How do I identify whether cloud activity was automated?¶
An event recorded under a user's account may still have been performed by software acting later on that account's authority.
Synchronisation clients, scheduled jobs, backup tools, workflows, scripts and connected applications can all create cloud activity without a person clicking at that moment.
Start with the execution record¶
Useful fields may include:
FileUploadAccount: dave@northstar.exampleClient: SyncClientApplication ID: APP-203Request ID: REQ-7741Time: 02:00:04 UTCThe account label is only one part of the event.
The client, application and request identifiers may show that a background process performed the technical action.
Separate trigger, configuration and execution¶
Consider a scheduled backup:
The later access event should not be reported as a contemporaneous manual act by the administrator merely because their account authorised the process.
Pattern is useful but not enough¶
Regular timing, large volume or activity while the user was absent may suggest automation.
But some automated jobs are irregular and people can also perform repetitive actions.
Use the technical route:
- client or application ID;
- service account;
- token;
- request/correlation ID;
- job history;
- task schedule; and
- configuration record.
Human relevance may sit earlier in the chain¶
Automation does not remove the person from the enquiry.
A person may have:
- created the workflow;
- approved the application;
- supplied credentials;
- changed the schedule; or
- manually triggered the job.
The practical point is: identify the executing system first, then work backwards to the trigger and configuration. Do not turn an automated provider event into a human action without that bridge.