Should I ask for raw cloud logs or a provider summary?¶
Where available and proportionate, seek the underlying event-level records with their field definitions. A provider summary may explain the system or answer a focused question, but it should not silently replace source records that preserve more detail.
“Raw” needs a definition¶
An original structured export may retain precise timestamps, outcome codes, event, session and correlation IDs, application details, resource IDs and source addresses. Those fields allow events to be tested and linked across systems.
A spreadsheet produced from a dashboard is not automatically raw: it may be filtered, grouped, normalised or truncated. Ask how the export was generated, what source systems and filters were used, whether any fields were omitted and whether event-level records remain retained. Preserve the supplied files in their original format before transforming them for analysis.
Use explanation alongside evidence¶
Provider narratives can define architecture, translate codes or explain why records are unavailable. Record who prepared a summary, their role, its date, the systems consulted and stated limitations. Keep it alongside - not embedded in place of - the technical material it interprets.
Sometimes only a summary can be disclosed, or specialist explanation is necessary to understand a complex system. That does not make the summary worthless; it means its evidential basis and limitations must be clear. If source records still exist, consider whether the appropriate process can obtain them later.
The point to remember
Prefer event-level records with definitions, and use provider summaries to explain their source and limitations rather than treating a simplified narrative as the complete record.