Getting started
This chapter introduces what XTM One does, who it is for, and how to find your way around.
What XTM One is for
Use XTM One to work with AI assistants built for cyber, intelligence, operations, and business workflows. You can ask for summaries, explanations, extractions, and recommendations; launch or monitor automated work handled by agents and assignments; reuse shared resources such as knowledge bases, prompts, skills, tools, and integrations; and review execution history before acting. Across the wider XTM Suite it acts as a common AI layer with shared authentication and platform services.
Who it is for
XTM One is designed for business users, analysts, and operators — you do not need to be an AI specialist. It is useful for teams working with OpenCTI, OpenAEV, threat intelligence, investigations, reporting and summarization, operational triage, security operations, and email or messaging workflows.
Key words in this guide
A few recurring terms appear throughout this documentation:
Agent: an AI assistant configured for a specific use case, role, or workflowAssignment: an automation rule that tells an agent when to run and what to doKnowledge Base: searchable internal knowledge used to ground answers and actionsPromptandSkill: reusable instructions that shape how agents behaveToolorMCP Server: capabilities that let agents query, fetch, or act outside the chat itselfIntegration: a connection to another system such as messaging, email, or external platforms
Sign in
Open the XTM One sign-in page and choose the login method available in your organization — a company account, email and password, or a local account if that is allowed. If your organization uses single sign-on, you are redirected to your identity provider and brought back automatically.
Find your way around
After signing in you land in the main application. A left sidebar moves you between sections, a top bar holds your profile, notifications, and quick actions (including the AI Catalog of shared, published items), and the center shows the current page.
The most common places to start are the Dashboard for an overview, Chat to work with an assistant, Agents to open a specific assistant, and History to review completed work. Administrators also see the administration sections (such as Users, Groups, Logs, and Settings).
What you can access depends on your role and your organization's license: some users only use the shared platform experience, some can use ready-made assistants, and some can create and manage their own agents and resources. If a section is missing, it may not be enabled for your account. This guide explains those differences only when they matter for a task.
XTM One in other XTM Suite products
Depending on your deployment, you may also use XTM One from inside another Filigran product such as OpenCTI or OpenAEV. In those cases it appears as an embedded AI capability — an assistant panel or AI action inside the product where you already work — rather than as a separate destination, while the resources and automations are still managed centrally in XTM One.
Start with the dashboard
If you are not sure where to begin, open the Dashboard first. It is the best place to see recent activity, check what is already in progress, and find the next action you need to take.
Next step
Once you are signed in and comfortable with the layout, move to the Foundations section. Start with Foundations Overview, then continue to Data model before moving into the Dashboard and the rest of the UI chapters.