Skip to content

Getting started

This chapter introduces what XTM One does, who it is for, and how to find your way around.

What XTM One is for

Use XTM One to:

  • access AI assistants built for cyber, intelligence, operations, and business workflows
  • ask for summaries, explanations, extractions, recommendations, and guided next steps
  • launch or monitor automated work handled by agents and assignments
  • reuse shared resources such as knowledge bases, prompts, skills, MCP servers, tools, variables, and integrations
  • review execution history, outputs, statuses, and results before taking action
  • use a common AI layer across the wider XTM Suite with shared authentication and platform services

Who it is for

XTM One is designed for business users, analysts, and operators. You do not need to be an AI specialist to use it.

It is useful for teams that work with:

  • OpenCTI
  • OpenAEV
  • cyber threat intelligence
  • investigations and analysis
  • reporting and summarization
  • operational triage and follow-up
  • security operations
  • threat-informed defense
  • email and messaging workflows
  • support or operational queues

What you will typically do

You will usually spend your time in a few places:

  • the Dashboard to see an overview
  • Chat to ask for help or start a conversation with an AI assistant
  • Agents to view and use configured assistants
  • History to check what happened and what was completed
  • Profile to update personal settings

Typical end-user activities include:

  • asking an assistant to explain, summarize, or transform content
  • using a prepared agent for a repeatable use case instead of writing long prompts manually
  • reviewing a run that was triggered automatically from a schedule, event, or external system
  • working with shared knowledge, prompts, skills, and tools created by your organization
  • using XTM One features from inside OpenCTI or OpenAEV when AI is embedded there

Access levels

What you can do in XTM One depends on your license and your role.

  • You may only see and use the shared platform capabilities.
  • You may be able to use the pre-packaged AI assistants.
  • You may be able to create and manage your own AI agents, skills, tools, and integrations.

This guide will explain those differences only when they matter for a task.

Key words in this guide

You will see a few recurring terms throughout this documentation:

  • Agent: an AI assistant configured for a specific use case, role, or workflow
  • Assignment: an automation rule that tells an agent when to run and what to do
  • Knowledge Base: searchable internal knowledge used to ground answers and actions
  • Prompt and Skill: reusable instructions that shape how agents behave
  • Tool or MCP Server: capabilities that let agents query, fetch, or act outside the chat itself
  • Integration: a connection to another system such as messaging, email, or external platforms

The main app uses a left sidebar for navigation.

The key sections are:

  • Dashboard
  • Agentic Flow
  • Chat
  • Agents
  • History
  • Knowledge
  • Prompts
  • Skills
  • MCP Servers
  • Tools
  • Variables
  • Integrations

If you are an administrator, you will also see:

  • Intents
  • Users
  • Groups
  • Objects
  • Logs
  • Settings

Some deployments may include additional administration modules, but these are the standard XTM One sections.

Top-right actions

The top bar may include quick actions for:

  • manual triggers
  • AI Catalog
  • notifications
  • your profile
  • settings, if you are an administrator
  • sign out

AI Catalog

XTM One also includes a catalog view for published items. It is used to browse shared content such as:

  • agents
  • skills
  • prompts
  • MCP servers
  • tools

XTM One in other XTM Suite products

Depending on your deployment, you may also use XTM One from inside another Filigran product such as OpenCTI or OpenAEV.

In those cases, XTM One appears as an embedded AI capability inside the product where you already work, rather than as a separate destination.

That means the same XTM One concepts can show up in different forms:

  • an assistant panel or AI action inside OpenCTI
  • embedded workflows, summaries, or contextual help inside OpenAEV
  • shared resources and automations that are managed centrally in XTM One but used from another product

Sign in

Open the XTM One sign-in page and choose the login method available in your organization.

You may see one or more of these options:

  • sign in with your company account
  • sign in with email and password
  • create a local account, if your organization allows it

If your organization uses single sign-on, you will be redirected to your identity provider and then brought back into XTM One automatically.

What happens after sign-in

After you sign in, you land in the main application area.

The first screen gives you access to:

  • the sidebar for moving between sections
  • the top bar for profile, notifications, and quick actions
  • the main page content in the center of the screen

Find your way around

Use the left sidebar to switch between the main parts of XTM One.

The most common places to start are:

  • Dashboard for the overall view
  • Chat to ask a question or work with an assistant
  • Agents to open a specific assistant
  • History to review completed work
  • Profile to update your own settings

If you are an administrator, you will also see the administration sections in the sidebar.

Understand what you can access

What you see in XTM One depends on your role and your organization’s license.

In practice, this means:

  • some users only use the shared platform experience
  • some users can use ready-made AI assistants
  • some users can manage their own agents and related resources

If a section is missing, it may not be enabled for your account.

Start with the dashboard

If you are not sure where to begin, open the Dashboard first.

It is the best place to:

  • see recent activity
  • check what is already in progress
  • find the next action you need to take

Next step

Once you are signed in and comfortable with the layout, move to the Foundations section.

Start with Foundations Overview, then continue to Data model before you move into the Dashboard and the rest of the UI chapters.