Does file access prove data theft?¶
No. A file may be listed, previewed, scanned, synchronised or opened without being copied or removed. Access proves interaction at the level recorded by the source.
Identify what the event means¶
Preserve the file, account, process, access type and time. Product fields such as preview, read, download, export and sync may describe different operations more precisely than a generic access label.
Applications can create caches, thumbnails and temporary files from one user action. Indexing, antivirus and backup may produce further events. Avoid counting these derived accesses as independent evidence that a person viewed the content.
Follow the wider sequence¶
Determine whether content was copied, exported, archived or followed by transfer. Targeted searches, selective reads, archive creation and an outbound upload form a stronger chain than access alone.
Recent-item or metadata records may be incomplete and do not prove the full file was viewed. The account may also be remotely controlled or automated, so connect access to the responsible session before personal attribution.
Key takeaway
Treat file access as a specific interaction event and require separate copying, staging or transfer evidence before concluding theft.