Skip to content

My profile

My Profile is where you manage your personal experience in XTM One. Unlike Settings, which is shared platform configuration, this page is about your own account.

What you can do here

Use My Profile to:

  • update your account details
  • set your time zone and theme
  • change your password, if you use a local account
  • protect your account with two-factor authentication
  • choose your default chat agent
  • tailor the General Assistant to your needs
  • control your private channel routing
  • review and clear memory
  • check your quotas
  • create API keys
  • manage your personal MCP exposure
  • download and enroll runners on your machines

The main profile tabs

The current profile page is organized into:

  • Profile
  • Channels & Bots
  • Memory
  • Quotas
  • API Keys
  • MCP Endpoint
  • Runners (when the runner subsystem is enabled on your deployment)

Profile tab

The Profile tab contains your personal account information.

You can usually review or update:

  • full name
  • title
  • email address
  • time zone
  • theme
  • authentication method

If you use SSO, the page shows that clearly so you know sign-in is handled by your identity provider.

Password changes

If you use a local account, the Profile tab also includes a password change area.

If you sign in with SSO, password changes are usually managed outside XTM One by your identity provider.

Two-factor authentication

Right below the password area, the Profile tab lets you protect your account with a second factor: a six-digit code from an authenticator app, asked for every time you sign in — after your password, or after your identity provider if you use SSO.

To turn it on:

  1. Select Set up. A QR code appears.
  2. Scan it with your authenticator app — Google Authenticator, Microsoft Authenticator, KeePassXC, 1Password, Bitwarden, or any other. If you cannot scan (for example KeePassXC on a desktop), choose Enter the key manually and type the key it shows.
  3. Type the six-digit code your app displays and select Enable two-factor.

XTM One then shows 10 recovery codes.

Save your recovery codes now

This is the only time they can be displayed. Each one signs you in once, in place of your app, if you lose your phone. Nobody can retrieve them for you afterwards — not even an administrator.

Once enabled, signing in becomes two steps: your password, then the code. If your phone is not to hand, choose Use a recovery code on the code screen.

From the same area you can:

  • Generate new recovery codes — replaces your current set. Requires a code from your app.
  • Disable two-factor — requires both your password and a current code, so neither an unlocked browser nor your phone alone is enough to remove it.

If you lose both your device and your recovery codes, ask an administrator to reset your two-factor enrollment. Your account then signs in with your password alone until you set it up again on a new device.

Works with SSO too

If you sign in through an identity provider, you can still enable two-factor here. XTM One asks for the code after your provider signs you in, so the extra factor applies even when your organisation's identity provider does not enforce one. If your account has no XTM One password, disabling only asks for a code.

General Assistant Tools

The Profile tab also contains your personal General Assistant tool overrides.

This is where you can review or override access to:

  • built-in tools
  • integrations
  • MCP servers
  • custom tools
  • knowledge bases

This matters when you want your own General Assistant experience to differ from the platform default.

You can also reset your personal choices back to the platform default.

Channels & Bots tab

Channels & Bots controls how your own chat routing works.

This tab currently lets you:

  • choose your default web chat agent
  • assign a different agent for your private conversations on supported channels
  • fall back to default routing when you do not want a personal override

If connected channel bots are available, you can set a different direct-message agent for each channel. Group-channel behavior remains governed by the shared admin routing, described in Channels and bots.

Memory tab

Memory shows what XTM One remembers about you.

It is split into two main parts:

  • a Cross-Agent Profile shared across agents
  • per-agent memory for agents you have interacted with

From this tab you can:

  • review consolidated memory
  • inspect recent interactions
  • clear the cross-agent profile
  • clear memory for one specific agent
  • purge all your memory if you want a full reset

This is the best place to check when an agent seems to be remembering something you no longer want it to keep.

Quotas tab

Quotas shows your personal usage against the limits that apply to your account.

In XTM One, this usually focuses on agentic executions. Some other deployments can also show additional quota types.

Use this tab to understand:

  • your current consumption
  • your limit period
  • whether the limit comes from a user rule, group rule, or platform default

API Keys tab

API Keys lets you create personal keys for controlled programmatic access.

From this tab you can:

  • create a named key
  • copy it when it is first shown
  • review existing keys
  • delete a key you no longer need

The page also shows the Platform API endpoint and basic usage guidance. In some non-XTM deployments, an additional LLM proxy section can appear.

MCP Endpoint tab

MCP Endpoint is for users who want to connect external MCP clients (Cursor, Claude Desktop, and others) to XTM One.

From this tab you can:

  • copy your personal MCP endpoint URL
  • review the connection snippet
  • choose which agents are exposed
  • remove agents from that exposed list

If you do not choose a restricted list, the endpoint can default to all eligible visible agents.

The same tab also shows the Platform MCP Servers card (unless an administrator has disabled the feature). Each connected OpenCTI, OpenAEV, or OpenGRC platform gets its own native MCP server (/mcp/opencti, /mcp/openaev, /mcp/opengrc) exposing its business tools, with the endpoint URL, live connection status, and a ready-to-copy client configuration; platforms that are not yet connected appear dimmed as Not connected until they are registered. See Platform MCP servers for the full guide.

When an administrator has enabled it, a Platform Tools MCP Server card appears too. It exposes XTM One's own tools on /mcp/xtm — agent traces, agents, assignments, runs, knowledge bases, prompts, skills, custom tools, integrations, and variables — scoped to what you can already see and manage. It is how you read an agent's traces from Claude Desktop or Cursor and fix its configuration there. The card also offers a downloadable installer package for Claude Code, Claude Desktop, and any Agent Plugins client — with One-click install on, the package already contains the endpoint URL and a freshly created API key, so there is nothing to configure (and the file is then a secret: delete it once installed). See Platform tools MCP server.

Runners tab

Runners appears when the runner subsystem is enabled on your deployment. It is where you download the native runner app for Windows, macOS, or Linux and manage the enrollment keys that connect your machines to XTM One.

From this tab you can:

  • download the installer for each operating system
  • copy a one-line headless install command for servers and fleets (no graphical session needed)
  • create an enrollment key (with optional default labels, capabilities, and permission mode)
  • review and revoke the machines you have enrolled

Once installed and enrolled, a runner lets agents act on that machine - most importantly, capture genuine full-desktop screenshots for audit evidence. See Runners for the full guide.

What to change first

For most customer users, the most useful first changes are:

  • name and title
  • time zone
  • default chat agent
  • General Assistant tool preferences

Next step

The Settings page explains where administrators manage shared platform behavior.