Skip to content
Skip to main content
Accounts & Identity Technical Explainer

Can several people share one account?

Yes. Families, partners, teams and businesses do it all the time.

That means an event recorded against an account may still leave you with a second question: which person was using it at that moment?

Sharing can be formal or informal

Some services deliberately support several operators.

A business page may have named administrators. A shared mailbox may allow several staff members to act through the same organisational identity.

Other sharing is informal: one password is saved on several devices or simply passed between people.

Those arrangements leave different evidence.

Access model What you may see
Named delegates/admins Separate operator IDs, roles or audit events
Shared credentials Common account identity with less provider-side separation
Shared signed-in device Activity may appear under one continuing session
Temporary use Another person may use the account without gaining long-term control

Understanding the access design tells you what attribution is realistically possible.

Start with the event, not the registered name

Suppose a shared account posts a message at 14:22.

Do not begin with “whose account is this?”

Begin with:

  • which session produced the event;
  • which device or application was involved;
  • whether the platform recorded a delegate/operator;
  • who had access to the device;
  • what other accounts were active there; and
  • what was happening around 14:22.
EventMessage at 14:22The account records the activity.
SessionWeb session S-4812Which access route generated it?
DeviceOffice laptop 07Which machine held that session?
UserWho was using it?Possession, access records and surrounding context.

Shared use does not make attribution impossible

It simply changes what you need.

Provider logs, local device artefacts, work rotas, building access, CCTV, communications and other account activity may help identify the operator.

Content may also help — for example, knowledge available only to one person — but should normally sit alongside stronger technical or real-world evidence.

Who was actually using the account? takes that event-specific attribution question further.

The practical point is: a shared account tells you which common provider record was used. Follow the event through the session and device to work out which person used it.

Reference: AI-006Accounts & Identity