click Delete User in confirmation message. The selected merchant sub-user is deleted, or marked as pending, depending on the sub-user's scan history.
How user deletion works
The following is key behavior for User Deletion workflow:
- Who can delete a user: Only the merchant POC can delete accounts, and only for sub-users under their own merchant account. A POC user cannot delete their own account.
- What is Default Retention Period: It is the time duration for which PCI Merchant scan history is maintained in the PCI Compliance platform. By default the Default Retention Period is set to three years, to comply with PCI security guidelines.
- How deletion is confirmed: A confirmation dialog explains that the user immediately lose access, that permanent deletion follows after the applicable retention period, that the username cannot be reused until then, and that the action cannot be undone.
- How long it takes to remove the account: Once confirmed, the account is marked Pending Deletion and the affected user immediately loses access to PCI Compliance. The usernames are blocked for the use until if the account has pending deletion status.
- How to delete accounts linked to Vulnerability Management (VM): Accounts linked to the VM must be un-linked before they can be deleted.
- How user is deleted: The user deletion depends on sub-users scan history. The following table explains how the user deletion is completed.
User Account Status During Deletion How Deletion is Processed How Account is Removed The user has no scan history on record The account is immediately deleted. The account is immediately removed, and the username is freed for reuse once the deletion is complete. The user has scan history (the typical case) The account is immediately disabled, and the sub-user access is revoked. The account and username is reserved till the applicable retention period is elapsed. By default, the account and scan history is maintained for the three years from its last scan date. The merchant has disable-only access. The account is disabled immediately. If the merchant-user specifically asks for disabled-only access, then the account is not deleted permanently.
What is account visibility for Pending Deletion status
Accounts awaiting permanent deletion remain visible in the Users tab so POC user retain full visibility into their user base:
- The is grayed-out with Pending Deletion status.
- The expected permanent-deletion date is displayed (for example, scheduled for deletion on 15-Sep-2029).
- Edit, view, and other actions are hidden for the account.
How long the deleted account's username is reserved
While an account is in the retention window, its username cannot be assigned to a new user. Anyone attempting to register with that username sees a clear message that it is currently reserved by an account pending deletion and cannot be reused until that deletion is complete.