Skip to content
FRP-018 Fraud & Financial Crime

What should be recorded about logged-in accounts?

A logged-in account may provide valuable evidence about current access, but it does not by itself identify the person who is using it.

Evidential caution: that the visible account holder must be the current user. Accounts may be shared, compromised, remotely accessed, left open or used through delegated permissions.

What this means

Specialists or providers may later establish more about session history, authentication and linked devices. The first-response task is to preserve the visible access state without turning preservation into a search.

What to check or do next

  • Record the service or application, the visible username, email address, account handle, profile URL, tenant or organisation name and any account image shown. Capture exact identifiers rather than relying on a display name.
  • Record any visible session, device or security information without navigating unnecessarily. This may include linked devices, sign-in alerts, administrator status, profile-switching options or indications that several accounts are available.
  • Do not log out, switch accounts, refresh the page or open security settings simply to investigate further. Those actions may terminate sessions, alter activity history or alert another user.
  • Record the relationship between the account and the device. Is the account open in a browser, dedicated application, remote desktop, virtual machine or managed work profile? That context may matter later.
  • If the person present says they own or control the account, record that as an account of what they said, not as technical proof.

Evidential limits

Note whether the account appears fully authenticated, partly authenticated or simply displaying cached information. A visible inbox or profile does not always prove that a live provider session is active.

Where more than one account is visible, record each separately. Do not assume the first account displayed is the relevant one.

Operational takeaway

Record exact account and session context as displayed, but keep account identity separate from the question of who was actually using it.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.