> I don't see how allowing helpdesk operators to help users recover access to their accounts has any relation at all to the helpdesk operators having access to the account itself. They need to be able to access and update account metadata, not the account itself.
So in your system the bad guy can't read my email because he only has the ability to access and update account metadata such as my password and the helpdesk system doesn't give him access to the actual email?
That would work, unless any of the bad guys is smarter than you and realises that they can use this metadata to... log into my account and read my email.