Skip to content
AI-030 Accounts & Identity

What should I ask a provider for?


id: "AI-030" title: "What should I ask a provider for?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"


What should I ask a provider for?

Script

You have identified an online account and need information from the provider.

Do not begin with a generic request for everything.

Begin with the investigative question.

Are you trying to identify who registered the account?

Who accessed it?

Whether control changed?

Who carried out a particular action?

Whether the account was compromised?

Your request should follow from that question.

For registration, consider the creation date, details supplied, verification records, recovery information, payment data and the IP address or device used when the account was opened.

For access, consider login and session records, IP addresses, device or application information, authentication methods and relevant time zones.

For account control, consider password resets, changes to recovery details, multi-factor authentication changes, trusted-device records and session revocations.

For a specific event, identify the exact date, time, account, action and time zone.

Ask whether the provider can link that event to a session, device, IP address or transaction record.

Where compromise is alleged, request the security history around the suspected takeover period.

Preserve first where delay may lead to loss.

Some records are retained for short periods, and the formal disclosure process may take longer than preservation.

Follow your lawful authority, organisational policy and the provider's current process.

Be precise, but do not pretend you know the provider's internal field names.

Describe the evidence and question clearly enough for the provider to identify the relevant record category.

Also ask for explanations where needed.

What does a “login” entry represent?

Is the time shown in UTC?

Does the IP relate to session creation or later activity?

Was the device identifier supplied by the device or generated by the provider?

Finally, record the limits.

A provider response may identify an account, connection, device or session.

It may not identify the human user.

Ask for the records that answer your investigative question, then interpret them alongside the rest of the evidence.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.