if you provide identity services to more than 100k people or w/e, you need to have a defined dispute process, served by humans with the power to do shit, with legal recourse in the event that they fail to do so. the "run a flag up the pole on social media, hope you're important enough or friends with the right set of people if you want shit done" approach is terrible.
the inevitable "but that will be vulnerable to fraudsters" backlash is stupid--the existing systems are too; fraud prevention and such isn't something you can ever do perfectly, since it's inherently adversarial. the problem we have now is that EVERYONE is treated as if they're a mastermind professional fraud network from the outset, and this does seemingly little to prevent actual bad actors. Twitter's trust and safety team is an even more egregious example, where they very effectively and immediately suspended my attempt to create a single parody account, immediately suspended it again after unsuspending it, and said any future attempts to reach them would be blackholed because the first unsuspend request was still open (there's, of course, no way to see that ticket or respond to it--all you get are email notifications stating that the reply-to discards all inbound mail). this, of course, does seemingly nothing to deal with actual bot networks, since those are run by sophisticated actors who've figured out how to game the system.
something like Estonia's digital ID system is perhaps best, with, importantly, built-in protection against tracking: I should be able to generate an ID that a company can verify, but all they should be able to glean from that is that I have an ID and that I've authorized X other IDs for that company--it shouldn't be something that's traceable back to who I actually am or trace my actions across companies, which is very much not the case (and is something companies very obviously take advantage of for adtech purposes) for the de facto standard of using mobile phone numbers.