Skip to content
CIM-232 Cyber Incidents & Offender Methods

Does authorised access mean the activity was legitimate?

The practical answer

No. Authorised access does not automatically make every action legitimate.

The key evidential caution

The dangerous assumption is that if a user was allowed into the system, whatever they did inside it was authorised.

Access may be limited by:

Key points

  • role
  • purpose
  • time
  • data type
  • case assignment
  • customer relationship
  • approval
  • location
  • specific instructions

A user may be entitled to view one record but not another.

They may be allowed to export data only for an approved purpose.

They may have administrative capability but no authority to use it for personal, commercial or investigative curiosity.

What investigators should establish

Investigators should establish:

Key points

  • what access was technically possible
  • what access was organisationally authorised
  • what purpose applied
  • what approval existed
  • what action was performed
  • whether the person knew or should have known the limitation

Technical permission and lawful or policy authority are different questions.

Evidential limits

Do not rely only on system permissions.

Poorly designed access controls may allow far more than the role requires.

Likewise, a policy breach does not automatically prove criminal or malicious intent.

The context, communications and resulting use matter.

Where policy is relied upon, confirm that it applied to the person, system and period and that the user had been informed of it. A written rule can support the authority assessment, but it should not replace evidence of the actual business process or instruction.

Where authority changed during the incident, preserve the timing. Temporary assignments, emergency roles, suspension or revoked permissions may mean an action was authorised at one point and unauthorised later. The assessment should follow the authority that existed when the action occurred.

Operational takeaway

Separate technical capability from authorised purpose, and assess whether the specific action was permitted, necessary and consistent with the user’s role.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.