This topic introduces the basic terms that are involved in ActionTrail. This helps you better understand and use this service.

Term Description
master account

A master account is the account that is used to enable a resource directory and is the super administrator of the resource directory. The master account has all administrative permissions on the resource directory and the member accounts in the resource directory. Only an Alibaba Cloud account that has passed enterprise real-name verification can be used as a master account. Each resource directory has only one master account.

member account

A member account serves as a container for resources and is also an organizational unit in a resource directory. A member account indicates a project or application. The resources of different member accounts are isolated.

A member account is an account that a master account invites to join a resource directory or creates in a resource directory.

event An event is a log that is generated when you use the Alibaba Cloud Management Console, API operations, or developer tools to access and manage cloud services. An event logs information about an operation, including the operation time, username, resource, operation type, operation result, and source IP address.
platform event A platform event is a log that is generated when the Alibaba Cloud O&M team maintains services for users. You can create a trail for the Inner-ActionTrail feature to deliver platform events to a specified storage object.
global service A global service is a service that applies to all regions of Alibaba Cloud, such as Resource Access Management (RAM). For global services, events are delivered to a trail that includes global services.
global event A global event is a log of a global service. On the Query Event Details page in the ActionTrail console, you can select a region to view all the global events in the region. After you create a trail to deliver events to a specified Object Storage Service (OSS) bucket, global events are logged in the same directory as the events that occur in the home region of the trail.
home region A home region is a region where a trail is created.
trail A trail is created to deliver events to a specified OSS bucket or Log Service Logstore for storage and further analysis. Based on the creator and applicable scope, trails are categorized into single-account trails, multi-account trails, and platform event trails.
single-account trail A single-account trail is a trail that is created to track and record the events of the Alibaba Cloud account that is used to create the trail.
multi-account trail A multi-account trail is a trail that is created by using a master account to track and record the events of all member accounts. A multi-account trail can deliver the events of all member accounts in a resource directory to a specified OSS bucket or Log Service Logstore.
platform event trail A platform event trail is a trail that is created by using an Alibaba Cloud account to deliver platform events to a specified storage object.
shadow trail A shadow trail is a trail that ActionTrail creates by replicating the configurations of the trail that you create to track events in multiple regions. ActionTrail creates a shadow trail in each of the regions to track and record the events in these regions.