Skip to content
Skip to main content
Cloud Services Technical Explainer

What is application information in a cloud event?

Application information identifies the software route that requested or performed a cloud action. It can distinguish a browser, mobile app, sync client, API tool, security product or third-party integration.

Prefer stable identity over display name

Preserve application/client ID, displayed name, publisher, version, permissions, session/token and event type. Names can change or be copied; the underlying ID and publisher/tenant records are usually stronger.

An application may act interactively or in the background under delegated authority granted earlier. An unfamiliar app can indicate compromise, but may also be legitimate automation or a provider component.

Test expected purpose

For organisation-managed software, deployment, approval, ownership and configuration records can show whether the event fits normal use. Consent and token records explain the authority available to the app.

State that the application generated the event, then separately address the person who approved, configured or used it.

The point to remember

Application fields explain the software route behind an event. Preserve stable client identity, permissions and token context before assigning the action to a user.

Reference: CLD-117Cloud Services