What is the difference between viewing, editing, downloading and sharing a file?¶
They describe different interactions with a cloud object. A provider event should be reported according to what that service recorded, because viewing content, changing it, transferring a copy and granting access support different conclusions.
| Event | Plain meaning | What may have happened technically |
|---|---|---|
| View | Content or a preview was presented | Browser rendering, preview request or application retrieval |
| Edit | Content or metadata changed | Manual change, autosave, conversion, import or automated update |
| Download | Data was transferred out of the service | Manual save, sync retrieval, cache or application request |
| Share | Another access route was granted | Permission, group membership or link creation |
One user action can generate several events¶
Opening a document in a browser might request a preview, download working data and trigger autosave. Editing can create a new version. Sharing the result is a separate permission event. A sequence of log entries may therefore describe one interaction rather than four people or four deliberate decisions.
The reverse is also true: one broad audit label may hide several technical stages. Provider documentation, event fields and application identifiers are needed to understand the local meaning.
Dave opens briefing.docx in Word for the web. One interaction produces a preview request, content retrieval, autosave version V-19 and, after Dave selects Share, permission PERM-72. The service records different operations because it performed different jobs; the investigator should not collapse them into the single claim that Dave “used the file”.
Event does not equal human interpretation¶
A download does not prove opening, and a view does not prove reading. Synchronisation, preview services, security scanners and authorised applications can create similar records.
An edit event is stronger evidence that the managed object changed, but the named account may represent a person, shared identity or automated process. Sharing proves capability was granted under the recorded settings, not that the recipient used it.
Preserve the distinctions in the conclusion¶
Record the object and version, exact event type, account or application, session, time and outcome. Then state any supported human action separately. “The provider recorded a download by session SES-41C2” is more accurate than “the user read the file”.
The next useful comparison is the exact operation and result against the application's session, resulting version or permission, receiving-device evidence and surrounding user activity.
Current Microsoft audit-operation example - checked 3 September 2026
Microsoft Purview currently lists distinct audit operations for file access, download, modification and sharing-related activity. The properties returned vary by workload and operation. Preserve the operation name, object, user or application, client details, result and correlated identifiers supplied in the export.
The point to remember
View, edit, download and share events answer different questions. Interpret the provider's event definition first, then use session, device and contextual evidence for the human conclusion.