Several accounts share the same device identifier. One linked account has enforcement history, making the cluster useful for review and graph-based pivoting.
- Login events.
- Device identifiers.
- Enforcement records.
- Generated case rows.
shared_infra.sqlshared_infrastructure.sql
The investigator starts from the subject user, pivots to the shared device, then reviews linked accounts and enforcement context. The graph helps make the relationship visible, while the timeline helps place the shared infrastructure events in sequence.
Shared infrastructure alone may not justify escalation; investigators should monitor for additional corroborating indicators.
Use UNDER_REVIEW for isolated shared-infrastructure cases; use REFERRED if the case should be reviewed by another policy or platform-integrity specialist.