What can cloud records prove about an account?¶
Cloud records may prove that a particular provider account existed and was associated with defined activity.
Evidential caution: that proving the account proves the person behind it.
What this means¶
Provider records may show the account ID, tenant, username, aliases, recovery details, creation time, login events, sessions, devices, applications and file activity.
They may also show changes to credentials, permissions, sharing and administrator roles.
Those records can establish that the account was used, altered or connected to particular resources.
But they do not automatically prove who controlled it at each moment.
The account may be shared, compromised, delegated to an application or accessed through a remembered session.
Then link the account activity to sessions, devices, applications, IP addresses and wider evidence.
The strength of the conclusion depends on the number and independence of the supporting sources.
Account creation records may also show who supplied contact or recovery details, but those details may be false, shared or later changed and should not be treated as identity proof alone.
Where recovery details or aliases are used for attribution, establish when they were added and whether they were verified. A later change should not be projected backwards onto earlier account activity.
What to check or do next¶
- Investigators should separate account identity from user identity.
- Establish the stable provider identifiers first.
- Use precise wording. Say that the provider attributed the event to the account and explain the additional evidence connecting that account activity to a person.
Evidential limits¶
Where the account holder, subscriber or organisation is known, do not assume they performed every action.
Operational takeaway
Cloud records can establish that an account existed and was associated with activity, but personal control and responsibility require separate corroboration.