Skip to content
Skip to main content
Accounts & Identity Technical Explainer

Does an account identify a person?

It can help — sometimes a lot — but the account itself does not automatically tell you who performed a particular action.

Think of the account as the provider’s continuing record. Your job is to connect the relevant account activity to a session, a device and then a person.

Start with what the account genuinely gives you

A provider may tell you:

  • the stable account ID;
  • the name and contact details supplied;
  • whether any details were verified;
  • login and session history;
  • recovery and security changes;
  • linked devices or applications; and
  • the activity recorded against the account.

That can be very strong evidence.

But different parts answer different questions.

AccountWhich provider record?Stable ID, registration and account history.
EventWhat happened?Message, purchase, upload, setting change or other activity.
Session / deviceHow was it done?Application, browser, connection and device context.
PersonWho controlled it then?Possession, access, communications and independent real-world evidence.

That chain is much more useful than jumping straight from the account name to a suspect.

Registration can be useful without settling identity

Some services perform strong identity checks. Others ask for little more than an email address.

Even genuine details may not answer who used the account later.

For example, an account may be:

  • created by one person and used by another;
  • shared;
  • delegated;
  • compromised;
  • accessed from several devices; or
  • operated partly by software.

That does not make the registration details useless. It tells you what they actually establish.

The registered account holder is therefore one question, while who controlled the account is another.

Work from the disputed event outwards

Suppose an account sends a payment instruction at 19:41.

Ask:

  1. Which account recorded the event?
  2. Which session or application generated it?
  3. Which device or connection was associated with that session?
  4. Who had control of that device or access route at 19:41?
  5. What independent evidence supports that person being the user?

Useful supporting evidence might include:

  • the same account active on a seized device;
  • recurring device or application identifiers;
  • possession of that device at the relevant time;
  • CCTV or access-control records;
  • account-recovery activity;
  • messages arranging the action; or
  • information in the content known to the user.

Several independent records agreeing can make the attribution very strong.

Use precise wording

There is a big difference between:

“The provider recorded the account in Ellis Ward’s name.”

and:

“Ellis Ward sent the message.”

The second conclusion may eventually be justified — but only after the intervening evidence supports it.

That precision is not bureaucratic caution. It makes the case stronger because another investigator can see exactly where each conclusion comes from.

The practical point is: use the account to narrow the enquiry, then connect the relevant event through its session and device to the person.

Reference: AI-003Accounts & Identity