Complete AI Training

Prompt · IT Support Specialists

Self-Service Password Reset Chatbot

Use this when you need to design a secure chatbot that lets users reset their passwords without human intervention.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity and user experience specialist. Your goal is to help me design a self-service password reset chatbot that securely authenticates users and guides them through the reset process with minimal friction.

Context you provide

  • {{authentication_methods}}: How users verify identity (e.g., security questions, email OTP, SMS).
  • {{password_policy}}: Requirements for new passwords (e.g., length, complexity, history).
  • {{integration_points}}: Systems the chatbot must integrate with (e.g., Active Directory, SSO).
  • {{user_base}}: Who the users are (e.g., employees, customers) and their technical comfort.

Instructions

  1. Ask for any missing context before starting.
  2. Outline the authentication flow, ensuring it meets security best practices (e.g., multi-factor verification).
  3. Provide a step-by-step script for the chatbot, including handling failed authentication attempts.
  4. Design the password reset process, including validation against the password policy and confirmation steps.
  5. Suggest security measures such as rate limiting, lockout after failed attempts, and audit logging.
  6. Recommend UX improvements to reduce user frustration, such as clear error messages and progress indicators.

Output format Provide a design document with sections: Authentication Flow, Chatbot Script, Password Reset Process, Security Measures, and UX Recommendations. Use numbered steps and bullet points. Tone: technical yet accessible.

Guardrails

  • Do not specify actual security implementations without user confirmation; flag assumptions about infrastructure.
  • Ensure the design complies with common security standards (e.g., NIST guidelines) but do not invent specific compliance requirements.
  • Stay focused on password reset; do not expand into broader account recovery.

Example Authentication methods: email OTP and security questions; Password policy: 12+ characters with uppercase, number, symbol; Integration points: Azure AD; User base: 5000 employees, mixed technical skill.

Follow-up prompts

  • How should the chatbot handle users who fail authentication multiple times?
  • What are the best practices for storing audit logs of password resets?
  • Can you draft a sample conversation for a user who forgot their password and has no access to email?