Appearance
The Password Reset Workflow ensures that a password is reset only after successful identity verification. The same flow applies whether the user resets their own password or an agent assists.
Step 1 - The User Requests a Password Reset
The request may begin in one of the following ways:
The user contacts the helpdesk directly (phone, chat, ticket)
The user reaches an automated helpdesk or IVR menu and selects a password reset option
The user initiates a request from an organizational portal
Step 2 - A Verification Link Is Sent
A helpdesk agent sends the user a secure Verification Portal link (via SMS or email) from the Helpdesk Verifications page; see Sending a Verification Portal Link for the exact steps.
The link takes the user to the Self-Service Portal (SSP) to complete verification.
Step 3 - The User Completes Verification
The user opens the link and completes identity verification in the Self-Service Portal (SSP), which combines silent infrastructure checks with dynamic challenge questions. The outcome (Passed, Failed, Timed Out, or Not Enough Questions) is recorded in the Helpdesk Verifications table.
Step 4 - The Password Is Reset
Once verification passes, the reset is completed in one of the following ways:
Self-service - the user is allowed to reset their own password immediately in the Self-Service Portal, with no agent involved.
Agent sends a reset link - an agent reviews the verification outcome and, if it passed, sends the user a password-reset link using the Actions button in the Verification Summary panel.
Reset through your own policy - an agent completes the reset using the organization's existing password-reset process, outside imper.ai.
If verification does not pass, no reset is offered, and the agent follows internal escalation or remediation procedures.
What Happens After the Reset
The verification record remains available for auditing.
The action is logged.
The user regains access according to organizational policy.
Important Notes
A password cannot be reset without successful verification.
All verification activity is logged for compliance and audit purposes.