Does an account name prove who created the file?¶
No. An account name does not prove who created a cloud file.
It shows the digital identity the service associated with the creation or upload event.
What this means in practice¶
The account may be shared, compromised or accessed through a remembered session. An application, service account or linked device may create the file under that account.
Where authorship matters, compare cloud records with device evidence, communications, work patterns and other corroboration.
Use precise language. Say that the service attributed creation or upload to the account and separately explain the evidence linking that account activity to a person.
What this may show¶
The displayed account name may also be changeable, duplicated or outdated. Internal user IDs and tenant context are usually more reliable identifiers.
Investigators should identify the account ID, session, application, device, IP address, timestamp and file-creation route.
Version history and audit logs may show additional editors or ownership changes.
Also check whether the account display name changed after the event. A current name may be shown against historical activity even though the account used a different visible identifier at the time.
What this does not show on its own¶
The dangerous assumption is that the name beside the file identifies the human creator.
What to do next¶
Check whether the file was uploaded, synchronised, generated automatically or copied from another user.
Do not assume that the current owner was the original creator. Ownership may have been transferred or inherited.
Key takeaway
An account name identifies the cloud identity associated with the event, not automatically the person who created the file, so corroborate the account, session and creation route.