Skip to content
CLD-083 Cloud Services

Cloud ServicesCLD-083

Does an account name prove who created the file?

No. An account name does not prove who created a cloud file.

It shows the digital identity the service associated with the creation or upload event.

What this means in practice

The account may be shared, compromised or accessed through a remembered session. An application, service account or linked device may create the file under that account.

Where authorship matters, compare cloud records with device evidence, communications, work patterns and other corroboration.

Use precise language. Say that the service attributed creation or upload to the account and separately explain the evidence linking that account activity to a person.

What this may show

The displayed account name may also be changeable, duplicated or outdated. Internal user IDs and tenant context are usually more reliable identifiers.

Investigators should identify the account ID, session, application, device, IP address, timestamp and file-creation route.

Version history and audit logs may show additional editors or ownership changes.

Also check whether the account display name changed after the event. A current name may be shown against historical activity even though the account used a different visible identifier at the time.

What this does not show on its own

The dangerous assumption is that the name beside the file identifies the human creator.

What to do next

Check whether the file was uploaded, synchronised, generated automatically or copied from another user.

Do not assume that the current owner was the original creator. Ownership may have been transferred or inherited.

Key takeaway

An account name identifies the cloud identity associated with the event, not automatically the person who created the file, so corroborate the account, session and creation route.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.