A multi-account trail is an ActionTrail trail that records the management events of all members in a resource directory and delivers them to Object Storage Service (OSS) or Simple Log Service (SLS). An enterprise that has enabled a resource directory can therefore keep a long-term record of the management events of all members in the resource directory.
How a multi-account trail works
By default, ActionTrail records only the management events of the last 90 days for each Alibaba Cloud account. To record management events for a longer period, you must create a trail. Otherwise, you cannot trace management events that occurred more than 90 days ago.
A multi-account trail extends this long-term record from a single account to an entire resource directory. After an enterprise enables a resource directory, either the management account or a delegated administrator account of that resource directory can create a multi-account trail in ActionTrail.
The trail delivers the management events of all members in the resource directory to an OSS bucket or an SLS Logstore.
The following figure shows how a multi-account trail works with a resource directory.

Resource directory terms
A multi-account trail operates on the accounts of a resource directory. The following table describes the resource directory terms that this topic uses.
| Term | Description |
| management account | The super administrator of a resource directory and the initial account that enables the resource directory. It has full control over the resource directory that it creates and over the members in that directory. Only an Alibaba Cloud account that has completed enterprise identity verification can enable a resource directory. Each resource directory has exactly one management account. |
| member | A resource container in a resource directory and a unit for grouping resources. A member usually represents a project or an application. The resources in each member are physically isolated from the resources in other members. The management account can grant Resource Access Management (RAM) users, RAM user groups, or RAM roles access permissions to the resources in a member. The management account either creates a member directly in the resource directory or invites an account to join the resource directory as a member. |
| delegated administrator account | A member that the management account sets as the delegated administrator account for a trusted service. After the setting takes effect, the delegated administrator account obtains authorization from the management account. It can then access the organization and member information of the resource directory in the corresponding trusted service and manage business within the scope of that organization. |
Changes to members in a resource directory
When the members in a resource directory change, ActionTrail handles the multi-account trail as follows:
A member joins the resource directory — When the management account creates a new member or invites an account to join, the new member can view the multi-account trail in the trail list. ActionTrail automatically delivers the management events of the new member to the OSS bucket or SLS Logstore configured for the trail.
A member is removed from the resource directory — The member can no longer view the multi-account trail, and ActionTrail stops delivering the management events of that member to the OSS bucket or SLS Logstore configured for the trail. Management events that were already delivered are not deleted automatically.
A member is moved to a different resource directory — Event delivery is not affected.