Skip to content
Console

Profile and Security

Profile is your account and security center.

Use Profile for personal security questions. Use Audit for account trail, session history, and a support-safe history packet. Use Billing for plan limits, Hubs for hub setup, Clients and Connections for setup links and connection files, and Permissions for access.

  • two-step sign-in blocks a sensitive action;
  • setup link or connection file access is blocked;
  • recovery codes are missing;
  • an active browser looks unfamiliar;
  • account security needs review before you continue setup.
Security question First check
Two-step sign-in blocks an action Confirm the authenticator app and recovery codes.
Setup material access is blocked Review two-step sign-in before returning to Connections.
An active browser looks unfamiliar Remove old sessions before continuing setup.
You need account trail or session history Open Audit before asking support.
The question is about plan limits Open Billing instead of changing Profile.
Profile page showing name, two-step sign-in, recovery codes, active browsers, and plan summary.
Profile owns your personal settings and security. Use it for two-step sign-in, recovery codes, active browsers, avatar, and account safety checks.

Name and avatar

Set a display name, choose an avatar style, and keep your profile readable for teammates.

Two-step sign-in

Enable an authenticator app, generate recovery codes, and protect private setup material.

Current devices

Review active browsers, remove old sessions, and set how long an idle browser stays signed in.

Plan summary

See hub, client, permissions, daily limits, hub address, listing, and help details.

Account data

Download a machine-readable copy of your retained account data before deleting the account.

Two-step sign-in protects sensitive account actions, setup links, and private connection files. When required, your account may be limited to security settings until it is set up.

Keep recovery codes somewhere safe outside Thalovant. Each code works once when the authenticator app is unavailable.

Use active browser controls to:

  • identify the current browser;
  • remove old sessions;
  • remove every other session;
  • set a shorter or longer idle sign-out time.

Use Audit when you need to compare session history or export safe support context. Use Profile when you need to remove sessions or change security settings.

Choose Download account data to create a JSON file containing your profile, safe resource inventory, retained memory, API-token metadata, approved browser origins, and session metadata. The export includes memory content because it is your account copy.

The export never includes passwords or hashes, authenticator secrets, recovery codes, API-token hashes, setup credentials, private runtime specifications, or payment-provider identifiers. Keep the file private and inspect it before sharing any part of it.

Account resources remain until you delete them or delete the account. Memory remains under your control until deletion, expiry, or account deletion. Session records remain through expiry, revocation, and operational cleanup. Account deletion erases identity-linked analytics and audit traces transactionally; one unlinkable deletion marker and non-identifying aggregates may remain.

Because setup links and client connection files behave like passwords, check Profile first when access is blocked or sensitive:

  1. Confirm two-step sign-in is enabled and working.
  2. Confirm recovery codes are stored safely.
  3. Remove browser sessions you no longer recognize.
  4. Return to Connections and get setup material only when you are ready to place it with the connecting app or device.

Download and inspect your account export before deletion if you want a copy. Account deletion cannot be undone: it removes the sign-in, revokes sessions, and erases linked resources and identity-linked telemetry. Do not use account actions to fix a hub or client issue. Those issues belong on Hubs, Clients, Permissions, Skills, Dashboard, or Live Map.

Profile is ready when:

  • your name and avatar are recognizable to teammates;
  • two-step sign-in is enabled when required;
  • recovery codes are stored somewhere safe;
  • old browser sessions are removed;
  • an account export has been downloaded and stored privately when needed;
  • Audit has been checked when session history or support evidence matters;
  • you know whether the next question belongs in Profile or another page.