Does a provider record prove who performed the action?¶
No. A provider record normally proves activity associated with an account, session, resource or network identifier.
Evidential caution: that the named subscriber or account holder personally performed the action.
What this means¶
The account may be:
shared;
compromised;
automated;
accessed through a stolen token;
used from a shared device;
controlled by an administrator;
operated through an API;
accessed by another person.
authentication method;
device and session identifiers;
source IP and intermediary services;
account recovery changes;
multi-factor events;
API keys;
linked provider accounts;
activity before and after;
communications;
local device evidence.
A provider record may be strong evidence that an account or object was involved.
Personal attribution requires additional evidence of control and use.
Likewise, a provider’s abuse label or intelligence association should not be treated as proof of personal identity.
Provider timestamps and labels should be interpreted according to the provider’s own definitions. A field described as device, location or login may represent inferred, normalised or partial data. Preserve the native record and any explanation of how it was produced.
A provider record may also describe activity performed by the provider itself, such as automated scanning, content processing, synchronisation or security enforcement. Establish whether the event represents customer action, provider automation or a derived alert.
================================================================================
What to check or do next¶
- Investigators should examine:
- Record the event origin and provider interpretation separately so automated service activity is not attributed to the customer without support. The operational takeaway is:
- Use provider records to attribute activity to accounts, sessions and resources, and build personal attribution separately from device, communication and contextual evidence.
Evidential limits¶
They may not have.