Support desk recovery
Support desk recovery
Last verified: 2026-06-30
Support can help a user recover access without collecting secrets. Treat recovery as an account-ownership decision first, then use only audited Awthy admin actions to reset factors.
Safe recovery workflow
- Open the user's account-security status before taking action.
- Verify the caller through the store's approved identity checks without asking for passwords, authenticator secrets, raw recovery codes, private keys, payment-card data, government documents, or recovery-code screenshots.
- Record only the minimum recovery decision details:
- ticket or reference ID.
- reason category.
- selected identity-check outcomes.
- support actor.
- timestamp.
- action taken.
- Avoid free-text personal data. Use categories and checkbox outcomes where possible, and redact accidental sensitive detail before retaining notes.
- Warn the requester if email recovery has not been tested. Do not imply email recovery is ready until delivery has been verified.
- Reset factors only through audited administrator actions. Do not bypass password checks, share recovery codes, or ask the user to reveal current secrets.
- For administrators and shop managers, require higher-risk reset approval before support resets factors.
Hub install ownership conflicts
Hub reclaim conflicts are ownership decisions, not password-reset problems. If a site is already active under a different Hub account, collect only non-secret evidence such as the site host, selected license reference, account email, and visible non-secret error code. Do not collect claim codes, Hub cookies, install secrets, Google refresh tokens, or Custd credentials. V1 has no self-service transfer path; support must verify ownership before any server-side recovery or transfer.
Evidence Awthy notes must not contain
Awthy recovery notes must not store:
- passwords.
- raw recovery codes or screenshots of recovery codes.
- authenticator secrets, QR codes, or one-time passwords.
- government documents.
- payment-card data.
- private keys.
- raw security logs copied from another system.
Use the external ticket reference for broader context when the store's support system has an approved retention and privacy process.
Access and retention boundary
Recovery-case storage is not shipped yet. Before Awthy stores recovery cases, the implementation must define:
- the documented support or administrator capability required to view and update cases.
- retention rules for recovery notes and audit history.
- redaction behavior for accidental sensitive input.
- audit events for case creation, update, reset action, approval, and denial.
Until that storage exists, keep detailed support notes in the store's approved support system and store only the minimum Awthy-safe recovery decision details listed above.