What should an investigator ask a provider for?¶
An investigator should ask for records linked to a clearly defined account, object, session or event and the investigative question being examined.
Evidential caution: that asking for “all logs” will produce a complete or useful answer.
What this means¶
Relevant requests may include:
account creation and recovery details;
login and session history;
IP and device records;
multi-factor events;
administrative actions;
object creation and access;
message or file metadata;
payment or subscription records;
API activity;
deletion and retention events;
provider alerts;
linked account identifiers.
The request should specify:
the exact identifier;
time range;
time zone;
event type;
whether content or metadata is sought;
whether deleted or historical records are relevant;
the legal basis and urgency.
Provider terminology matters.
A “login,” “session,” “access event” and “API call” may be separate records.
Requests should also distinguish account-level records from event-level records. A provider may return registration and login history without the message, file, object or API event actually under investigation. Ask for the specific records needed to answer the question.
Frame provider requests around the precise account, object, session and question, and ask for native records with their field definitions and retention limits.
================================================================================
What to check or do next¶
- Where possible, ask what the provider actually retains and how the records are generated.
Evidential limits¶
It may not.
Do not assume that one provider product records the same fields as another.
Where the provider cannot supply the requested field, ask whether an alternative record answers the same question. Device, token, access, audit and security records may overlap without being identical. Record what was unavailable rather than assuming it never existed. The operational takeaway is: