Does an account identify a person?¶
id: "AI-003" title: "Does an account identify a person?" subtitle: "Separate an account identifier from evidence of the person who created, controlled or used it." slug: "ai-003-does-an-account-identify-a-person" pathway: "Accounts and Identity" section: "Starting with an online account" card_type: "investigator-question" content_type: "spoken-script" risk_level: "high-risk" pathway_order: 3 status: "draft" owner: "IF Digital" version: "0.1" review_gate: "pending" review_mode: "ai-assisted" review_timebox_mins: 60 qa_gate: "pending" qa_count: 0 pipeline_ref: "PIPELINE_PRG_001" pipeline_version: "1.1" public_safe: true video_ready: true word_count: 267 estimated_reading_time_mins: 1.3 audiences: - "investigators" - "analysts" - "supervisors" - "fraud teams" - "compliance staff" tags: - "identity" - "attribution" - "account holder" - "account user" - "corroboration" - "evidential limitations" primary_source_notes: - "NIST SP 800-63-4" - "Official provider account and security documentation"
Does an account identify a person?¶
Separate an account identifier from evidence of the person who created, controlled or used it.
Script¶
Does an online account identify a person?
Not by itself.
An account identifies a record held by a provider.
It may also contain information that points towards a person, but the strength of that link depends on how the information was obtained and what corroborates it.
Some accounts are created after formal identity checks.
Others can be created using a false name, a disposable email address or a telephone number controlled only briefly.
Even where the registration details are genuine, the registered holder may not have carried out the activity under investigation.
The account could have been shared.
It could have been used by an employee, family member or delegate.
It could have remained signed in on a device.
It could also have been compromised.
Investigators should therefore separate several questions.
Who is named on the account?
Who created it?
Who controlled its recovery methods and security settings?
Which devices and networks accessed it?
Who was in a position to use those devices at the relevant time?
And what evidence links a particular action to a particular person?
Useful corroboration might include provider login records, material recovered from a device, payment information, communications about the account, recovery details, location evidence or an admission.
The conclusion should match the evidence.
It may be reasonable to say that an account was registered using a person’s details.
It may be reasonable to say that a device associated with that person accessed it.
Neither statement automatically proves that the person performed every action recorded against the account.
The account is part of the attribution chain.
It is rarely the whole chain.
Key takeaway
An account may point towards a person, but attribution requires evidence linking the relevant account activity, session and device to that person.
Related questions¶
- Who is the registered account holder?
- Can several people share one account?
- What does a successful login actually prove?
Source notes¶
- NIST SP 800-63-4: Digital Identity Guidelines
- Microsoft Support: Recent sign-in activity for a Microsoft account
- Apple Support: Manage and use your Apple Account
- Apple Support: Check your Apple Account device list