Skip to content
imper.ai

Password Reset Workflow

The Password Reset Workflow ensures that a password is reset only after successful identity verification. The same flow applies whether the user resets their own password or an agent assists.


Step 1 - The User Requests a Password Reset

The request may begin in one of the following ways:

  • The user contacts the helpdesk directly (phone, chat, ticket)

  • The user reaches an automated helpdesk or IVR menu and selects a password reset option

  • The user initiates a request from an organizational portal


A helpdesk agent sends the user a secure Verification Portal link (via SMS or email) from the Helpdesk Verifications page; see Sending a Verification Portal Link for the exact steps.

The link takes the user to the Self-Service Portal (SSP) to complete verification.


Step 3 - The User Completes Verification

The user opens the link and completes identity verification in the Self-Service Portal (SSP), which combines silent infrastructure checks with dynamic challenge questions. The outcome (Passed, Failed, Timed Out, or Not Enough Questions) is recorded in the Helpdesk Verifications table.


Step 4 - The Password Is Reset

Once verification passes, the reset is completed in one of the following ways:

  • Self-service - the user is allowed to reset their own password immediately in the Self-Service Portal, with no agent involved.

  • Agent sends a reset link - an agent reviews the verification outcome and, if it passed, sends the user a password-reset link using the Actions button in the Verification Summary panel.

  • Reset through your own policy - an agent completes the reset using the organization's existing password-reset process, outside imper.ai.

If verification does not pass, no reset is offered, and the agent follows internal escalation or remediation procedures.


What Happens After the Reset

  • The verification record remains available for auditing.

  • The action is logged.

  • The user regains access according to organizational policy.


Important Notes

  • A password cannot be reset without successful verification.

  • All verification activity is logged for compliance and audit purposes.