Skip to content
Skip to main content
Cloud Services Technical Explainer

What can cloud records prove about a person?

Cloud records usually identify technical actors - accounts, sessions, applications, devices and connections - not the person physically responsible. Personal attribution is built by connecting those records to independent evidence for the particular event.

Construct the attribution chain

Start with the precise provider event and stable account, session, application, device and resource identifiers. Then test who could control each element at that time.

Corroboration may include possession and examination of a device, local session artefacts, communications, work schedules, physical access records, CCTV, witness evidence and patterns of known use. Sources are strongest when independently derived; several fields or dashboards produced from one provider log do not become separate corroboration simply through repetition.

Test alternatives as part of the conclusion

Consider account sharing, credential compromise, stolen sessions, remote access, delegated applications and automation. A person may have configured an automated workflow without being present when it later ran. Repeated behaviour can add context but should not substitute for evidence linking the disputed action.

State what the provider recorded first, then explain the links to the individual and the remaining alternatives. Where the evidence is mixed, distinguish what is possible, what it supports and what it cannot determine rather than allowing a named account or device label to carry the attribution.

The point to remember

Personal attribution requires an event-specific chain from cloud account or session to device, context and independent real-world evidence.

Reference: CLD-143Cloud Services