AccountsPublic guide
Recover account access
Use the identity provider’s verified recovery flow while keeping password choice and recovery codes in the account holder’s control.
Purpose
Use the identity provider’s verified recovery flow while keeping password choice and recovery codes in the account holder’s control.
Obedience Cloud is the shared identity and tenant-control surface. It does not turn a platform role into a customer workspace role or a corporate owner, and it never exposes readable passwords or authentication-factor secrets.
Checks before action
- The recovery request is for the correct primary email.
- The user controls the trusted recovery channel.
- Support has a named case if operational help is needed.
Safe process
- Use the canonical hostStart on cloud.obedience.global or the approved obedience.cloud entry and confirm the secure browser origin before entering account information.
- Verify scope and authorityFor recover account access, confirm the account, organisation, role and customer case or contract reference before continuing.
- Complete the bounded actionUse the narrow control provided. Elevated operations require personal 2FA, exact-origin requests, unique request identifiers and durable audit availability.
- Review the resultConfirm provider-authoritative state, record the outcome and route any inconsistency to support without repeating a high-impact request blindly.
Expected records
- Recovery request and provider outcome.
- Session revocation where compromise is suspected.
- Case notes without credential content.
Security boundary
- Administrators can lock an account, revoke sessions or start a bounded support flow; they cannot read or choose the user’s password.
- A support actor session is time-limited, labelled, auditable and blocked from non-read HTTP methods.
- Tenant metadata is validated server-side and cannot contain executable JavaScript, secret credentials or hidden role elevation.
Did this guide help?
Only your answer, guide slug and version are recorded.