Skip to content
Skip to main content
Logs, Records & Provider Evidence Operational Explainer

How should authentication events be attributed to a person?

Begin with the technical fact that a system accepted or rejected authentication for an identity. Attribute it to a person only through corroboration about credential, device and session control.

Relevant factors include authentication method, individually assigned devices, physical possession, source network, session continuity, communications and actions before and after access. Stronger attribution usually comes from several mutually consistent sources rather than one account name.

Test realistic alternatives: shared or stolen credentials, remembered sessions, remote access, automation, administrator action and compromised devices. The mere possibility of an alternative does not defeat evidence, but material alternatives should be evaluated rather than ignored.

Keep observation and inference distinct

Record provider fields and definitions, then state exactly what they establish. If the combined evidence supports association but not certainty, wording such as “consistent with use by” may be more accurate than “proves the person logged in”.

Preserve the records used for the link and identify any assumptions about ownership, time or location. This makes the strength and limits of personal attribution open to review.

The point to remember

Personal attribution comes from a corroborated chain of control, not from the account label in an authentication event.

Reference: LOG-100Logs, Records & Provider Evidence