Skip to main content

Prepare and use emergency access

Who this is for

Tenant administrators, owners, and security teams responsible for SSO continuity.

Goal

Prepare offline recovery codes before enabling SSO-only login, and use one safely during an identity-provider outage.

Prereqs

  • Your identity is an active Owlie administrator or owner.
  • You can complete a fresh primary-authentication check.
  • You have a secure offline location that is separate from your SSO account and device.

Success criteria

  • At least two distinct administrators each have their own offline recovery kit.
  • Tenant SettingsAuthentication reports at least one recovery-ready administrator.
  • During an outage, an administrator can restore Secure Password login and then sign in normally.

How emergency access works

Owlie recovery codes are personal, identity-bound, and single-use. A code can only be used while its owner is still an active administrator or owner.

Redeeming a code does not sign anyone in or open the dashboard. It starts a ten-minute recovery flow that can only:

  1. create a new Secure Password for the code's owner; and
  2. add Secure Password to the tenant's allowed login methods without removing SSO.

Afterward, the administrator signs in normally with the new credential. Owlie records recovery activity in the audit log and notifies active administrators when recovery starts and completes.

Use two distinct administrators. Each administrator should generate their own three-code kit and store it offline in a different secure location. Multiple kits or codes held by one person do not protect against that person being unavailable.

Owlie blocks SSO-only login when no administrator is recovery-ready. It allows one recovery-ready administrator but warns that two are recommended.

Generate and store a recovery kit

  1. Sign in as the administrator who will own the codes.
  2. Open the account menu from your profile image and select My Settings.
  3. Select Security, then Emergency recovery.
  4. Select Generate codes.
  5. In the confirmation dialog, select Continue.
  6. Use Copy or Download and move the codes to your approved offline store.
  7. Select I stored these codes somewhere safe and separate from my SSO account.
  8. Select Done.

You should see 3 codes stored in the Emergency recovery card. Repeat these steps while signed in as a second administrator.

warning

Owlie displays a kit only once. Selecting Replace codes immediately invalidates every unused code from the previous kit.

Use emergency access during an SSO outage

  1. Open your tenant's Owlie login page.
  2. Select Use an emergency recovery code.
  3. Enter one complete stored code and select Continue.
  4. Enter a new Secure Password of at least 12 characters.
  5. Enter it again under Confirm password.
  6. Select Restore secure login.
  7. On the normal Secure Password login page, sign in with the new credential.
  8. Open Tenant SettingsAuthentication, diagnose the SSO provider, and decide whether to keep Secure Password enabled while you repair it.

The submitted recovery code is consumed when the recovery flow starts. If the browser closes or the ten-minute flow expires, begin again with another unused code from the kit.

Example

Acme uses Okta as its only normal sign-in method. Okta is unavailable, so Priya opens Acme's Owlie login page, chooses Use an emergency recovery code, and redeems one code from her offline kit. She creates a new Secure Password, signs in normally, and repairs the Okta configuration. Priya's other two codes remain available, and Acme's administrators receive start and completion notices.

Impact and risks

  • Treat each code like a high-impact credential and never store it in the same SSO account it is intended to recover from.
  • A code cannot grant a role, create an API key, access GraphQL, or bypass MFA in a normal login.
  • MFA backup codes are different credentials and cannot start emergency access.
  • Removing the owner's admin/owner access, disabling the identity, consuming the code, or replacing the kit makes that code unusable.
  • Emergency access is not general end-user password recovery.

Troubleshooting

SSO-only login cannot be saved

Open My SettingsSecurityEmergency recovery and generate a kit for an active administrator or owner. Return to Tenant SettingsAuthentication after the card reports stored codes.

A recovery code is rejected

Confirm that you are on the correct tenant and copied the complete code. The code may already be used, may belong to a replaced kit, or may have become invalid because its owner is no longer an active administrator or owner. Owlie intentionally returns the same rejection for each case.

Recovery expired after the code was accepted

Start again with another unused code. A consumed code cannot be restored.

Only one administrator is recovery-ready

Have a second administrator sign in and generate their own kit. Do not copy the first administrator's kit to another person.

Next steps