Recovery Operator
Authority view of TapSign lost-device recoveries for this workspace. Approve or reject a recovery case — the user's identity only rebinds to a new device after the witness quorum, this authority approval, and the cooling-off period. Items are keyed by opaque reference; no citizen PII is stored here.
A caller claims to be a customer? Ask your security questions, then push a live check to their phone. You pass your own TapSign step-up first; then only the customer's hardware + Face ID can approve it — stolen credentials and deepfakes can't.
Recovery cases
No recovery cases for this filter.
Identity bindings
0 devices connectedCreated automatically when a customer enables TapSign — one binding per device, activated only by the device's hardware key. Keyed by opaque reference; no name or device id is searchable.
No identity bindings yet — they appear here as customers enable TapSign.