Stitchflow
Peakon logo

Peakon User Management Guide

Manual workflow

How to add, remove, and manage users with operational caveats that matter in production.

UpdatedMar 11, 2026

Summary and recommendation

Peakon user management can be run manually, but complexity usually increases with role models, licensing gates, and offboarding dependencies. This guide gives the exact mechanics and where automation has the biggest impact.

Peakon (now part of Workday) is an employee engagement platform that manages users through a role-based access control model with five predefined roles: Super Admin, Admin, Manager, Employee, and Read-Only.

There is no custom role builder; permission granularity is achieved through segment scoping, which limits an Admin's data visibility to assigned organizational segments such as department or region. Like every app in the Workday ecosystem, user management lives at Settings → Employees (https://app.peakon.com/settings/users) and is accessible to Admin and Super Admin roles.

Quick facts

Admin console pathSettings → Users (accessible to Admin and Super Admin roles)
Admin console URLOfficial docs
SCIM availableYes
SCIM tier requiredEnterprise (starting $20,000/year)
SSO prerequisiteYes

User types and roles

Role Permissions Cannot do Plan required Seat cost Watch out for
Super Admin Full platform access: manage all users, roles, segments, surveys, integrations, billing, and global settings. Can view all employee data across the organization. All plans Counts as a licensed seat Super Admin can see all survey responses and employee data regardless of segment restrictions; assign this role with caution.
Admin Manage users, configure surveys, view dashboards, manage segments and attributes. Scope may be limited to assigned segments depending on configuration. Cannot manage billing or modify Super Admin accounts. All plans Counts as a licensed seat Admin access scope is segment-dependent; an Admin scoped to a sub-segment cannot view data outside that segment.
Manager View engagement dashboard and survey results for their direct reports and reporting hierarchy. Can action on insights for their team. Cannot configure surveys, manage other users, or view data outside their reporting line. All plans Counts as a licensed seat Manager role is typically assigned automatically based on the employee hierarchy imported via HRIS or CSV; manual assignment is possible but may conflict with automated sync.
Employee (Respondent) Receives survey invitations and submits responses. No dashboard or admin access. Cannot view aggregate results, manage other users, or access admin settings. All plans Counts as a licensed seat (primary billable unit) All active employees in the system consume a seat regardless of whether they have logged in or completed a survey.
Read-Only / Viewer Can view dashboards and reports for assigned segments without editing capability. Cannot configure surveys, manage users, or export data (export permissions vary by configuration). Availability varies; confirm with Peakon/Workday account team Counts as a licensed seat

Permission model

  • Model type: role-based
  • Description: Peakon uses a role-based access control model with predefined roles (Super Admin, Admin, Manager, Employee). Admins can be scoped to specific employee segments, limiting their data visibility to those segments. There is no fully custom role builder; permissions are tied to the predefined role tiers.
  • Custom roles: No
  • Custom roles plan: Not documented
  • Granularity: Role-level with segment scoping. Admins can be restricted to specific organizational segments (e.g., department, region). Individual permission toggles within a role are not available.

How to add users

  1. Log in as Super Admin or Admin.
  2. Navigate to Settings → Employees (or Settings → Users depending on account configuration).
  3. Click 'Add Employee' or 'Invite User'.
  4. Enter required fields: first name, last name, email address.
  5. Assign employee attributes (department, manager, location, etc.) as applicable.
  6. Assign a role if the user requires admin or manager access (default is Employee).
  7. Save the record. The user receives an email invitation to set up their account.

Required fields: First name, Last name, Email address

Watch out for:

  • If HRIS or SCIM sync is active, manually added users may be overwritten or duplicated on the next sync cycle unless the sync is configured to allow manual additions.
  • Email address must be unique across the tenant; duplicate emails will cause an import error.
  • Users added manually still consume a licensed seat immediately upon creation, not upon first login.
  • Invitation emails may land in spam; no built-in resend throttle is documented.
Bulk option Availability Notes
CSV import Yes Settings → Employees → Import Employees (CSV upload). Template downloadable from the same page.
Domain whitelisting No Automatic domain-based user add
IdP provisioning Yes Enterprise (starting $20,000/year); SSO must be configured as a prerequisite for SCIM provisioning.

How to remove or deactivate users

  • Can delete users: No
  • Delete/deactivate behavior: Peakon does not permanently delete employee records from the platform. Users are deactivated (set to inactive status), which removes them from future survey rounds and releases their seat for billing purposes, but their historical response data and attributes are retained for reporting continuity and anonymization compliance.
  1. Log in as Super Admin or Admin.
  2. Navigate to Settings → Employees.
  3. Search for the employee by name or email.
  4. Open the employee record.
  5. Click 'Deactivate' (or set status to Inactive).
  6. Confirm the deactivation. The employee will no longer receive survey invitations and will lose login access.
Data impact Behavior
Owned records Historical survey responses are retained and remain included in aggregate reporting. Individual responses remain anonymized per Peakon's anonymization thresholds.
Shared content Dashboards and segments the user was associated with remain intact; segment membership is removed upon deactivation.
Integrations If provisioned via SCIM, deactivation in the IdP (e.g., Okta) will trigger automatic deactivation in Peakon via the SCIM deprovision action. Manual deactivation in Peakon does not push back to the IdP.
License freed Seat is freed upon deactivation; the employee no longer counts toward the active employee billing count from the next billing cycle or immediately depending on contract terms.

Watch out for:

  • If HRIS sync is active, a deactivated employee may be reactivated on the next sync if the HRIS still shows them as active. Ensure the HRIS record is updated first.
  • Deactivated employees' historical data is retained indefinitely; there is no automatic purge.
  • Anonymization thresholds still apply to deactivated employees' responses; small teams may see data suppressed after deactivation reduces group size.
  • Reactivating a previously deactivated employee restores their record and re-consumes a seat.

License and seat management

Seat type Includes Cost
Active Employee Seat All active users in the system regardless of role (Employee, Manager, Admin, Super Admin). Includes survey participation, dashboard access per role, and platform features per plan tier. Custom pricing; contract is based on total active employee headcount. Starting at approximately $20,000/year for Enterprise tier.
  • Where to check usage: Settings → Employees → filter by Status: Active to view current active employee count. Billing seat count is typically reconciled by Workday/Peakon account team at contract renewal.
  • How to identify unused seats: No built-in 'last login' report is documented in publicly available help content. Admins can filter employees by survey participation status (e.g., never responded) as a proxy for identifying inactive users. Contact the Peakon account team for usage analytics.
  • Billing notes: Pricing is based on total active employee headcount under contract, not on feature usage or login frequency. Deactivated employees do not count toward the billable seat total. Contract pricing is negotiated annually with the Workday/Peakon sales team; no self-serve plan changes are available.

The cost of manual management

Active employees consume a licensed seat immediately on record creation-not on first login-so any delay in deactivating leavers directly inflates your billable headcount.

Peakon does not support permanent deletion; deactivation is the only offboarding action, and if your HRIS sync is active, a deactivated record can be silently reactivated on the next sync cycle if the HRIS record was not updated first.

There is no documented last-login report, so identifying unused seats requires manual filtering by survey participation status or a call to the Peakon account team.

What IT admins are saying

Practitioners consistently flag three friction points. First, the Enterprise-only pricing floor makes the platform inaccessible to smaller organizations and limits negotiating leverage for mid-market buyers.

Second, post-Workday acquisition, some admins report disorientation navigating between the legacy Peakon UI and Workday-integrated views. Third, CSV bulk-upload errors are often non-descriptive, making import troubleshooting slow and opaque.

The absence of granular custom roles is also a recurring complaint for organizations that need fine-grained permission control beyond the predefined tiers.

Common complaints:

  • High cost compared to some employee feedback tools; minimum spend threshold makes it inaccessible for smaller organizations.
  • Admin interface complexity increases after Workday acquisition; some users report confusion navigating between legacy Peakon UI and Workday-integrated views.
  • HRIS sync conflicts can cause deactivated employees to be reactivated unexpectedly if the HRIS record is not updated simultaneously.
  • No granular custom role builder; organizations needing fine-grained permission control must work within predefined role tiers.
  • Limited visibility into which employees have never logged in or engaged, making it difficult to identify wasted seats without manual filtering.
  • CSV import errors are not always descriptive, making bulk upload troubleshooting time-consuming.

The decision

Every app in your stack that lacks reliable automated deprovisioning adds headcount reconciliation overhead at renewal, and Peakon is no exception given its absence of a last-login report and its HRIS sync conflict risk.

Peakon is a strong fit if your organization is already in the Workday ecosystem or needs enterprise-grade engagement analytics with HRIS-driven hierarchy management; the native Workday HCM integration and full SCIM 2.0 support reduce manual provisioning overhead significantly at scale.

However, if your team is smaller, budget-constrained, or needs custom role granularity, the predefined role model and Enterprise-only entry point will create ongoing administrative friction.

Bottom line

Peakon delivers robust engagement analytics and a clean HRIS-to-platform sync story for Workday customers, but the manual provisioning path carries real seat-leak exposure: seats are billed on creation, deactivation is the only removal option, and HRIS sync conflicts can undo offboarding actions silently.

Every app that relies on manual lifecycle management creates reconciliation risk at renewal time, and Peakon's absence of a last-login report makes that reconciliation harder than it should be.

Organizations outside the Workday ecosystem or below the Enterprise spend threshold should weigh those operational costs carefully against the platform's analytics value.

Automate Peakon workflows without one-off scripts

Stitchflow builds and maintains end-to-end IT automation across your SaaS stack, including apps without APIs. Built for exactly how your company works, with human approvals where they matter.

Every app coverage, including apps without APIs
60+ app integrations plus browser automation for apps without APIs
IT graph reconciliation across apps and your IdP
Less than a week to launch, maintained as APIs and admin consoles change
SOC 2 Type II. ~2 hours of your team's time

UpdatedMar 11, 2026

* Details sourced from official product documentation and admin references.

Keep exploring

Related apps

15Five logo

15Five

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

15Five uses a fixed role-based permission model with six predefined roles: Account Admin, HR Admin, Billing Admin, Group Admin, Manager, and Employee. No custom roles can be constructed. User management lives at Settings gear → People → Manage people p

1Password logo

1Password

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

1Password's admin console at my.1password.com covers the full user lifecycle — invitations, group assignments, vault access, suspension, and deletion — without any third-party tooling. Like every app that mixes role-based and resource-level permissions

8x8 logo

8x8

Full API + SCIM
AutomationAPI + SCIM
Last updatedFeb 2026

8x8 Admin Console supports full lifecycle user management — create, deactivate, and delete — across its X Series unified communications platform. Every app a user can access (8x8 Work desktop, mobile, web, Agent Workspace) is gated by license assignmen