Skip to content
AI-007 Accounts & Identity

Can an online account belong to a business or organisation?


id: "AI-007" title: "Can an online account belong to a business or organisation?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"


Can an online account belong to a business or organisation?

Script

You have identified an account involved in the activity.

The account belongs to a company, public body, charity or other organisation.

That tells you who the account represents.

It does not yet tell you which person carried out the activity.

Organisations routinely operate online accounts.

These include shared email inboxes, social-media pages, payment accounts, cloud platforms, customer-service systems and administrative accounts.

Access may be spread across several people.

One employee may create content. Another may approve it. A contractor may manage the platform. An IT administrator may control security settings without using the account for its normal business purpose.

Access can also change over time.

Staff leave, roles change, passwords are reset and permissions are added or removed. The person authorised today may not have been authorised when the relevant activity occurred.

Start by identifying how the organisation managed the account at the relevant time.

Who owned the business process?

Who was authorised to access the account?

Were individual user profiles used, or did several people share one username and password?

What audit logs, access-control records or device records exist?

Organisational records may be as important as provider records.

Staff rotas, employment records, internal messages, password-management systems and device allocation records can help narrow the possible user.

Be precise about what the evidence shows.

An organisational email address does not prove that a particular employee wrote the message.

A post published through a company page does not prove that the director personally posted it.

A transaction from a business account does not, by itself, identify the individual who authorised or completed it.

The organisation may still be responsible in a civil, regulatory or policy sense, but that is separate from proving who performed a particular act.

An organisation-owned account identifies the organisation first.

The next investigative task is to identify the individual access, decision or action behind the event.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.