Does a cloud account identify a person?¶
Not by itself. It identifies a provider profile or organisational user identity. A person becomes attributable when records connect a particular account event, technical route and device context to that person's activity.
Follow one event all the way to Dave¶
Return to the fictional Google Workspace Drive event from CLD-013. Google recorded a Download event for Document ID 1AbC-4407, with Dave's work account as Actor, IP address 198.51.100.27 and Windows device identifier DEV-77.
That is already meaningful evidence - but “Dave's account appears in the event” and “Dave deliberately downloaded the file” are not the same conclusion.
No label performs the whole journey. The strength comes from independent records agreeing about the same object, time, account and device.
What each new record adds¶
- Provider profile: the Workspace identity exists within Northstar's tenant.
- Drive event: Google's system associated the account with a defined event, object and time.
- Device context: the event contains Windows device identifier DEV-77.
- Local device evidence: Dave's laptop contains the matching managed-device identity, signed-in account context and a corresponding local file or browser event.
- Independent context: Dave sends a message at 21:34 naming the file and explaining what he has just done.
At stage two, the safe conclusion is about the account event. By stages four and five, the evidence may support a personal attribution because the provider and device records converge with Dave's own communication.
The message matters because it is not merely another copy of the account label. It supplies independent context: knowledge of the object and activity at the relevant time.
Use the chain to find the missing bridge¶
Google recorded the event against the account and device context; matching local and communication evidence connects that event to Dave.
Whether another person used Dave's device or account, whether the provider's Download label describes the assumed action, and what the event proves about knowledge, intention or responsibility.
If the chain stops at the account, investigate account control. If it stops at the device identifier, identify and examine the device. If the event could be automatic, distinguish interactive and background activity. If the person is established but intention remains open, look to communications, sequence, repeated behaviour and other case evidence.
This makes the page operational without becoming a jurisdiction-specific procedure: the place where the chain stops tells the investigator what sort of evidence should come next.
Provider fields are evidence, not identity certificates
Google currently describes Actor as the email address of the user who performed the action, normally recording the primary address where an alias exists. It also exposes Document ID, Event name, IP address and, for relevant events, User device ID.
In Microsoft 365, the comparable investigation might join a Purview audit event - using fields such as Operation, UserId, ObjectId, ClientIP and Workload - to Microsoft Entra sign-in information describing the user identity, client application and resource.
Those provider definitions make the records more useful, not less. They tell the investigator exactly which technical proposition each system supplies and where personal corroboration is still required.
Write the conclusion so it can be challenged¶
Prefer a joined conclusion:
Google recorded the Download event for Document ID
1AbC-4407against Dave's work account and Windows device identifierDEV-77. Dave's laptop contained the matching account and file activity, and his message three minutes later referred to that file. Taken together, those records support that Dave used that route for the event.
Avoid both extremes:
- Too strong: “The account proves Dave downloaded and read the file.”
- Too weak: “It was only an account, so it proves nothing.”
A precise conclusion shows the bridge and leaves any genuine alternative visible.
The point to remember
An account starts the attribution chain; it does not finish it. Follow the same event through provider identifiers, device evidence and independent context, then stop the conclusion exactly where the evidence stops.