What does a successful login event prove?¶
A successful login event proves that the system accepted an authentication process for an account or session. It does not, on its own, prove which person supplied or controlled the accepted credential.
“Success” depends on the authentication method¶
Access may use a password, biometric, security key, certificate, remembered session, token or federated identity provider. A broad success label can therefore cover primary sign-in, single sign-on, token validation or additional verification.
The event may identify the account, application, device, source address, method and resulting session. Those fields establish how the service granted access and provide anchors for later actions.
Separate system acceptance from personal attribution¶
Obtain the provider's event and method definitions. Link the login to multi-factor, identity-provider, device, session and token records. Shared or stolen credentials, unattended applications and remote control remain possible unless other evidence excludes them.
Use wording such as “the service accepted authentication for the account from the recorded source”. Saying that a named person logged in is a further inference requiring evidence that they controlled the credential, device and resulting session.
The point to remember
Login success establishes accepted authentication, not automatically the identity of the person behind it.