Enrollment, replacement, and recovery
Before the first sign-in
Alex buys a new security key. Before it can open the staff portal, Cedar Inc. must associate the key's credential with Alex's account. This is enrollment. Without it, a valid signature from the key would tell Cedar Inc. nothing about which account Alex is trying to use.
For a new employee, enrollment can begin through a verified onboarding process. Later additions need suitable proof from the person who already controls the account. Knowing Alex's email address or employee number is not enough to add another way to sign in.
The confirmation depends on the method. An authenticator app can demonstrate that it produces a valid code. A security key returns a registration response that Cedar Inc. validates. Before an email address or phone number becomes a recovery destination, Alex must demonstrate control of it.
Adding and replacing methods
Now Alex replaces a phone while the old one still works. After a fresh authentication check, Alex enrolls the new phone and confirms it can sign in. Only then does Alex remove the old phone. Removing it first could leave Alex without a working method.
A list of enrolled methods helps Alex find the right one to remove. Names and enrollment dates can distinguish a personal security key from an old phone without displaying secret material. A name is just a label, though; it does not prove who currently holds the device.
Alex also needs a backup before something is lost. Depending on the service, that might be another registered key, protected recovery codes, or an assisted recovery route. A backup kept only on the phone Alex might lose will not help.
Cedar Inc. should record method changes and notify Alex through an established channel. A notification may reveal an unexpected change, but the service still has to authorize the change before making it.
When a device is lost
If Alex loses a phone, two things may have changed. Alex might lose a way to sign in, and someone else might now have the phone or a session already open on it. Recovery restores Alex's access. Revocation tells Cedar Inc. to stop accepting a credential that can no longer be trusted.
Removing the lost phone's credential from Alex's account stops future sign-ins with that credential at Cedar Inc. It does not erase a key from the phone or end sessions that are already active. Alex may need to review and end those sessions separately.
If the phone held a synced passkey, removing that credential at Cedar Inc. can stop all synced copies from signing in there. Separately, Alex may need to remove the lost phone from the credential provider's account. These changes act in different places.
Recovery without a shortcut
If Alex loses every enrolled method, Cedar Inc. needs another way to establish that Alex may regain the account. It could use recovery codes issued earlier, a verified recovery channel, or an assisted process with its own checks. Simply knowing the account email address cannot be enough.
A recovery code is a secret that may open the account when the usual methods are unavailable. Alex needs to store it somewhere separate from the device it backs up. Cedar Inc. must limit its use, protect its stored form, retire it after use, and invalidate old codes when a new set is issued.
If support staff help with recovery, they need defined authority and a verification process. The decision should be recorded without storing recovery codes or other secrets. A persuasive caller or an answer to a public personal question cannot replace those checks.
Recovery also needs a route for someone changing phone numbers, without a particular smartphone, or unable to use a biometric check. If that route is temporarily unavailable, the service should say so rather than report that the account was recovered.
A recovery walkthrough
In this fictional example, Alex loses a phone but still has a separately registered backup key.
- Alex opens the Cedar Inc. staff portal through a trusted address and signs in with the backup key.
- The service checks Alex's current authority before allowing a method change.
- Alex removes the lost phone's credential and reviews active sessions. The service records the changes without credential values.
- Alex enrolls a replacement authenticator and confirms it works. Cedar Inc. sends a security notification.
- Alex checks that an independent backup remains available.
If Alex had lost the backup key as well, this sequence could not begin with an ordinary sign-in. Cedar Inc. would need to use its recovery process before allowing anyone to replace a credential.