Why Access Might Be Revoked
- Referral link expired or sponsor manually deactivated access
- Config slot inactive for extended period (typically 30+ days)
- Jurisdictional breach or node usage anomaly
- Tier 3 operator enforcement of infrastructure policy
Recognising a Revoked Session
- Dashboard displays “Trust Expired” or “Config Disabled”
- WireGuard client shows persistent handshake failures
- Region restrictions block tunnel regeneration
- Referral glyph becomes non-functional
How to Recover Access
- Contact your sponsor and request trust revalidation
- If sponsor is unreachable, submit a recovery request via
/client/recover.html - Tier 3 reviewers may issue new credentials under updated trust logic
After Reapproval
- New configuration file or QR will be issued
- Previous endpoints may be retired or rekeyed
- Your account audit log will reflect recovery signal
How to Avoid Revocation
- Keep at least one tunnel active every 30 days
- Stick to your assigned jurisdiction unless sponsor-authorised
- Monitor config for failed handshakes or routing anomalies
“Credential flow is trust flow - recovering access means rebuilding encrypted alignment.”