What should I request from a cloud provider?¶
Request the provider records that can answer the investigation's defined question, with the accounts, services, record types and period stated precisely. “All cloud data” is neither a clear technical specification nor necessarily a proportionate one.
Match records to the activity in dispute¶
For account access, this may mean login attempts, authentication factors, sessions, token events, devices, applications and recovery changes. For files, it may mean metadata, stable IDs, versions, ownership, sharing, access, edit, download and deletion events. Administrative questions may require role, policy, user, consent, audit-setting and retention changes.
Ask for event-level structured records where available, with original timestamps and zones, outcome codes, event and correlation IDs, source addresses, application IDs and resource identifiers. Provider field definitions and explanatory material help interpret those records without replacing them.
Identify each possible holder¶
The provider, customer organisation, identity provider, connected application and backup service may retain different parts of the same sequence. Establish which entity controls each record set rather than assuming the consumer-facing provider holds everything.
The correct legal route, jurisdiction and provider process must follow current local procedure. An urgent preservation request may be necessary before the acquisition route is complete, but the two have different effects.
Where a standard provider form is used, fit the technical detail into it without losing exact identifiers, time scope or record definitions.
The point to remember
Define the evidence question first, then request the specific event-level records and identifiers needed to answer it from each relevant data holder.