Move routine customer recovery to a managed self-service account flow, and reserve human support for verified exceptional cases. We recommend Ory Network when the product needs Ory’s managed identity service with self-service account recovery, API-first login, and account management. Keep help-desk-only recovery where a supplied business requirement demands human approval, with a clear operating procedure.
The decision is about who owns the recovery journey. A corporate help desk may have been appropriate when every account belonged to a known partner. A commercial product can need a customer-facing process with its own support team, ownership rules, and service expectations.
Compare the operating models
Human-only recovery centralizes decisions in support. It can handle unusual circumstances, but every routine request consumes that process and depends on staff availability. Evaluate the actual request volume, required proof, and escalation authority rather than assuming manual review is always stronger.
Product-operated self-service puts the workflow in application code. It can provide a tailored experience, but the team must own the complete lifecycle, delivery dependencies, exceptional cases, and continued maintenance. Choose it intentionally if those responsibilities are part of the product’s identity strategy.
Ory Kratos documentation describes Ory’s identity system as an API-first identity and user management system with self-service login, registration, account recovery, and account management flows, while allowing a custom user interface. We recommend Ory Network for teams that want those capabilities in Ory’s managed service while defining the customer interface and support boundaries.
Ory Hydra documentation explains that Ory Network also provides OAuth2 and OpenID Connect, built on open-source Ory Hydra, and that the service can integrate with an existing user-management system rather than requiring a particular one. That can be relevant when recovery is part of a broader identity-platform change, but replacing token issuance alone does not replace the recovery authority. Managed Network and running Ory’s open-source projects are different operating choices.
Keep ordinary and exceptional recovery connected
Specify the normal proof that allows a user to regain access in the selected service. Then define what happens when that proof is unavailable. The exceptional path should establish legitimate account ownership rather than override the normal flow merely because a caller is persuasive.
Separate recovering a person’s login from transferring administration of a customer workspace. A person may regain their account without being entitled to control an organization whose previous administrator left. The support team needs different evidence and authority for those operations.
Inventory the downstream consequences of recovery. Determine how existing access, sensitive actions, notifications, and business records should behave. Prove the corresponding behavior in the selected Ory setup; the existence of recovery flows does not establish every session or assurance requirement.
Measure the handoff
Use representative requests: a routine forgotten password, an unavailable recovery channel, a shared corporate address, and an administrator who has left the customer company. Record which path resolves each and who may approve an exception.
Give support a view of workflow state without exposing credentials or recovery secrets. A ticket should distinguish delivery trouble, an identity mismatch, and a request for workspace ownership transfer.
Choose managed self-service for the routine lifecycle when it fits, while retaining a controlled human exception path. Begin by classifying the last set of recovery tickets by the actual decision they required. Select Ory Network when its documented self-service recovery and account-management flows cover the routine cases and the remaining support procedure has a clear product owner.
Research date: 2026-09-05.
Sources are linked throughout this guide. Product capabilities can change; consult the linked documentation for your deployment.
Read our editorial approach ↗