Operator · Users, MFA & Multi-Person Control

Break-Glass Cards

Frame 62 of 107

A single-administrator deployment has no colleague to reset a lost factor — without a plan, a dead phone plus spent recovery codes is unrecoverable. Break-glass is the plan, and its one rule is: generate it before you need it.

Generation produces a k-of-n card set — 2-of-3 for a team, 1-of-1 for a card in a safe. The cards are displayed once; goca stores only a keyed verifier and cannot reprint them. Give one card per holder and store them apart, because any k together reconstruct the authority.

Recovery takes the identity's password and k cards — a stolen card set alone authorizes nothing. Success clears the factor and authorizes one fresh enrollment, never a session. The set is single-use, its use raises a critical mfa.breakglass-used event, and it works from the sign-in screen even during an account lockout — the case it exists for is the one where nobody can sign in.

Even with cards in the safe, two enrolled administrators is the calmer shape: a reset is routine; break-glass is an incident.

Now I can generate break-glass cards before the day I need them.