After an enterprise creates a resource directory, an enterprise management account can create multi-account trails in the ActionTrail console. A multi-account trail can deliver the events of all member accounts in a resource directory to a specified Object Storage Service (OSS) bucket or Log Service Logstore.

The following figure shows how a multi-account trail works with a resource directory.

multi account

Terms

Term Description
enterprise management account

An enterprise management account is the account that is used to enable a resource directory and is the super administrator of the resource directory. The enterprise management account has all administrative permissions on the resource directory and the member accounts in the resource directory. Only an Alibaba Cloud account that has passed enterprise real-name verification can be used as a enterprise management account. Each resource directory has only one enterprise management account.

member account

A member account serves as a container for resources and is also an organizational unit in a resource directory. A member account indicates a project or application. The resources of different member accounts are isolated.

A member account is an account that an enterprise management account invites to join a resource directory or directly creates in a resource directory.

multi-account trail A multi-account trail is a trail that is created in the ActionTrail console by using an enterprise management account . To create a multi-account trail, select Yes for Apply Trail to All Member Accounts when you create the trail. A multi-account trail can deliver the events of all member accounts in a resource directory to a specified OSS bucket or Log Service Logstore.
single-account trail A single-account trail is a trail that is created in the ActionTrail console to track and record the events of the Alibaba Cloud account that is used to create the trail.

Differences between multi-account and single-account trails

Trail type Created by Scope of events Query method Maximum number of trails allowed
Single-account trail Alibaba Cloud account Events of the current account
  • ActionTrail console
  • LookupEvents operation
  • OSS console
  • Log Service console
Five in each region
Multi-account trail Enterprise management account Events of all member accounts
  • Enterprise management account:
    • ActionTrail console
    • LookupEvents operation
  • Member account:
    • OSS console
    • Log Service console
One in each region

Changes of member accounts in a resource directory

When a member account in a resource directory changes, ActionTrail performs the following operations:

  • When the management account invites a member account to join the resource directory or creates a member account in the resource directory, the new member account can view multi-account trails in the trail list. The events of the new member account are automatically delivered to the specified OSS bucket or Log Service Logstore.
  • When a member account is removed from the resource directory, the member account cannot view multi-account trails. The events of the member account are no longer delivered to the specified OSS bucket or Log Service Logstore. However, the events that have been delivered are not automatically deleted.
  • Changes of the resource directory to which a member account belongs do not affect the delivery of events.