Project Mad AdderHelp Centre
All help articles
Operations & safetyCurrent Beta guidance

Account recovery, MFA, and signed-in device safety

Recover access and manage authentication safely without exposing passwords, MFA secrets, recovery codes, or active sessions to PMA staff or other organization members.

About 13 minutesessential

Before you begin

  • Access to the verified account email whenever possible.
  • Your authenticator or recovery codes when MFA is enabled.
  • A trusted device and network for sensitive account changes.

Interface walkthrough

These annotated interface maps describe the current PMA controls. They do not replace a real record review in your workspace.

1Sign-in recovery
Look for: Forgot password

Sends a time-limited recovery flow without confirming arbitrary account details to another visitor.

2Security settings
Look for: MFA and sessions

Enrolls an authenticator, records assurance level, and provides controls for other signed-in sessions.

3Security history
Look for: Recent account events

Shows important changes such as password reset, email verification, MFA enrollment, and session revocation.

Step-by-step workflow

1

Request recovery from the sign-in page

Enter the account email and follow the message delivered to that inbox. PMA uses a generic response so account existence is not exposed.

2

Choose a new unique password

Do not reuse a password from another service. PMA staff will never ask you to send it.

3

Restore or enroll MFA

Use your authenticator or a stored recovery code. Platform-level Control Vault access requires an elevated AAL2 session.

4

Review signed-in sessions

Revoke devices you do not recognize and sign out other sessions after suspected compromise.

5

Contact support for controlled assistance

Support may verify account ownership and explain recovery steps, but cannot retrieve your password, authenticator seed, or recovery codes.

Expected result

The account owner regains access through a time-limited, auditable process and can verify MFA and session state without disclosing authentication secrets.

Safety boundaries

  • PMA never displays stored passwords because it does not retain them in readable form.
  • Recovery messages and codes must not be forwarded or pasted into support cases.
  • Email changes require verification and do not silently transfer organization ownership.
  • Repeated recovery requests are rate-limited.
  • Platform roles require stronger authorization than ordinary organization membership.

Troubleshooting

The recovery email has not arrived

Check spam and confirm the address. Wait for the cooldown before requesting another message, then contact support if delivery continues to fail.

I lost my authenticator and recovery codes

Contact support from the verified email. Recovery will require controlled identity review and will not be completed by sharing passwords or secret keys.

I see an unknown session

Revoke it, change your password, confirm MFA, and create a security support case with the approximate time and device information.

Related articles