SUMMARY: Recovery authority is the practical power to restore an identity, account, record, or service after its ordinary controls stop working.
Systems often describe recovery as a convenience feature: receive a code, answer a question, contact support. In practice, recovery is a governance layer. It determines whose testimony counts, which evidence can override a locked interface, and whether a person can regain continuity without surrendering more identity than the original service required.
The visible account owner may not hold the final authority. A mobile carrier can redirect a recovery code. An employer can disable an identity provider. A platform support queue can accept or reject documentary evidence. A domain registrar can decide whether control of an address is enough to establish control of everything attached to it.
The Recovery Chain
Trigger authority: identify who can begin a reset and what event makes the request legitimate.
Evidence authority: record which device, document, address, or human witness can prove continuity.
Decision authority: name the party that can approve an exception when automated checks fail.
Override authority: determine who can reverse a completed recovery, invalidate sessions, or transfer control again.
A Sovereignty Test
Map one critical identity from the login screen outward. Follow every dependency until the chain reaches a person, institution, or physical artifact. Then ask whether two independent routes exist and whether either route depends on the system being recovered.
This extends permission weather. Permission drift describes a changing access climate; recovery authority identifies who controls the emergency door when that climate becomes hostile. Pair the map with an evidence exit route so proof of continuity remains available outside the affected platform.
Field assessment: an identity is not sovereign when its recovery depends on an authority the owner cannot identify or reach.