Skip to content
Skip to main content
Accounts & Identity Technical Explainer

Can software or a device use an online account?

Yes. Plenty of account activity happens without somebody actively sitting in front of the service at that moment.

Phones synchronise photographs. Email clients check for messages. Cameras upload footage. Business systems send notifications. Apps refresh sessions in the background.

So a provider record showing account activity does not always mean “the user just logged in and did this”.

Accounts can give software continuing authority

A person may sign in once and the application then receives a session or token that lets it keep working.

That can look like:

Initial accessUser signs inThe service authenticates the account.
Authority storedSession or token issuedThe application can continue without asking for the password each time.
Later activityApp synchronisesThe service records account activity even though no fresh human action occurred.

This is normal behaviour.

What should you look for?

Useful fields may include:

  • application or client ID;
  • device identifier;
  • session ID;
  • token or credential type;
  • scheduled interval;
  • service-account identity;
  • API activity; and
  • the event that triggered the process.

If the same client refreshes every hour, that may be background activity rather than somebody repeatedly signing in.

Separate the machine event from the human decision

Suppose a business rule automatically emails a customer when an invoice becomes overdue.

The email event may occur at 02:00 when nobody is working.

The relevant human activity may have happened days earlier when somebody configured the rule.

That gives you two different events:

  1. the earlier configuration or authorisation;
  2. the later automated action.

Keeping them separate makes the timeline much more accurate.

Automation does not make the evidence useless

Quite the opposite.

Application IDs, recurring device identifiers, tokens, schedules and configuration changes can be very useful for showing how the account was being used.

You may also be able to identify who installed, authorised or changed the automation.

Who controlled the account? is often the useful next question if you need to connect that authority back to a person.

The practical point is: an account can act through software long after the original login. Identify the application, credential and trigger before describing the event as a fresh human action.

Reference: AI-008Accounts & Identity