To uniquely identify the user, we should modify the scan queue request endpoint and scope it to the active ACL user. Like this, we can reliably detect who sent the request.
Additionally, we can add some unx info like hostname and username, albeit we cannot guarantee that it is correct