How do I distinguish device evidence from cloud evidence?¶
Device and cloud records are separate sources that often describe different stages of one process. Keep their provenance and meanings distinct, then link them through identifiers, content, sessions and time.
Each source observes a different event¶
A device may contain a local file, cache, preview, browser artefact, application database, token or sync record. The provider may retain account details, authentication and session events, sharing, versions, deletion and administrator actions.
A local creation time can describe when an application wrote a file to the device; a cloud event may describe upload; a second device may record later synchronisation. Different timestamps can therefore reconstruct sequence rather than signal an error.
Cloud activity may leave no local copy, while downloaded content may remain after the provider object is deleted.
Join without merging provenance¶
Maintain a source map for the physical device, provider, tenant organisation and connected applications. Preserve each acquisition independently and identify the system that generated every field.
Compare stable file and resource IDs, version IDs, hashes, account and session values, paths and timestamps. Explain whether a match identifies the same content, the same cloud object or merely a related copy.
Do not overwrite one source's values with another or count duplicated provider-derived data as independent corroboration.
The point to remember
Device and cloud evidence observe different technical events. Preserve them separately and make every cross-source link explicit.