#Profile Settings
| Role | Access Level |
|---|---|
| Client Admin | Edit own account profile details in Account, and manage available security/MFA lifecycle actions in Account > Security |
| Client Manager | Edit own account profile details in Account, and manage available security/MFA lifecycle actions in Account > Security |
| Client Staff | Edit own account profile details in Account, and manage available security/MFA lifecycle actions in Account > Security |
| Partner Admin | Edit own account profile details in Settings, and review required operations-managed MFA status |
| Partner User | Edit own account profile details in Settings, and review required operations-managed MFA status |
#Overview
Profile settings let you review and edit the identity and security posture attached to your current portal session.
Client Admin, Client Manager, and Client Staff users manage their own profile in the Account area at /account?section=profile, with security and MFA under Account > Security at /account?section=security. All three customer roles share the same Account shell (a Profile tab and a Security tab).
Partner Admin and Partner User sessions manage their own profile from Settings Profile at /settings?section=profile. That section reuses the same Account Profile form and /api/account/profile contract to edit supported fields, and adds a required, operations-managed, non-editable MFA summary.
Legacy /settings?section=profile links behave differently by role:
- Client Admin legacy links are redirected to
/account?section=profileby the portal middleware (HTTP 307). - Client Manager and Client Staff do not have a Profile section under
/settings;/settings?section=profilereturns a not-found state for those roles. Use/account?section=profileinstead.
Client Admin, Client Manager, Client Staff, Partner Admin, and Partner User can all edit the implemented Account Profile fields that the backend exposes for self-service: first name, last name, mobile number, timezone, and portal language. Email address remains read-only in the profile form; a verified email-change flow handles email updates. The portal does not offer unaudited identity changes.
#Prerequisites
- You are signed in to the AiDial portal. See Signing In for instructions.
- Your current session belongs to an active tenant.
- Client Admin, Client Manager, and Client Staff users use the
/accountshell for self-service profile edits and security actions. Partner Admin and Partner User sessions edit their own profile from/settings?section=profile. - If MFA remediation is required, other protected portal areas remain blocked until the identity-provider setup or verification is completed and the portal security status is refreshed.
#Reviewing Your Profile
For Client Admin, Client Manager, and Client Staff:
- Open Profile from the account menu, or go to
/account?section=profile. - Review and edit the supported Account Profile fields: first name, last name, mobile number, timezone, and portal language.
- Review the read-only email address and email verification badge when one is available. Use the email-change panel to request a verified email update.
- Use Account > Security at
/account?section=securityfor the password, two-factor, recovery-code, active-sessions, notification-centre, and (Client Admin only) recent-activity cards.
For Partner Admin and Partner User:
- Select Settings from the sidebar.
- Open the Profile section at
/settings?section=profile. - Review and edit the supported Account Profile fields: first name, last name, mobile number, timezone, and portal language.
- Review the read-only email address and email verification badge when one is available.
- Review the required operations-managed MFA summary. This summary is read-only; partner MFA is managed through the identity provider and an operations workflow, not from Settings Profile controls. Use Refresh security status (sign in again) after completing MFA setup or verification with the identity provider.
#Account Security Surface (Client Admin, Client Manager, Client Staff)
The Account > Security tab at /account?section=security shows:
- Password - a Change password link to the identity provider's password management when a trusted target is available.
- Two-factor authentication - the current MFA enrollment badge (Enrolled, Not enrolled, or Unknown) and a Manage 2FA link to provider MFA setup/management when a trusted target is available.
- Recovery codes - a Manage recovery codes link plus action-needed prompts to acknowledge that you stored or reviewed provider-issued recovery codes. Acknowledgements are recorded through the portal; raw codes are never stored in the portal.
- Active sessions - the same self-scoped active-sessions panel described in Active Sessions.
- Notifications - your in-app notification centre: updates about calls and portal activity. This card is the notification list, not notification delivery preferences.
- Recent activity - an audit-log preview shown for Client Admin only. Client Manager and Client Staff do not see this card.
All three provider links open the identity provider in a new tab and share the same trusted target. When the portal cannot derive a trusted provider self-service target for the current session, there is no per-row disabled button: the links are omitted and the tab shows a single concise "provider actions unavailable" notice instead of dead ends. Sign in again and refresh your security status; if it remains unavailable, contact your administrator or help@aidial.com.au.
#Ownership Matrix
| Field or Action | Portal Behaviour | Source of Truth |
|---|---|---|
| Display name | Composed from the self-service Account Profile first and last name after save. When both are blank, the backend falls back to the identity-provider full name and then to the email address. Blank or missing values display as Unavailable in the partner Settings summary. | aidial_api account profile endpoint, falling back to identity-provider values |
| Email address | Read-only in the profile form; selectable for copying but not directly edited. Verified email-change requests use the dedicated email-change flow. | Identity provider or account profile source |
| First name, last name, mobile, timezone, and language (all customer and partner roles) | Self-service Account Profile fields saved through the Account BFF with ETag concurrency checks. | aidial_api account profile endpoint |
| Portal role | Read-only security fact. The portal does not offer role changes from Profile. | Server-resolved tenant assignment |
| Allowed factors | Provider-backed read-only security fact, filtered by portal role and tenant policy. Shown as a factor list in the partner Settings Profile summary. | Current MFA policy and identity-provider state |
| Enrolled factors | Provider-backed read-only security fact, shown as a factor list. Neither Account > Security nor the partner Settings Profile summary displays per-factor device metadata. | Identity-provider lookup and session MFA state |
| Partner MFA status | Required, operations-managed, non-editable summary in Settings Profile. | Identity provider, portal security policy, and operations workflow |
| MFA lifecycle actions | Self-service only when the trusted identity-provider action is available for your account state. Client roles manage these in Account > Security; partner Settings Profile does not expose MFA edit controls. | Identity provider and portal security policy |
| Password changes | Not a profile-form action. Use the trusted identity-provider link or administrator-supported recovery path. | Identity provider |
#MFA Actions
Account > Security (Client Admin, Client Manager, Client Staff) shows MFA actions only when the current session and account security state make them available.
| Action | When It Appears | Behaviour |
|---|---|---|
| Change password / Manage 2FA / Manage recovery codes | A trusted provider setup or management URL is available (provider-supplied, or a portal-derived trusted identity-provider URL). | Opens the identity provider in a new tab. Complete the change there, then refresh the security status. |
| Provider actions unavailable | The portal cannot derive a trusted provider action for the current state. | The three provider links are hidden and a single section notice is shown. Refresh your security status after signing in again. If it remains unavailable, contact your administrator. |
| I stored my recovery codes | A new or re-enabled MFA recovery-code set needs acknowledgement. | Records that you stored the recovery codes. This action requires the current lifecycle marker. |
| I reviewed my recovery codes | This session used a recovery code and the portal shows a reminder. | Records that you reviewed provider-issued recovery codes. This action requires the current lifecycle marker and does not store raw codes in the portal. |
When both a reminder and an unacknowledged recovery-code set apply, the reminder takes priority and only its acknowledgement is offered.
Partner Settings Profile does not expose any of these actions. It shows the read-only, operations-managed MFA summary (role, allowed factors, enrolled factors, policy, enrolment, challenge state, and the time the lifecycle status was last refreshed) plus a Refresh security status link that signs you in again.
Neither surface offers self-service enrolment of an SMS one-time code or a passkey, and neither displays passkey device labels or last-used times. When sms_otp or webauthn is permitted for your role and tenant, the factor appears in your allowed and enrolled factor lists only; enrolment itself is completed with the identity provider. SMS one-time codes are additionally restricted to a role allowlist (client_admin / partner_admin) and a per-tenant override that defaults to off.
Other protected portal areas remain blocked while mandatory MFA is not compliant. Complete setup or verification with the provider, then return to the security surface and refresh the security status.
If you lose access to your authenticator, use a provider-issued recovery code during sign-in. If you no longer have recovery codes, contact your organisation administrator or help@aidial.com.au. The profile and security surfaces can show reminders and trusted provider links, but they cannot bypass MFA, reveal one-time codes, or reset your authenticator directly.
#Field Reference
| Field Name | Description | Source and Behaviour |
|---|---|---|
| Display name | Name shown for the current signed-in user | Composed from the self-service Account Profile first and last name after save, falling back to the identity-provider full name and then the email address. Blank or missing values are displayed as Unavailable where a managed summary is used. |
| First name | Account Profile field | Editable at /account?section=profile for client roles and at /settings?section=profile for Partner Admin and Partner User. Changes are saved through /api/account/profile with an If-Match ETag. |
| Last name | Account Profile field | Editable at /account?section=profile for client roles and at /settings?section=profile for Partner Admin and Partner User. Changes are saved through /api/account/profile with an If-Match ETag. |
| Mobile number | Account Profile field | Editable through the Account Profile form; backend validation is surfaced inline when the value is rejected. |
| Timezone | Account Profile field | Editable from the supported timezone list returned to the form: Australia/Sydney, Australia/Brisbane, Australia/Melbourne, and Australia/Perth. |
| Portal language | Account Profile field | Currently limited to English (Australia), en-AU. |
| Email address | Email shown for the current signed-in user | Identity-provider managed. The profile form renders email as read-only and shows an Email verified badge when reported. A verified email-change flow handles updates. |
| Portal role | Server-resolved role for this session | Portal role is a read-only access assignment resolved server-side from the session context. Navigation visibility is not a security boundary. |
| Allowed factors | MFA factors recognised for this session | Derived from MFA state on the session, with supported labels for authenticator app, recovery code, email one-time code, SMS one-time code, and passkey or security key. SMS one-time code and passkey are additionally filtered by role and, for SMS, by a per-tenant override. |
| Enrolled factors | MFA factors reported for your account | Derived from session MFA state and provider lookup. Absence is not treated as editable profile data. |
| Policy | Whether MFA is required or optional for the current role/session | Derived from the session MFA snapshot. The partner Settings Profile summary always displays Required. Client roles are optional by role; any role may still be required by an explicit tenant or user policy. |
| Enrollment | Current MFA enrolment state | Shows enrolled, not enrolled, or unknown. |
| Challenge state | Current MFA challenge state | Shows satisfied, required, failed, or unknown. |
| Lifecycle status last refreshed | Time the MFA lifecycle status was last refreshed | Displayed in your portal locale on the partner Settings Profile summary. |
#Access, Scope, and Runtime Behaviour
The browser uses your signed-in portal session. You do not need to enter or send an API key, and the browser must not send X-API-Key.
Profile details and MFA actions are scoped to the current signed-in user and active tenant. Browser calls go to portal route handlers such as /api/account/profile, /api/account/email-change, /api/settings/profile, /api/settings/profile/mfa-lifecycle, /api/account/security/activity, and /api/auth/sessions; those server-side routes inject the bearer token and call aidial_api. API routes enforce their own auth, CSRF, tenant checks, and route security headers because middleware does not protect /api/**. The recent-activity route is self-scoped and ignores caller-supplied query parameters; it returns a non-enumerating not-found response for every role other than Client Admin.
Account Profile reads and saves profile details through /v1/account/profile. The Account Profile save path (PATCH /api/account/profile) requires an If-Match ETag (returning 428 when it is absent), rejects unsupported fields before calling the API, and refreshes the trusted session context after a successful save so the shell/topbar display name updates. Settings Profile and Account Security read MFA lifecycle state from aidial_api through /v1/portal-mfa-lifecycle.
MFA actions may be rate-limited and require a current trusted identity-provider state. If your tenant, session, or MFA state cannot be verified, the portal blocks the action and asks you to refresh or sign in again.
#Common Issues
| Issue | Resolution |
|---|---|
I am a Client Admin and /settings?section=profile opens Account instead | This is expected. The portal middleware redirects Client Admin legacy Settings Profile links to /account?section=profile. |
I am a Client Manager or Client Staff and /settings?section=profile shows not found | This is expected. Your profile lives in the Account area. Open Profile from the account menu or go to /account?section=profile. |
| I cannot find the Profile section in my Settings sidebar (client roles) | Profile relocated to the Account area for client roles. Use /account?section=profile. Partner Admin and Partner User continue to edit their profile in Settings Profile. |
| Save profile is disabled | Save is only enabled after a supported field changes and the latest Account Profile load returned an ETag. Refresh the profile and try again if the page reports that it could not load the latest values. |
| My Account Profile save says the profile changed elsewhere | The portal reloaded the latest profile after an ETag conflict. Review your local edits, make another change if needed, then save again. |
| I cannot edit my email address directly | Email is read-only in the profile form. Use the email-change panel to request a verified email update. |
| MFA setup is unavailable | Sign in again and refresh the security status. If no trusted provider action appears, use a provider-issued recovery code during sign-in where available, then contact your administrator or help@aidial.com.au if you remain locked out. |
| Other pages stay blocked after MFA setup | Return to the profile or security surface and refresh the security status so the portal can read the latest MFA state. |
| I cannot enrol an SMS one-time code or a passkey from Profile | Neither the Account Security tab nor the partner Settings Profile summary offers self-service enrolment for those factors. Enrol them with the identity provider, then refresh your security status so the factor appears in your enrolled factor list. |
| Passkey device details are not shown | The profile and security surfaces list factor names only. They do not display passkey device labels or last-used times. |
| A recovery-code prompt stays visible | Confirm that you stored or reviewed your provider-issued recovery codes, then use the matching acknowledgement action. If the lifecycle changed elsewhere, refresh the surface. Do not paste recovery-code values into portal support requests. |
| The profile or security surface will not load | Retry the surface. If it still fails, your session, tenant status, or MFA lifecycle state may need administrator attention. |