Does an account name prove who used the application?¶
No. It can identify a claimed, configured or displayed account identity without identifying the person controlling a particular session.
Prefer stable account evidence¶
Separate display name, username, email, telephone number, service account ID, device registration and authentication material. A display name may be false, imported or outdated. A stable provider ID is stronger for linking records but still identifies the service account rather than its human operator.
Build from account to control¶
Determine whether the account was actively signed in, merely stored, restored or synchronised. Link sessions, devices, authentication, provider network records and local activity to possession and corroborating human evidence. Sharing, compromise, automation or another linked client may explain an individual event.
Key takeaway
Move from the account identifier to the relevant session, device and human control before attributing an action.