When Client admins move an object or reset a password, the responsible userid for this action is not reported on in CG.
The service ID is reported as responsible for the change; and this only happens if the change is done through DRA.
If it is done natively in AD, the responsible admin ID can be reported.
DRA does not make any attribute changes on the object when either of these changes are initiated. Which is why only the Service account is displayed, and not the admin’s ID.