← All controls

57 Air-gapped recovery identity

draft

A sealed kit, kept wholly outside the tenant, that recovers the domain when every in-tenant admin — the break-glass account (19 Break-glass admin + offline backup codes) included — belongs to the attacker. Google's documented way back in is domain verification: support restores super-admin access to whoever proves ownership of the primary domain by setting a DNS record, which makes the registrar login the tenant's real root key. The kit's job is keeping that login exercisable and non-circular when the tenant is hostile: registrar/DNS-host credentials with their second factor, the facts support asks for (customer ID, support PIN, billing account or purchase records), a recovery email on infrastructure unrelated to the tenant, and the printed runbook for the recovery request itself.

Caveats

This is a process control — it is carried out offline, so there is no Admin Console walkthrough to show.

Ongoing maintenance

How to verify

  1. Open the kit under custody rules and inventory it against the manifest: registrar/DNS credentials and their second factor, customer ID and support PIN, recovery email credentials, printed runbooks — then re-seal with fresh serials.

  2. Rehearse the entry point from a clean machine: sign in to the registrar with the kit's credentials and confirm the recovery email receives mail — touching nothing inside the tenant.

draft v0.1.0 Recover policy #11 · #13, #16 (gap G4) ↗