Your preparation
0 of 0 safeguards readyMake the next decision with evidence
Recover the vault through legitimate methods, protect still-open sessions, and restore critical access without creating an insecure shadow password list.
Capture before evidence disappears
- Record account email, plan, organization, administrators, recovery policy, trusted devices, emergency access, last sync, and provider case numbers.
- Preserve sign-in, device, recovery, administrator, export, item-change, and policy events from any open trusted session.
- List time-critical credentials, domains, banking, cloud, identity, backup, and customer systems whose recovery depends on the vault.
Decisions that change the response
| Question | Act when | Action |
|---|---|---|
| Keep an open session online? | It may be the only legitimate path to export or add a recovery factor. | Isolate and power it; do not sign out, update, or clear storage until the recovery plan is ready. |
| Reset the account? | The provider confirms reset consequences, including possible vault deletion. | Export or recover critical records first when possible; document items that must be reissued. |
Proof that recovery worked
- Known administrators can unlock and sync the intended vault from two independent devices.
- Critical accounts have verified current credentials and no emergency plaintext copies remain.
- Recovery methods, trusted devices, members, collections, and audit events match the approved inventory.
Controls to put in place
- Keep two organization administrators with separate devices and tested provider recovery.
- Store the master credential and emergency instructions through a secure offline succession process.
- Test encrypted exports and restoration without weakening everyday vault security.
Assume the primary user and device are unavailable. A second administrator must recover a test vault, retrieve three critical records, rotate one credential, and document the process.
Use provider support and business continuity or legal authority when organization ownership, a deceased or unavailable owner, billing, or destructive account reset is involved.
What this means
You may be unable to reach the credentials needed to operate or recover the business. Treat an unexpected lockout as a possible account compromise until the provider confirms otherwise.
Warning signs
- The master password, passkey, or recovery method is rejected.
- Every device is signed out or the vault is unexpectedly empty.
- The provider reports a suspension, outage, or ownership change.
- A recovery email or security setting changed without approval.
Recover now
First 15 minutes
- Check the provider status page from a trusted device. Separate an outage from an account-specific problem.
- Use the documented recovery path. Do not keep guessing and trigger a longer lockout.
- Open the offline emergency kit. Use only the minimum credentials needed to keep critical services running.
- Secure the vault’s email account. Review sessions, forwarding, recovery methods, and recent changes.
Today
- Contact official support with the account ID and proof of ownership.
- If compromise is possible, rotate the most powerful credentials after regaining control.
- Export a fresh encrypted backup and verify that it contains the expected items.
- Record which operations stopped and which credentials were unavailable.
Verify recovery
- Two authorized people can open the correct vault.
- Unknown sessions, devices, and recovery methods are removed.
- Emergency credentials work and exposed credentials have been replaced.
- A fresh offline export can be opened.
Prepare now
Access
- Two named administrators have separate accounts and tested recovery methods.
- The vault email uses independent recovery credentials and phishing-resistant MFA.
Backups and evidence
- A recent encrypted export is stored offline with its decryption instructions.
- Break-glass credentials for domain, email, cloud, code, and payments are available outside the vault.
Contacts and ownership
- Provider support details, account ID, and billing proof are recorded offline.
Practice
- A second person has completed a vault-recovery drill without the founder.
Common mistakes
- Storing every recovery method inside the same vault. The lockout then becomes circular.
- Sharing one login. It removes accountability and creates one failure point.
- Rotating everything before confirming compromise. Unmapped changes can cause a second outage.