filesaudit.com

9/9/2026

How to See Who Created or Last Edited a Word Document

Determining who created a Word document is often a primary requirement in legal disputes, investigative journalism, or even simple administrative audits. When you work with a .docx file, the document contains more than just text and formatting choices; it carries a wealth of hidden metadata that acts as a digital footprint of its history. This data typically includes the name of the original author, the last person to save the file, and specific timestamps for both creation and last modification. However, this information is not always visible to the casual observer. To find it, you must dig into the file's internal properties using built-in tools or specialized forensic platforms.

The most basic way for a standard user to view this information is directly through the Microsoft Word interface itself. By clicking on the "File" tab and selecting "Info," you can see a panel that displays the "Related People." Here, the "Author" field usually lists the name registered with the Office installation that was used when the document was first created. But it is important to note that this field reflects the software's settings rather than necessarily the verified legal identity of the person. If a user used a generic name or a pseudonym during installation, the metadata will reflect that choice. For a more deep dive into what these fields actually represent, you can consult this detailed guide on docx metadata to understand how Word structures these properties.

Beyond the software interface, Windows users can access similar data through the file system properties. By right-clicking on the file, selecting "Properties," and navigating to the "Details" tab, you will see a variety of fields including the "Authors" and "Last saved by." This is a quick way to get a baseline, but these fields are frequently stripped or altered during file transfers. For instance, if a document was downloaded from a web portal or sent through certain email clients, the original author information might be wiped out or replaced with the name of the person who performed the download. In professional environments where data integrity is paramount, relying on basic OS-level properties is often insufficient because they are so easy to manipulate.

When the stakes are high, such as in a copyright dispute or a cybersecurity investigation, you need a more robust forensic approach. This is where platforms like FilesAudit become essential because they perform a deep technical extraction that standard office suites might miss. Instead of just showing you a name field, a forensic tool can analyze the underlying XML structure of the .docx container—which is essentially a compressed archive of files—to find hidden revision history, editing durations, and application version strings that provide context to who was actually working. This level of analysis provides a technical fingerprint that is much harder to forge than a simple name field in a properties box.

It is also vital to distinguish between the creator of the file and the creator of the content. The "Author" field usually tracks the person who initiated the file, while the "Last Saved by" field tracks the most recent contributor to hit the save button. In collaborative environments, these names shift frequently as team members pass the document around. If you are trying to prove that a specific individual authored a document, you must also look at the "Total Editing Time" metric, which can either corroborate or contradict the narrative provided. If a document claims to be fifty pages long but shows only two minutes of editing time, it suggests that the content was likely copied and pasted from another source rather than written from scratch.

For those handling large volumes of documents, checking each file manually is impossible. Professional analysts often turn to the FilesAudit Desktop App to perform bulk metadata analysis, allowing them to extract information from hundreds of Word files simultaneously. This allows for the identification of patterns, such as seeing the same author ID appearing across an entire project folder. By generating cryptographic hashes like SHA-256 alongside the metadata, you can also ensure that the document you are analyzing has not been tampered with since its acquisition, providing a verifiable chain of custody for the digital evidence.

Ultimately, while metadata provides powerful clues about a document's origin, it serves as technical evidence rather than a definitive legal conclusion. A file can tell you that a user named "John Doe" created the document, but it cannot prove that John Doe was physically sitting behind the keyboard at that moment. It provides the "what" that a lawyer or investigator then uses to build a case. By combining deep metadata extraction with file fingerprinting and forensic reporting, you can create a comprehensive picture of a document's lifecycle that goes far beyond what is visible on the screen.

Ready to see what's hidden in your own files? Upload a file to FilesAudit and get a free forensic metadata report in seconds — no registration required.