Skip to content
Skip to main content
Accounts & Identity Technical Explainer

What information can an online account contain?

Potentially much more than the name and profile that a user can see.

An online account can bring together registration details, security changes, login and session records, devices, payments and activity under one provider-held record. For an investigator, that can turn a username or profile into a much richer line of enquiry.

The useful question is not “what does an account normally contain?” It is which records does this particular service hold that can answer the question I have?

Think in groups of records

A provider may hold information such as:

Record area Examples What it may help with
Registration Account ID, supplied name, email, telephone number, creation time How the account was created and what details were supplied
Security and recovery Password changes, recovery details, MFA enrolment, trusted devices Who may have controlled or recovered the account
Access Logins, sessions, source addresses, applications, device/browser fields When and how the account was accessed
Payments Billing details, subscriptions, purchases, payment instruments Links to transactions or other accounts
Activity Messages, posts, uploads, searches, sharing, settings What happened through the service

A public profile may expose only a tiny fraction of that.

The field itself is only half the story

Suppose a provider return contains:

Simplified account record
account_id=FC-88214display_name=Fenland Classicsname_supplied=David Fosterrecovery_mobile=+44••••••6142created=2026-08-02T19:14:22Z

Those values are immediately useful, but they are not all the same kind of evidence.

The account ID is provider-generated. The display name may be freely editable. The name may simply be what somebody typed into a form. The recovery number may have been added later.

So for any important field, ask:

  • who supplied it;
  • whether the provider verified it;
  • when it was added or changed; and
  • whether it relates to the event you are investigating.

That is often more useful than the label alone.

Access records may be more valuable than the profile

If the question is who was using the account, registration details may only get you so far.

Login, session and device records may show:

  • when access occurred;
  • which application or browser was involved;
  • recurring device or installation identifiers;
  • source IP addresses;
  • security-factor activity; and
  • session creation or revocation.

Those records can then be compared with devices, communications and real-world activity.

Does an account identify a person? explains why that extra work matters.

Account records may be split across services

A visible service may rely on:

  • an external identity provider;
  • a payment processor;
  • a tenant or employer;
  • a cloud platform;
  • another linked application.

So a single “account return” may not contain every useful record.

If the account uses another service for sign-in or payments, that other provider may hold part of the evidence you need.

Ask for records that answer the question

If you are investigating account creation, creation time, initial identifiers and registration records matter.

If you are investigating compromise, security changes, sessions and recovery events matter.

If you are investigating a particular message or transaction, the relevant activity and session records matter.

What account records might a provider hold? goes deeper into provider-side record categories.

The practical point is: an account can be a very rich evidence source, but the useful record depends on the question. Start with the event you need to understand, then identify the provider records that can actually answer it.

Reference: AI-002Accounts & Identity