Skip to content
Skip to main content
Cloud Services Technical Explainer

What does a cloud record actually prove?

It proves that the provider's system recorded the event or state described by its fields. To move beyond that, read the actual field names, learn what the provider means by them and identify the next record that can test the interpretation.

Read a recognisable record, not the word “cloud”

Imagine that an authorised Google Workspace administrator exports a Drive log event while investigating a disputed file download.

Read the provider's fields together
Simplified fictional Google Workspace Drive log event
Date=2026-07-09T21:31:42ZEvent name=DownloadActor=dave@northstar.exampleDocument ID=1AbC-4407IP address=198.51.100.27User device ID=DEV-77 · DESKTOP_WINDOWS
Established Google associated this Download event, actor, item, time, address and device context.Still open What produced the event, who controlled the account and device, and whether Dave viewed, deliberately saved or later used the file.

This is fictional training data using current documented Google attribute names. Not every attribute is reported for every Drive event.

The record is useful immediately. Its Document ID identifies the item to follow. Date fixes the comparison time. Actor identifies the account context Google recorded. User device ID may distinguish this route from Dave's other devices. IP address identifies the network observation recorded for that event.

But each field has a defined job. Google says Actor is the user's primary email address, even when an alias is involved. It also says an IP address may instead be a proxy or VPN address and is absent from some events. The details strengthen the enquiry because they create specific comparisons; they do not all become verified personal identity.

Turn the entry into three statements

Layer Defensible statement from this example
Recorded directly Google recorded a Download event for Document ID 1AbC-4407 against the listed actor, time, address and device context
Supported if definitions fit The event was associated with Dave's Workspace account and the Windows device identifier shown
Still unresolved Whether Dave controlled that route, whether “Download” represented deliberate saving or another documented behaviour, and what he knew or intended

This three-layer reading prevents two opposite mistakes: dismissing the event because it is not final proof, or overstating it as proof that Dave personally downloaded and read the file.

Find the record that answers the open question

The next source depends on the gap:

  • Who controlled the account? Compare authentication, recovery and account-management records.
  • Which device was DEV-77? Obtain the device inventory or corresponding local application evidence.
  • Was this a deliberate save? Examine browser, application, filesystem and Drive-for-desktop activity.
  • Was the same item used later? Follow Document ID, filename, hash, versions, sharing and communications.
  • Could the log be incomplete? Preserve the search criteria, date range, exported columns and provider documentation.

That is the practical purpose of reading fields literally: each one becomes a join point to another source.

How the same idea appears in Microsoft 365

A Microsoft 365 Purview audit export uses different terminology. Depending on the event and workload, useful properties may include:

  • CreationTime - when the audit record was generated in UTC;
  • Operation - the recorded activity;
  • UserId and UserType - the recorded user or system/application context;
  • ObjectId - for SharePoint activity, the full path of the accessed file or folder;
  • ClientIP - the recorded client address, subject to documented exceptions; and
  • Workload - the Microsoft 365 service in which the activity occurred.

Microsoft warns that ClientIP may represent a trusted application acting for a user and may be null for some administrator or system activity. It also documents system, application and service-principal UserType values. Those are concrete reasons not to translate every UserId and ClientIP directly into a human actor and physical device.

Why no matching event needs its own test

Google states that not all Drive activities are logged and that event availability depends on the Workspace edition and administrative access. Microsoft fields likewise depend on the service and activity.

Preserve the exact source, filters, columns, time zone and date range. “The supplied search returned no matching event” is more defensible than “the event never happened”.

The point to remember

A cloud record is not vague background. Its time, event name and identifiers are concrete join points. State what the provider recorded, then use the unresolved field or proposition to choose the next record.

Provider sources - checked 2 September 2026
Reference: CLD-013Cloud Services