Skip to content
Skip to main content
Cloud Services Technical Explainer

What can cloud records prove about an account?

Cloud records can establish that a provider account existed, its stable identifiers and configuration, and that the provider associated it with defined activity. They do not automatically establish who controlled it for each event.

Build the account history

Provider and tenant records may show account ID, tenant, usernames and aliases, creation and closure, recovery details, authentication factors, sessions, devices, applications, files, permissions and administrative roles. Changes to those features can reveal how account control developed over time.

Use stable IDs rather than display names to link events. Record when aliases, telephone numbers or recovery addresses were added, verified, changed or removed. A current contact detail should not be projected backwards onto earlier activity, and supplied information may be false or shared.

Keep account identity separate from user identity

An account event may result from its subscriber, another authorised user, a delegated application, a remembered or stolen session, or compromised credentials. Even where an organisation or account holder is known, that does not assign every action to them.

Link the account to particular sessions, access methods, devices and wider evidence. Use wording that preserves the provider's attribution - for example, that its audit service recorded the account ID performing an operation - then explain the independent evidence connecting that technical actor to a person.

The point to remember

Cloud records can prove account existence, state and provider-attributed activity. Personal control requires a separate, event-specific evidential link.

Reference: CLD-141Cloud Services