Skip to content
Skip to main content
Cloud Services Checklist

What is the final investigator checklist for cloud evidence?

Use this when you are getting towards the end of a cloud enquiry and want to make sure nothing important has slipped through the gaps.

This page is not a substitute for the more detailed guidance in the rest of this section. Think of it as the final check before you move on: have you got the right service and account, kept the useful records, understood what they actually show, and avoided jumping straight from an account name to a person?

1. Define the cloud environment

  • [ ] Identify the service and product involved.
  • [ ] Identify the relevant tenant, organisation or workspace where applicable.
  • [ ] Identify the account, application and resource involved.
  • [ ] Record the stable identifiers you will use to join later records.
  • [ ] Identify which organisations or providers may hold relevant evidence.

If the service model itself is unclear, start with the difference between cloud storage, cloud computing and a cloud account and who the cloud provider is.

2. State the investigative question

Be clear about what you are actually trying to find out.

For example:

  • Was a file uploaded, downloaded, deleted or shared?
  • Which account performed an action?
  • Which session or application generated the event?
  • Which device may have been involved?
  • Was the account compromised?
  • Did a linked application or automated process act on the user's behalf?
  • What evidence connects the technical activity to a person?

What does a cloud record actually prove? is the useful reference when the proposition starts to drift.

3. Preserve the volatile material early

  • [ ] Preserve sign-in and authentication records where relevant.
  • [ ] Preserve session and token records where available.
  • [ ] Preserve audit, sharing and permission history.
  • [ ] Preserve deleted-item, recycle-bin or version history where relevant.
  • [ ] Preserve security alerts and compromise indicators.
  • [ ] Preserve application-consent and third-party integration records.
  • [ ] Record the current state before changing permissions or access.

If the account may be compromised, use the urgent-action guidance and cloud-account compromise guidance. Before changing sharing or permissions, use the pre-change preservation checklist.

4. Keep the evidence sources separate

A cloud investigation often spans several evidence holders.

Evidence source What it may contribute
Provider / tenant Sign-in, audit, session, sharing, file and administrative records
Device Local copies, sync state, browser/app use and cached artefacts
Organisation Identity, employment, access rights, asset records and business context
Third-party service Application, workflow, API or delegated-access records
Other participants Recipient, collaborator or linked-account evidence

Do not treat several views of the same provider event as independent corroboration.

5. Preserve identifiers that join records

  • [ ] Account or user ID
  • [ ] Tenant/workspace ID
  • [ ] Resource or file ID
  • [ ] Session or token identifier
  • [ ] Application/client ID
  • [ ] Request/correlation ID
  • [ ] Device identifier
  • [ ] Exact timestamps and time zone
  • [ ] Sharing-link or permission identifier where relevant

These identifiers are often far more useful than friendly names. They give you something solid to match across different records even if a display name has changed.

6. Work out what generated the activity

Ask whether the event was:

  • [ ] direct user activity;
  • [ ] synchronisation from another device;
  • [ ] an automated rule or workflow;
  • [ ] a service account;
  • [ ] a linked third-party application;
  • [ ] a delegated or shared-account action; or
  • [ ] activity from a compromised session.

Use automated cloud activity and linked third-party service activity when those routes are plausible.

7. Keep attribution layered

Before you say who did what, walk through the links one by one:

What are you trying to link? What should you check?
Account Which account or service identity is recorded?
Session Which session, token, client or application generated the event?
Device What connects that activity to a particular device?
Person What independent evidence links the device/account/session to the person?

Does a cloud account identify a person? and can several people use the same cloud account? help when those layers are being collapsed.

8. Check deletion, sharing and synchronisation carefully

  • [ ] If data appears deleted, establish which system recorded the deletion and whether recoverable versions or recycle-bin records exist.
  • [ ] If data was shared, establish who or what had access and how that access was granted.
  • [ ] If data was synchronised, identify which devices or clients may hold copies.
  • [ ] If permissions changed, preserve the state before and after the change.

Use deleted cloud data, external sharing and synchronisation across devices for those specific questions.

9. Record interventions as part of the evidence

If you change the live environment:

  • [ ] record who authorised the action;
  • [ ] record who carried it out;
  • [ ] record the exact time;
  • [ ] record what setting, permission, session or account state changed;
  • [ ] record the provider response; and
  • [ ] verify the effect afterwards.

How should I document cloud-account containment? covers this in more detail.

10. Reconcile the investigation before closing

Before treating the cloud line of enquiry as complete, confirm that:

  • [ ] provider returns and tenant exports have been reconciled;
  • [ ] device findings have been compared with cloud activity;
  • [ ] important timestamps have been normalised and explained;
  • [ ] automation, sharing and third-party routes have been considered where relevant;
  • [ ] conflicting records have been addressed;
  • [ ] missing or unavailable data is documented;
  • [ ] specialist questions have been resolved or explicitly left open; and
  • [ ] the final conclusion says what is established and what remains unproven.

By the end, you want one understandable account of what happened — not six provider exports sitting in separate folders that nobody has joined together.

The final check

Ask yourself:

Can another investigator see which service and account were involved, which records support the important events, how those records were joined, what changed during the enquiry, and exactly where the evidence stops?

If another investigator can follow it without having to reverse-engineer your thinking, you are in a good place to make the next decision.

Reference: CLD-174Cloud Services