Skip to content

Profile, Security, and Preferences

Customer Portal Profile

Profile is the control center for customer identity data, notifications, privacy, language/theme preferences, and account security.

Profile Information

Users can edit and save:

  • first/last name
  • phone
  • location (country, city, address)
  • company display metadata (name, registration number)

Notification Preferences

Notification settings are split by:

  • channel: email, SMS, push
  • activity type: invoice updates, complaint updates, rating responses, promotions/newsletter

Language and Display Preferences

Users can set:

  • preferred language (en, sw, fr)
  • timezone
  • date format
  • theme mode (light/dark/system)

Privacy Preferences

Privacy controls include:

  • profile visibility (public, contacts, private)
  • rating visibility
  • activity visibility
  • analytics/data-sharing preference

Security Controls

Two-Factor Authentication (2FA)

Built-in 2FA setup is available in the security section.

Password Management

Password changes are delegated to Keycloak account flows.

Passkeys (WebAuthn)

Users can:

  • register a passkey (webauthn-register-passwordless action)
  • use profile/security or the app-side enrollment nudge to start passkey registration
  • use the passkey sign-in option on the login page after registration

Recommended sequence:

  1. open My Profile
  2. open the security section
  3. choose passkey registration
  4. complete the browser/device prompt
  5. use passkey login on the next sign-in

If a passkey-capable device is detected and no passkey is registered, the portal may prompt the user to register one after sign-in.

Active Sessions

Users can:

  • open Keycloak device activity page
  • sign out all sessions from security controls

Account Activity Snapshot

Security view includes a lightweight account activity summary (last login/session timing).

Profile Maintenance Procedure

  1. Open Profile and compare name, phone, organization, location, and address with your current business records.
  2. Correct one section at a time and save it before moving to another section.
  3. Reopen the page or wait for the success message to confirm that the change persisted.
  4. Review notification preferences after changing email, phone, language, or time zone.
  5. Check privacy choices and make sure they match the information you intend other users to see.

Some identity fields can be controlled by the authentication service and may not be editable directly in TCAMS. Use the secure account action or support process when a protected field must change.

Security Hardening Checklist

  • Use a unique password and never share it with a CFA, association user, or support agent.
  • Register a passkey on a device you control and keep a separate recovery method.
  • Enable two-factor authentication where offered and store recovery material securely.
  • Review active sessions after using a shared or unfamiliar device; end sessions you do not recognize.
  • Treat unexpected password-reset, passkey, or login emails as suspicious until you confirm that you initiated them.
  • Sign out when finished on shared equipment and do not allow the browser to save credentials there.

If you lose access to every sign-in method, start account recovery from the official login page. Support can help verify the account state, but should never ask for your password, authenticator code, passkey response, or full payment credentials.