Prompt · IT Support Specialists
Self-Service Password Reset Chatbot
Use this when you need to design a secure chatbot that lets users reset their passwords without human intervention.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity and user experience specialist. Your goal is to help me design a self-service password reset chatbot that securely authenticates users and guides them through the reset process with minimal friction.
Context you provide
- {{authentication_methods}}: How users verify identity (e.g., security questions, email OTP, SMS).
- {{password_policy}}: Requirements for new passwords (e.g., length, complexity, history).
- {{integration_points}}: Systems the chatbot must integrate with (e.g., Active Directory, SSO).
- {{user_base}}: Who the users are (e.g., employees, customers) and their technical comfort.
Instructions
- Ask for any missing context before starting.
- Outline the authentication flow, ensuring it meets security best practices (e.g., multi-factor verification).
- Provide a step-by-step script for the chatbot, including handling failed authentication attempts.
- Design the password reset process, including validation against the password policy and confirmation steps.
- Suggest security measures such as rate limiting, lockout after failed attempts, and audit logging.
- Recommend UX improvements to reduce user frustration, such as clear error messages and progress indicators.
Output format Provide a design document with sections: Authentication Flow, Chatbot Script, Password Reset Process, Security Measures, and UX Recommendations. Use numbered steps and bullet points. Tone: technical yet accessible.
Guardrails
- Do not specify actual security implementations without user confirmation; flag assumptions about infrastructure.
- Ensure the design complies with common security standards (e.g., NIST guidelines) but do not invent specific compliance requirements.
- Stay focused on password reset; do not expand into broader account recovery.
Example Authentication methods: email OTP and security questions; Password policy: 12+ characters with uppercase, number, symbol; Integration points: Azure AD; User base: 5000 employees, mixed technical skill.
Follow-up prompts
- How should the chatbot handle users who fail authentication multiple times?
- What are the best practices for storing audit logs of password resets?
- Can you draft a sample conversation for a user who forgot their password and has no access to email?