#Profile Settings

12 min read
RoleAccess Level
Client AdminEdit own account profile details in Account, and manage available security/MFA lifecycle actions in Account > Security
Client ManagerEdit own account profile details in Account, and manage available security/MFA lifecycle actions in Account > Security
Client StaffEdit own account profile details in Account, and manage available security/MFA lifecycle actions in Account > Security
Partner AdminEdit own account profile details in Settings, and review required operations-managed MFA status
Partner UserEdit own account profile details in Settings, and review required operations-managed MFA status

#Overview

Profile settings let you review and edit the identity and security posture attached to your current portal session.

Client Admin, Client Manager, and Client Staff users manage their own profile in the Account area at /account?section=profile, with security and MFA under Account > Security at /account?section=security. All three customer roles share the same Account shell (a Profile tab and a Security tab).

Partner Admin and Partner User sessions manage their own profile from Settings Profile at /settings?section=profile. That section reuses the same Account Profile form and /api/account/profile contract to edit supported fields, and adds a required, operations-managed, non-editable MFA summary.

Legacy /settings?section=profile links behave differently by role:

  • Client Admin legacy links are redirected to /account?section=profile by the portal middleware (HTTP 307).
  • Client Manager and Client Staff do not have a Profile section under /settings; /settings?section=profile returns a not-found state for those roles. Use /account?section=profile instead.

Client Admin, Client Manager, Client Staff, Partner Admin, and Partner User can all edit the implemented Account Profile fields that the backend exposes for self-service: first name, last name, mobile number, timezone, and portal language. Email address remains read-only in the profile form; a verified email-change flow handles email updates. The portal does not offer unaudited identity changes.

#Prerequisites

  • You are signed in to the AiDial portal. See Signing In for instructions.
  • Your current session belongs to an active tenant.
  • Client Admin, Client Manager, and Client Staff users use the /account shell for self-service profile edits and security actions. Partner Admin and Partner User sessions edit their own profile from /settings?section=profile.
  • If MFA remediation is required, other protected portal areas remain blocked until the identity-provider setup or verification is completed and the portal security status is refreshed.

#Reviewing Your Profile

For Client Admin, Client Manager, and Client Staff:

  1. Open Profile from the account menu, or go to /account?section=profile.
  2. Review and edit the supported Account Profile fields: first name, last name, mobile number, timezone, and portal language.
  3. Review the read-only email address and email verification badge when one is available. Use the email-change panel to request a verified email update.
  4. Use Account > Security at /account?section=security for the password, two-factor, recovery-code, active-sessions, notification-centre, and (Client Admin only) recent-activity cards.

For Partner Admin and Partner User:

  1. Select Settings from the sidebar.
  2. Open the Profile section at /settings?section=profile.
  3. Review and edit the supported Account Profile fields: first name, last name, mobile number, timezone, and portal language.
  4. Review the read-only email address and email verification badge when one is available.
  5. Review the required operations-managed MFA summary. This summary is read-only; partner MFA is managed through the identity provider and an operations workflow, not from Settings Profile controls. Use Refresh security status (sign in again) after completing MFA setup or verification with the identity provider.

#Account Security Surface (Client Admin, Client Manager, Client Staff)

The Account > Security tab at /account?section=security shows:

  • Password - a Change password link to the identity provider's password management when a trusted target is available.
  • Two-factor authentication - the current MFA enrollment badge (Enrolled, Not enrolled, or Unknown) and a Manage 2FA link to provider MFA setup/management when a trusted target is available.
  • Recovery codes - a Manage recovery codes link plus action-needed prompts to acknowledge that you stored or reviewed provider-issued recovery codes. Acknowledgements are recorded through the portal; raw codes are never stored in the portal.
  • Active sessions - the same self-scoped active-sessions panel described in Active Sessions.
  • Notifications - your in-app notification centre: updates about calls and portal activity. This card is the notification list, not notification delivery preferences.
  • Recent activity - an audit-log preview shown for Client Admin only. Client Manager and Client Staff do not see this card.

All three provider links open the identity provider in a new tab and share the same trusted target. When the portal cannot derive a trusted provider self-service target for the current session, there is no per-row disabled button: the links are omitted and the tab shows a single concise "provider actions unavailable" notice instead of dead ends. Sign in again and refresh your security status; if it remains unavailable, contact your administrator or help@aidial.com.au.

#Ownership Matrix

Field or ActionPortal BehaviourSource of Truth
Display nameComposed from the self-service Account Profile first and last name after save. When both are blank, the backend falls back to the identity-provider full name and then to the email address. Blank or missing values display as Unavailable in the partner Settings summary.aidial_api account profile endpoint, falling back to identity-provider values
Email addressRead-only in the profile form; selectable for copying but not directly edited. Verified email-change requests use the dedicated email-change flow.Identity provider or account profile source
First name, last name, mobile, timezone, and language (all customer and partner roles)Self-service Account Profile fields saved through the Account BFF with ETag concurrency checks.aidial_api account profile endpoint
Portal roleRead-only security fact. The portal does not offer role changes from Profile.Server-resolved tenant assignment
Allowed factorsProvider-backed read-only security fact, filtered by portal role and tenant policy. Shown as a factor list in the partner Settings Profile summary.Current MFA policy and identity-provider state
Enrolled factorsProvider-backed read-only security fact, shown as a factor list. Neither Account > Security nor the partner Settings Profile summary displays per-factor device metadata.Identity-provider lookup and session MFA state
Partner MFA statusRequired, operations-managed, non-editable summary in Settings Profile.Identity provider, portal security policy, and operations workflow
MFA lifecycle actionsSelf-service only when the trusted identity-provider action is available for your account state. Client roles manage these in Account > Security; partner Settings Profile does not expose MFA edit controls.Identity provider and portal security policy
Password changesNot a profile-form action. Use the trusted identity-provider link or administrator-supported recovery path.Identity provider

#MFA Actions

Account > Security (Client Admin, Client Manager, Client Staff) shows MFA actions only when the current session and account security state make them available.

ActionWhen It AppearsBehaviour
Change password / Manage 2FA / Manage recovery codesA trusted provider setup or management URL is available (provider-supplied, or the portal-derived trusted Zitadel URL).Opens the identity provider in a new tab. Complete the change there, then refresh the security status.
Provider actions unavailableThe portal cannot derive a trusted provider action for the current state.The three provider links are hidden and a single section notice is shown. Refresh your security status after signing in again. If it remains unavailable, contact your administrator.
I stored my recovery codesA new or re-enabled MFA recovery-code set needs acknowledgement.Records that you stored the recovery codes. This action requires the current lifecycle marker.
I reviewed my recovery codesThis session used a recovery code and the portal shows a reminder.Records that you reviewed provider-issued recovery codes. This action requires the current lifecycle marker and does not store raw codes in the portal.

When both a reminder and an unacknowledged recovery-code set apply, the reminder takes priority and only its acknowledgement is offered.

Partner Settings Profile does not expose any of these actions. It shows the read-only, operations-managed MFA summary (role, allowed factors, enrolled factors, policy, enrolment, challenge state, and the time the lifecycle status was last refreshed) plus a Refresh security status link that signs you in again.

Neither surface offers self-service enrolment of an SMS one-time code or a passkey, and neither displays passkey device labels or last-used times. When sms_otp or webauthn is permitted for your role and tenant, the factor appears in your allowed and enrolled factor lists only; enrolment itself is completed with the identity provider. SMS one-time codes are additionally restricted to a role allowlist (client_admin / partner_admin) and a per-tenant override that defaults to off.

Other protected portal areas remain blocked while mandatory MFA is not compliant. Complete setup or verification with the provider, then return to the security surface and refresh the security status.

If you lose access to your authenticator, use a provider-issued recovery code during sign-in. If you no longer have recovery codes, contact your organisation administrator or help@aidial.com.au. The profile and security surfaces can show reminders and trusted provider links, but they cannot bypass MFA, reveal one-time codes, or reset your authenticator directly.

#Field Reference

Field NameDescriptionSource and Behaviour
Display nameName shown for the current signed-in userComposed from the self-service Account Profile first and last name after save, falling back to the identity-provider full name and then the email address. Blank or missing values are displayed as Unavailable where a managed summary is used.
First nameAccount Profile fieldEditable at /account?section=profile for client roles and at /settings?section=profile for Partner Admin and Partner User. Changes are saved through /api/account/profile with an If-Match ETag.
Last nameAccount Profile fieldEditable at /account?section=profile for client roles and at /settings?section=profile for Partner Admin and Partner User. Changes are saved through /api/account/profile with an If-Match ETag.
Mobile numberAccount Profile fieldEditable through the Account Profile form; backend validation is surfaced inline when the value is rejected.
TimezoneAccount Profile fieldEditable from the supported timezone list returned to the form: Australia/Sydney, Australia/Brisbane, Australia/Melbourne, and Australia/Perth.
Portal languageAccount Profile fieldCurrently limited to English (Australia), en-AU.
Email addressEmail shown for the current signed-in userIdentity-provider managed. The profile form renders email as read-only and shows an Email verified badge when reported. A verified email-change flow handles updates.
Portal roleServer-resolved role for this sessionPortal role is a read-only access assignment resolved server-side from the session context. Navigation visibility is not a security boundary.
Allowed factorsMFA factors recognised for this sessionDerived from MFA state on the session, with supported labels for authenticator app, recovery code, email one-time code, SMS one-time code, and passkey or security key. SMS one-time code and passkey are additionally filtered by role and, for SMS, by a per-tenant override.
Enrolled factorsMFA factors reported for your accountDerived from session MFA state and provider lookup. Absence is not treated as editable profile data.
PolicyWhether MFA is required or optional for the current role/sessionDerived from the session MFA snapshot. The partner Settings Profile summary always displays Required. Client roles are optional by role; any role may still be required by an explicit tenant or user policy.
EnrollmentCurrent MFA enrolment stateShows enrolled, not enrolled, or unknown.
Challenge stateCurrent MFA challenge stateShows satisfied, required, failed, or unknown.
Lifecycle status last refreshedTime the MFA lifecycle status was last refreshedDisplayed in your portal locale on the partner Settings Profile summary.

#Access, Scope, and Runtime Behaviour

The browser uses your signed-in portal session. You do not need to enter or send an API key, and the browser must not send X-API-Key.

Profile details and MFA actions are scoped to the current signed-in user and active tenant. Browser calls go to portal route handlers such as /api/account/profile, /api/account/email-change, /api/settings/profile, /api/settings/profile/mfa-lifecycle, /api/account/security/activity, and /api/auth/sessions; those server-side routes inject the bearer token and call aidial_api. API routes enforce their own auth, CSRF, tenant checks, and route security headers because middleware does not protect /api/**. The recent-activity route is self-scoped and ignores caller-supplied query parameters; it returns a non-enumerating not-found response for every role other than Client Admin.

Account Profile reads and saves profile details through /v1/account/profile. The Account Profile save path (PATCH /api/account/profile) requires an If-Match ETag (returning 428 when it is absent), rejects unsupported fields before calling the API, and refreshes the trusted session context after a successful save so the shell/topbar display name updates. Settings Profile and Account Security read MFA lifecycle state from aidial_api through /v1/portal-mfa-lifecycle.

MFA actions may be rate-limited and require a current trusted identity-provider state. If your tenant, session, or MFA state cannot be verified, the portal blocks the action and asks you to refresh or sign in again.

#Common Issues

IssueResolution
I am a Client Admin and /settings?section=profile opens Account insteadThis is expected. The portal middleware redirects Client Admin legacy Settings Profile links to /account?section=profile.
I am a Client Manager or Client Staff and /settings?section=profile shows not foundThis is expected. Your profile lives in the Account area. Open Profile from the account menu or go to /account?section=profile.
I cannot find the Profile section in my Settings sidebar (client roles)Profile relocated to the Account area for client roles. Use /account?section=profile. Partner Admin and Partner User continue to edit their profile in Settings Profile.
Save profile is disabledSave is only enabled after a supported field changes and the latest Account Profile load returned an ETag. Refresh the profile and try again if the page reports that it could not load the latest values.
My Account Profile save says the profile changed elsewhereThe portal reloaded the latest profile after an ETag conflict. Review your local edits, make another change if needed, then save again.
I cannot edit my email address directlyEmail is read-only in the profile form. Use the email-change panel to request a verified email update.
MFA setup is unavailableSign in again and refresh the security status. If no trusted provider action appears, use a provider-issued recovery code during sign-in where available, then contact your administrator or help@aidial.com.au if you remain locked out.
Other pages stay blocked after MFA setupReturn to the profile or security surface and refresh the security status so the portal can read the latest MFA state.
I cannot enrol an SMS one-time code or a passkey from ProfileNeither the Account Security tab nor the partner Settings Profile summary offers self-service enrolment for those factors. Enrol them with the identity provider, then refresh your security status so the factor appears in your enrolled factor list.
Passkey device details are not shownThe profile and security surfaces list factor names only. They do not display passkey device labels or last-used times.
A recovery-code prompt stays visibleConfirm that you stored or reviewed your provider-issued recovery codes, then use the matching acknowledgement action. If the lifecycle changed elsewhere, refresh the surface. Do not paste recovery-code values into portal support requests.
The profile or security surface will not loadRetry the surface. If it still fails, your session, tenant status, or MFA lifecycle state may need administrator attention.