What should be recorded about logged-in accounts?¶
Record the service, exact account identifiers and the way the account is presented on the device, while keeping that visible session separate from the question of who controlled it.
Preserve the access context¶
Capture usernames, email addresses, handles, profile URLs, tenant or organisation names and profile images already shown. Note whether the account is open in a browser, dedicated application, managed work profile, virtual machine or remote desktop.
Record visible security or session information such as linked devices, sign-in warnings, administrator status or the presence of multiple profiles without opening additional settings. A display name alone may be changeable or shared; the underlying identifier is usually more useful for later provider enquiries.
Do not log out, refresh, switch profiles or test credentials. Those actions can terminate access, replace session records, alter activity history or notify another user.
Account identity is not user attribution¶
An account may be shared, delegated, compromised, remotely accessed or simply left open. A visible inbox might also be cached rather than backed by a current provider session.
Record what a person says about ownership or use as their account, not as technical proof. Later session, authentication, provider and device records may establish more about access. The first-response observation supports a narrow statement: the identified device displayed this account in this state at this time.
Key takeaway
Preserve exact account and session context without altering access, and do not equate the named account holder with the person responsible for the observed activity.