Skip to content
Skip to main content
Cloud Services Technical Explainer

How do I identify whether cloud activity was automated?

An event recorded under a user's account may still have been performed by software acting later on that account's authority.

Synchronisation clients, scheduled jobs, backup tools, workflows, scripts and connected applications can all create cloud activity without a person clicking at that moment.

The question to answer
Which system executed the event, what triggered it, and who or what supplied the authority? Those can be three different things.

Start with the execution record

Useful fields may include:

Example cloud event
Operation: FileUploadAccount: dave@northstar.exampleClient: SyncClientApplication ID: APP-203Request ID: REQ-7741Time: 02:00:04 UTC

The account label is only one part of the event.

The client, application and request identifiers may show that a background process performed the technical action.

Separate trigger, configuration and execution

Consider a scheduled backup:

ConfigurationAdministrator creates backup jobSets scope and credentials.
Trigger02:00 schedule firesNo person needs to be present.
ExecutionBackup service reads filesProvider records API activity.
EvidenceJob and provider logs can be joinedRequest IDs, application IDs and times connect the two.

The later access event should not be reported as a contemporaneous manual act by the administrator merely because their account authorised the process.

Pattern is useful but not enough

Regular timing, large volume or activity while the user was absent may suggest automation.

But some automated jobs are irregular and people can also perform repetitive actions.

Use the technical route:

  • client or application ID;
  • service account;
  • token;
  • request/correlation ID;
  • job history;
  • task schedule; and
  • configuration record.

Human relevance may sit earlier in the chain

Automation does not remove the person from the enquiry.

A person may have:

  • created the workflow;
  • approved the application;
  • supplied credentials;
  • changed the schedule; or
  • manually triggered the job.

The practical point is: identify the executing system first, then work backwards to the trigger and configuration. Do not turn an automated provider event into a human action without that bridge.

Reference: CLD-171Cloud Services