I think account recovery should be treated as a separate authentication method, not as harmless customer support. An email reset link, SMS code, trusted device, or support override can bypass the password, passkey, or MFA setup a service encouraged you to use. That makes the recovery path part of the real security boundary.
Services should show users every active recovery route, explain which ones are weaker or more phishable, and let them remove fallbacks they do not want. Changes to recovery details should notify an independent existing channel and perhaps sit behind a delay so the legitimate owner can cancel them. Standards already recognize recovery notifications and, in some cases, waiting periods.
The trade-off is real: stronger controls reduce takeover risk but can permanently strand someone who loses a device or access method. Which recovery controls do you actually use, and what compromise would you accept?