How you control password restoration

Dear colleagues,

It’s my first topic on the forum, but I’ve done my best to find topic answering my question and have not succeeded.

The question is how you mitigate the risk that fraud that steal restoration info from user or even admin not use info from the passbolt to hide his activities: remove e-mails or cases in ServiceDesk system created from e-mail from passbolt notification? Is there any mechanism to confirm restoration by other admin?