Skip to content
Skip to main content
Cloud Services Technical Explainer

What is the difference between viewing, editing, downloading and sharing a file?

They describe different interactions with a cloud object. A provider event should be reported according to what that service recorded, because viewing content, changing it, transferring a copy and granting access support different conclusions.

Event Plain meaning What may have happened technically
View Content or a preview was presented Browser rendering, preview request or application retrieval
Edit Content or metadata changed Manual change, autosave, conversion, import or automated update
Download Data was transferred out of the service Manual save, sync retrieval, cache or application request
Share Another access route was granted Permission, group membership or link creation

One user action can generate several events

Opening a document in a browser might request a preview, download working data and trigger autosave. Editing can create a new version. Sharing the result is a separate permission event. A sequence of log entries may therefore describe one interaction rather than four people or four deliberate decisions.

The reverse is also true: one broad audit label may hide several technical stages. Provider documentation, event fields and application identifiers are needed to understand the local meaning.

Dave opens briefing.docx in Word for the web. One interaction produces a preview request, content retrieval, autosave version V-19 and, after Dave selects Share, permission PERM-72. The service records different operations because it performed different jobs; the investigator should not collapse them into the single claim that Dave “used the file”.

One interface interaction can create records with different meanings
EstablishedEach event can establish the particular service operation and its recorded actor, object and result.
Still openWhich events were automated and what Dave read, understood or intended.

Event does not equal human interpretation

A download does not prove opening, and a view does not prove reading. Synchronisation, preview services, security scanners and authorised applications can create similar records.

An edit event is stronger evidence that the managed object changed, but the named account may represent a person, shared identity or automated process. Sharing proves capability was granted under the recorded settings, not that the recipient used it.

Preserve the distinctions in the conclusion

Record the object and version, exact event type, account or application, session, time and outcome. Then state any supported human action separately. “The provider recorded a download by session SES-41C2” is more accurate than “the user read the file”.

The next useful comparison is the exact operation and result against the application's session, resulting version or permission, receiving-device evidence and surrounding user activity.

Current Microsoft audit-operation example - checked 3 September 2026

Microsoft Purview currently lists distinct audit operations for file access, download, modification and sharing-related activity. The properties returned vary by workload and operation. Preserve the operation name, object, user or application, client details, result and correlated identifiers supplied in the export.

The point to remember

View, edit, download and share events answer different questions. Interpret the provider's event definition first, then use session, device and contextual evidence for the human conclusion.

Reference: CLD-065Cloud Services