Limit support power
A support agent should not be able to read a recovery secret and approve the same reset alone. Separate request, verification, approval, and completion where the risk calls for it. Use a sandbox account to test a caller who knows public facts but cannot reach a trusted device. Record how the team handles an urgent case without bypassing the audit trail. Send a notice to a channel that existed before the recovery request.
Test cases and proof
| Case | Expected result | Proof to keep |
|---|---|---|
| Caller knows public account facts | Do not reset account from those facts | Support record |
| Agent overrides recovery hold | Require second approval under the override policy | Approval trail |
| Recovery completes | Notify trusted channel | Delivery record |
Synthetic example
A caller knows a customer’s name, address, and recent public social post. Those facts must not let an agent enroll a new device. Test the staff path for approval, recorded reason, and notice sent to a trusted channel.
Evidence to keep
Use a scripted support exercise with a test account. Give the caller only public facts first, then add one verified factor at a time. Record which step unlocks the reset and who approves it. If an agent can bypass the normal path, capture the reason field and second approver. Keep call recordings and personal details under the firm’s data policy.
Try a support request immediately after a new phone number or email is added. Recent contact changes may make those channels poor recovery proof. The staff workflow should surface that history and route the case to a stronger check. Record the case outcome and customer notice.
Make override power visible
Support needs a way to help a real customer who lost every device. That path should not let one agent add a trusted phone based only on public facts. Give each exception an owner, reason, second approval when required, and expiry for any temporary hold. Record the old channel used for notice. In a test, the caller may know a recent transaction amount from a leaked receipt; that is still knowledge, not control of a trusted factor. Check whether the support tool exposes more private data than the agent needs to make the decision.
Related reading
Why these checks matter
NIST account recovery guidance calls for proof and notice. OWASP’s authorization guide says staff actions need their own permission checks. A support agent’s access to an account screen is not the same as authority to enroll a device. The scripted test records each approval and the old channel that receives notice.
Define the full-loss recovery route
Use synthetic account A-101 with no usable device, email, or phone factor. Public name, address, and a known payment amount must not be the complete proof. Run the firm’s accepted reproofing or documented recovery path and show that a legitimate customer can finish it. NIST recovery rules depend on the account’s assurance levels; second approval and a transfer hold are product controls to set from risk, not a universal rule for every support ticket.
For a high-risk override fixture, name maker S1 and reviewer S2. S1 records the evidence types and requested authenticator change. S2 approves that exact case version. Change the recovery address after approval and attempt completion. The tool must reject the changed version until it is reviewed again. Being allowed to open an account screen is not authority to bind a credential.
Close drafts and handle failed notice
Deny one impersonation attempt, then inspect the desk tool for draft resets, pending device enrollment, temporary tokens, and later callbacks. A second agent must not finish the denied case from stale state. Cancelled and expired cases should leave no active binding code. Record state changes and actors without copying identity documents into broad ticket notes.
Attempt notice on preexisting channels. If all are unavailable, record failed delivery and follow the reviewed recovery policy; do not invent a trusted new channel from the caller’s latest address. Test a legitimate exception and its approval record. Keep case ID, evidence types, version, approver, new credential ID, notice outcome, and session changes. NIST’s account recovery section covers recovery methods and notices.