Skip to content
Skip to main content
Accounts & Identity Operational Explainer

Who controlled the account?

Account control is about who had the practical ability to get in, recover it, secure it, delegate access or lock somebody else out.

That can be more useful than the registered name, especially where the account has been shared or compromised.

Look for control events

Useful provider records may include:

  • password changes;
  • recovery-email or telephone changes;
  • multi-factor enrolment;
  • trusted-device decisions;
  • session revocation;
  • new application consent;
  • permission changes; and
  • account-recovery events.

These events can show how control shifted over time.

Example account-control timeline
08:12 · recovery_mobile changed to ending 614208:14 · new authenticator enrolled08:19 · existing sessions revoked08:23 · password changed

That sequence may be far more informative than the current settings page.

Control can change

An account might be:

  1. controlled normally by its legitimate holder;
  2. taken over by somebody else;
  3. recovered by the legitimate holder later.

If you only inspect today's settings, you may miss the period that actually matters.

Build the control picture around the relevant time, not the present day.

Knowing a password is not always full control

Somebody may know the password but not control the recovery email or multi-factor method.

Another person may control recovery and be able to reset the password and eject every session.

An organisational administrator may be able to suspend or reset an account without producing its everyday content.

So ask what practical authority the person actually had.

Control and use are different

A person may control an account but let somebody else use it.

A business owner may control recovery while employees operate the account day to day.

A compromised account may be controlled by an offender for a short period while still being registered to the victim.

Registered holderWhose details are recorded?The provider's account record.
ControllerWho could govern access?Recovery, password, factors and sessions.
UserWho performed the event?Session, device and surrounding evidence.

Who was actually using the account? takes that last step.

The practical point is: reconstruct account control as a timeline of security and recovery authority. Then deal separately with who performed the event you care about.

Reference: AI-011Accounts & Identity