Does a saved account prove who used the device?¶
A saved account shows that the device was configured to access that account.
What this means¶
The account may belong to the usual device owner.
But it may also be shared, inherited from a previous user, left signed in after a device was borrowed or restored automatically from a backup.
Several people may know the password or use an already authenticated session.
Some applications maintain access through session tokens, meaning a person can use the account without entering the password again.
A saved account can still be important evidence.
It may connect the device to an email address, username, cloud service, app provider or trusted-device list.
Account history may show when the device was first linked, when it logged in and what other devices accessed the same service.
To attribute activity, ask more precise questions.
Was the account actively used on this device at the relevant time?
Was the action created locally or synchronised from elsewhere?
Which device identifier, IP address or session was involved?
Who possessed and controlled the device then?
Also consider compromise or remote access where there is specific evidence for it.
The operational takeaway is: a saved account links the device to a service, not automatically to a human action. Establish when and how the account was used, then corroborate who controlled the relevant session.
What to check or do next¶
- Look for supporting evidence such as location, notifications, app databases, message content, typing patterns, payment details and witness evidence.
Evidential limits¶
It does not automatically prove who used the device or who performed a particular action.