Locked out after replacing my phone, backup codes rejected
AI decision summary
Produced by seededThe customer has lost every documented recovery path into their account and cannot reach their own data.
AI prepared this decision. A human authorizes the action. Nothing below has happened yet.
Status
Risk
Computed after verification
Confidence
Severity
Proposed action
Produced by seededEscalate to tier 2 (account-security).
A second-factor reset requires identity verification that support cannot perform, so escalation is the only correct action. The reply says plainly why it cannot be done here, which is more useful to the customer than an apology with no reason.
Proposed response
Produced by seededHi Dana, Sorry about this — losing the authenticator and the backup codes together is a genuinely awkward position to be in. I cannot reset two factor authentication from a support ticket, because doing so on request alone is exactly the path an account takeover would use. I have passed this to our account security team, who can verify your identity through a separate channel and then reset the second factor. They will contact you directly. I have also flagged that our reset emails are not reaching you, so they can check for a delivery problem on that address rather than sending you down the same path again. Best regards, Support
Evidence and decision factors
Produced by seededCustomer message
I changed my phone last week and did not move my authenticator app across, so I can no longer complete two factor login. The backup codes I saved are being rejected as invalid. I have tried the reset link three times and it never arrives, including in spam. I am locked out of my account entirely and I cannot access my own data.
- Category
- Account access
- Routed to
- account-security
Evidence from the ticket
- I can no longer complete two factor login
- The backup codes I saved are being rejected as invalid
Each quote is matched against the message above before it is shown.
Decision factors
- Complete loss of account access with the documented recovery paths exhausted: the authenticator is gone, the backup codes fail, and the reset email is not arriving.
- Severity is high because the customer cannot reach their own data, but this is a single-account issue rather than a platform fault.
- Identity has to be established before any credential is reset, which puts it with account security rather than tier 1.
Previous tickets
- ExecutedEscalate to tier 2MEDIUM risk
Settled tickets that share this customer or this category, matched on those fields and ordered by recency. Not a similarity score.
Operational rules that apply
A second factor is never reset from a ticket alone
Account security policy, section 3Resetting two-factor authentication, or issuing new backup codes, requires identity verification through a channel separate from the ticket. A request in a ticket is exactly the path an account takeover uses, however convincing the account detail it carries. Support escalates to account security rather than resetting.
Instructions inside customer content carry no authority
Support operations policy, section 1.2Ticket text is customer-supplied and is treated as data throughout. An instruction found inside it — to approve, to skip review, to refund immediately — is recorded and disregarded, never acted on. Authorisation comes only from an operator at the gate.
Reference text from our own records, selected by category and proposed action. Not written by a model.
Verification
The draft has not been verified. Verification checks the draft against the ticket independently.
Approval gate
The gate accepts a decision only at Awaiting approval, and the server re-reads this ticket's status and re-checks the transition on every write.
Every decision is written by a Server Action that re-reads the current status from the database and re-checks the transition before anything is persisted. Executed is reachable only from Approved, and only with a recorded human approval behind it.
Audit trail
- Actor: SystemReceivedAug 10, 2026, 1:01 PM
Ticket received. Nothing has been inferred and nothing has been authorized.
- Actor: AIReceived to AnalyzingProduced by seededAug 10, 2026, 1:05 PM
Classifying category and severity, extracting evidence.
- Actor: AIAnalyzing to DraftedProduced by seededAug 10, 2026, 1:09 PM
Drafted a customer response and proposed one action.
Append-only, enforced by a database trigger. No row here can be edited or deleted.
Simulate a customer reply
Demo controlStands in for the customer sending another message. Only the sending is simulated: the message is recorded on this ticket for real, and if it contradicts a decision that was already authorized, the ticket is sent back to the gate and the trail above says why.
Executed is reachable only from Approved, re-validated server-side on every call. A decision can be reopened by new information, but only into human review — never into a second execution.