Laptop stolen, security key left in a hotel, disk wiped. This is a normal event and the answer is short:
Enrol a new key on your new device: secretsmgr enroll request.
An administrator approves it, with the same fingerprint check as the first time.
Any existing member of each vault runs secretsmgr grant <vault> <you>.
An administrator revokes your old principal, which reviews anyone you had granted access to, gives each of your vaults a fresh vault key, and prints the value-rotation checklist.
secretsmgr recover walks you through it and produces the exact list of vaults and the single command a colleague needs to run.
There is no secret recovery mechanism, and that is the point
No escrowed copy of your key, no support account that can decrypt on your behalf, no master key in a safe. Recovery is your colleagues re-granting you access, because that capability already exists and adds no new way for the system to be compromised. A "recovery key" that could restore your access is by definition a key that reads everything.
The corollary is that a vault with only one member is one lost laptop away from being gone forever. Which brings us to: