Skip to content
Skip to main content
Accounts & Identity Technical Explainer

Can an online account belong to a business or organisation?

Yes. Many online accounts represent a company, charity, public body, team or other organisation rather than one individual.

That can be very useful because the organisation may hold its own records showing who had access, what role they held and which internal process sat behind the account activity.

The organisation and the operator are different questions

A company social-media account may clearly belong to the company.

That does not automatically tell you which employee posted a particular message.

Likewise, a shared mailbox may belong to a department while several staff members can send from it.

OrganisationNorthmere Services LtdThe entity represented by the account.
AccountCompany service accountThe provider record used by the organisation.
OperatorEmployee, contractor or automationWho or what had permission to act.
EventPost, message or transactionThe specific activity being investigated.

Keep those layers separate.

Organisational systems may give you extra evidence

Depending on the environment, useful internal records may include:

  • administrator or delegate logs;
  • historical permissions;
  • employee and contractor records;
  • device allocation;
  • staff rotas;
  • change or approval workflows;
  • password-management records;
  • internal messages; and
  • management-platform logs.

These can be extremely helpful when the provider-side record only identifies the company account.

Historical permissions matter

Do not rely only on who can access the account today.

Staff leave. Roles change. Passwords are reset. Administrators are added or removed.

If the event happened six months ago, establish who had access then.

A current permissions screen may describe the wrong period.

Some actions may be automated

A customer system may send notifications automatically.

A scheduled process may update records.

A social platform may publish content through an authorised application.

So if the account event appears machine-generated, work out what system triggered it and who configured or approved that process.

Can software or a device use an online account? explains that distinction.

The practical point is: an organisational account can strongly establish the business context while still leaving the operator open. Use provider records and the organisation’s own historical access records to identify who or what was behind the event.

Reference: AI-007Accounts & Identity