Two paths to recovery
It always starts with user autonomy; admin approval steps in only when needed, and only to authorize.
Path 1 · Self-serviceGet back in on your own with a recovery code
When you set up 2FA you receive a set of one-time recovery codes. They exist precisely for the day you lose, replace or wipe the phone with your authenticator: no administrator is involved and the principle of exclusive control stays intact.
- 1When you set up 2FA, you store the recovery codes somewhere safe (password manager, vault, printout).
- 2If you lose your TOTP device, at login you choose to use a recovery code instead of the time-based code.
- 3You enter a one-time code: it is consumed and authenticates you. You then re-enroll 2FA on a new device.
Path 2 · Admin approvalRequest an MFA reset with administrator approval
If you no longer have your recovery codes, you open an MFA reset request. An administrator (of the tenant or of the project, according to the ACLs) approves it. The approval authorizes unlocking the second factor: the admin neither sees nor sets your credentials or your 2FA, it only authorizes you to reconfigure it yourself.
- 1You open an MFA reset request. The system prevents duplicate requests for the same user.
- 2An administrator with the permissions defined by the ACLs reviews the request and approves it.
- 3The approval authorizes resetting the second factor, without exposing any credentials.
- 4At your next login you reconfigure 2FA yourself on the new device.