Account recovery, MFA, and signed-in device safety
Recover access and manage authentication safely without exposing passwords, MFA secrets, recovery codes, or active sessions to PMA staff or other organization members.
Before you begin
- Access to the verified account email whenever possible.
- Your authenticator or recovery codes when MFA is enabled.
- A trusted device and network for sensitive account changes.
Interface walkthrough
These annotated interface maps describe the current PMA controls. They do not replace a real record review in your workspace.
Sends a time-limited recovery flow without confirming arbitrary account details to another visitor.
Enrolls an authenticator, records assurance level, and provides controls for other signed-in sessions.
Shows important changes such as password reset, email verification, MFA enrollment, and session revocation.
Step-by-step workflow
Request recovery from the sign-in page
Enter the account email and follow the message delivered to that inbox. PMA uses a generic response so account existence is not exposed.
Choose a new unique password
Do not reuse a password from another service. PMA staff will never ask you to send it.
Restore or enroll MFA
Use your authenticator or a stored recovery code. Platform-level Control Vault access requires an elevated AAL2 session.
Review signed-in sessions
Revoke devices you do not recognize and sign out other sessions after suspected compromise.
Contact support for controlled assistance
Support may verify account ownership and explain recovery steps, but cannot retrieve your password, authenticator seed, or recovery codes.
Expected result
The account owner regains access through a time-limited, auditable process and can verify MFA and session state without disclosing authentication secrets.
Safety boundaries
- PMA never displays stored passwords because it does not retain them in readable form.
- Recovery messages and codes must not be forwarded or pasted into support cases.
- Email changes require verification and do not silently transfer organization ownership.
- Repeated recovery requests are rate-limited.
- Platform roles require stronger authorization than ordinary organization membership.
Troubleshooting
The recovery email has not arrived
Check spam and confirm the address. Wait for the cooldown before requesting another message, then contact support if delivery continues to fail.
I lost my authenticator and recovery codes
Contact support from the verified email. Recovery will require controlled identity review and will not be completed by sharing passwords or secret keys.
I see an unknown session
Revoke it, change your password, confirm MFA, and create a security support case with the approximate time and device information.