Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could another household or workplace user control the device?

Yes. Physical possession and the visible account do not establish sole control: household members, employees, administrators, support staff and remote services may all affect the same device.

Look for shared and delegated access

Record where the device was found, who could physically use it, who knows the passcode and who has administrator or management rights. Preserve visible profiles, logged-in sessions, account-switching options, shared credentials and remote-access indicators without opening other users' accounts merely to test them.

In homes, family accounts, parental controls, common tablets and automatic synchronisation can mix activity. In workplaces, domains, virtual desktops, delegated mailboxes, shared drives, management tools and support access add other control paths. Record whether an employer, school, household member or provider owns or manages the equipment.

Separate capability from authorship

Another user may change or delete content through cloud services or a linked device after the item is preserved. That risk may justify specialist advice or proportionate account action, but the evidence should retain competing explanations.

An administrator's access does not show they created a user's files, just as an account name does not show who operated it at a particular time. Correlate profiles and permissions with sessions, timings and other records before attributing conduct.

Key takeaway

Treat household and workplace devices as potentially multi-user systems, preserving physical, account, administrative and remote-control routes without equating access capability with authorship.

Reference: FRP-183First Response & Preservation