What account records might a provider hold?¶
Potentially a lot more than the public profile.
A provider may hold separate systems for registration, security, authentication, sessions, devices, activity, payments and administration.
For an investigator, the useful approach is to match the record category to the question you are trying to answer.
A provider account can span several record systems¶
| Record area | Examples | Useful for |
|---|---|---|
| Registration | Stable account ID, supplied details, verification, creation time | Who or what was supplied when the account was created |
| Authentication | Successful/failed access, factors, recovery events | How access was granted |
| Sessions | Session IDs, clients, devices, source addresses, revocation | Connecting later activity to an access route |
| Security/control | Password changes, MFA enrolment, trusted devices | Who may have controlled the account |
| Activity/content | Messages, posts, uploads, searches, transactions | What happened through the service |
| Commercial | Billing, subscriptions, payment instruments | Funding and account relationships |
| Administration | Roles, delegation, consent, policy changes | Organisational or application control |
Not every provider has every category, and retention can vary.
The public account export may not be the full evidence picture¶
A user-facing download might contain posts, messages and profile data but omit internal security or authentication logs.
Likewise, some content may be encrypted, deleted or held in another system.
A linked identity provider, payment processor or tenant organisation may hold part of the evidence instead.
Work backwards from the investigative question¶
If the question is who created the account, look for:
- creation time;
- source connection;
- device/client;
- supplied and verified details;
- recovery and payment information.
If the question is who accessed it, look for:
- authentication;
- session IDs;
- device/client;
- source address;
- MFA and trusted-device records.
If the question is was it taken over, look for:
- recovery changes;
- password changes;
- factor enrolment;
- session revocation;
- new devices;
- security alerts.
If the question is who sent the disputed message, ask for the event and any available link to the session, client or device that generated it.
Preserve definitions and scope¶
Provider fields can be easy to misread.
If a record says device, login, session, location or read, ask what the provider means by that field.
Also keep:
- original timestamps and time zones;
- export filters;
- date range;
- product/account scope;
- field definitions;
- known retention limits; and
- any exclusions.
What should I ask a provider for? turns this record map into a practical request.
The practical point is: provider evidence is usually a collection of record systems, not one universal account file. Start with the investigative question and ask which provider records can actually answer it.