Agentic SOC, a service within Security Center, helps you centralize the processing of alerts and log data from multi-cloud environments, multiple accounts, and various products to improve security operations efficiency. You can use Resource Directory (RD) from Resource Management, the multi-account security management feature of Security Center, and Agentic SOC to centrally manage multiple accounts and resources across your enterprise. This topic describes how to configure a multi-account structure for Agentic SOC.
Key concepts
Before you use Agentic SOC to centrally manage multiple accounts and resources, understand the following concepts.
Concept | Description | Product |
management account | A management account (MA) is an Alibaba Cloud account that has completed enterprise real-name verification. You can use a management account to enable a resource directory. After enabling the resource directory, the management account becomes its super administrator, granting it full control over the resource directory, folders, and members. Each resource directory has only one management account. | Resource Management |
member | A member is a resource account created within a resource directory. This account is used to host a specific project or application on Alibaba Cloud. If you already have an Alibaba Cloud account, you can also invite it to join the resource directory as a cloud account-type member. | |
delegated administrator | The management account of a resource directory can designate a member as the delegated administrator for a trusted service. Once designated, the delegated administrator receives authorization from the management account. This authorization allows the delegated administrator to access organizational and member information within the resource directory for that trusted service and manage service operations across the organization. | |
global administrator | When using Agentic SOC on the console, a global administrator can switch to the global account view. In this view, they can configure cloud service log ingestion policies and threat detection rules for all Alibaba Cloud accounts managed by Agentic SOC, and handle security events. | Security Center |
Multi-account structure
When you use Agentic SOC to manage data across multiple Alibaba Cloud accounts, consider the following common scenario. Use this example and the diagram to help build your multi-account structure.
Typical scenario: Alibaba Cloud accounts A, B, C, D, and E belong to the same resource directory. Account A is the management account of the resource directory, and accounts B, C, D, and E are members. Account A designates Account B as the delegated administrator for the trusted service Security Center-Threat Analysis. This designation allows Account B to centrally manage log ingestion, threat detection settings, and event response for accounts B, C, D, and E in Agentic SOC.
Step 1: Purchase Agentic SOC
Each Alibaba Cloud account that needs to ingest logs into Agentic SOC must purchase log ingestion traffic. The global administrator can centrally manage only Alibaba Cloud accounts that have purchased log ingestion traffic for Agentic SOC. For more information, see What is Agentic SOC (formerly Threat Analysis and Response).
If your Alibaba Cloud account purchased the service before Agentic SOC adjusted its billing items, member accounts within its resource directory do not need to purchase Agentic SOC. For more information, see [Notice] Billing Changes for Agentic SOC.
Step 2: Build a multi-account structure
Only Alibaba Cloud accounts that share the same enterprise real-name verification can be added to the same resource directory. Enable the Resource Directory service and designate an Alibaba Cloud account that has purchased Agentic SOC as the delegated administrator.
Use your management account to log on to the Resource Management console.
If this is your first time using Resource Directory, in the left-side navigation pane, choose , and then click Enable Resource Directory. Follow the on-screen instructions to complete the process. For more information, see Enable a resource directory.
Create members for the resource directory or invite other Alibaba Cloud accounts to join.
To create a member: In the left-side navigation pane, choose to create a resource account. For more information, see Create a member.
To invite a member: Choose to add another Alibaba Cloud account to the resource directory. For more information, see Invite an Alibaba Cloud account to join a resource directory.
Designate the Alibaba Cloud account that has purchased Agentic SOC as the delegated administrator.
In the left-side navigation pane, choose . In the Actions column for both Security Center and Security Center - Threat Analysis, click Manage. Add the Alibaba Cloud account that has purchased Agentic SOC as the delegated administrator for these two trusted services. For more information, see Add a delegated administrator account.

Step 3: Onboard accounts to Agentic SOC
Use the Alibaba Cloud account that has purchased Agentic SOC to log on to the Security Center console.
In the left-side navigation pane, choose . In the upper-left corner on the console, select the region where your assets are located: Chinese Mainland or Outside Chinese Mainland.
If this is the first time you are using the multi-account security management feature, click Enable Management in Security Center.
After enabling this feature, the system automatically creates the AliyunServiceRoleForSasRd service-linked role in the member accounts. In a multi-account setup, this role allows the delegated administrator of Security Center to access the Security Center console of member accounts. You can then centrally configure security protection and monitor security risks in real time across all member accounts.
On the and click the Agentic SOC Monitoring Accounts sub-tab.
If the Configure tab is not visible on the console, directly click the Agentic SOC Monitoring Accounts tab.
In the Total Monitored Accounts section, click Account Management.
In the Multi-account Management Settings panel, select the resource directory members that you want to add to Agentic SOC, and then click OK.
If the AliyunServiceRoleForSasRd and AliyunServiceRoleForSasCloudSiem service-linked roles do not exist for a member account, this action creates them. These roles are required to enable the corresponding features. For more information, see Service-linked roles for Security Center.
Step 4: Configure the global administrator
A global administrator can switch between the global account view and current account view in Agentic SOC. The global account view allows you to configure cloud service log ingestion policies, threat detection rules, and handle security events for all managed Alibaba Cloud accounts. The current account view allows you to configure policies for the current account only. Follow these steps to set the Alibaba Cloud account that has purchased Agentic SOC as the global administrator.
Only one account per resource directory can be set as the global administrator for Agentic SOC in Security Center.
The global administrator designation cannot be changed. Proceed with caution.
On the Agentic SOC Monitoring Accounts tab, in the Global Administrator Account section, click Settings.
In the Specify Global Administrator Account dialog box, select the Alibaba Cloud account to be designated as the global administrator, and then click OK.
The account designated as the global administrator must be either the management account or the delegated administrator for the Security Center-Threat Analysis trusted service on the Resource Management console. The account must also have purchased Agentic SOC.
Step 5: Ingest cloud service logs
As the global administrator, you can ingest cloud service logs from the current account, managed accounts, and third-party cloud accounts. This enables unified monitoring and analysis of alerts and log data across all accounts.
To ingest logs from Alibaba Cloud services, see Ingest logs from Alibaba Cloud services.
To ingest logs from third-party cloud services, see Ingest logs from third-party cloud services.
Step 6: Use Agentic SOC
After completing the preceding steps, you can use Agentic SOC features such as event analysis and response orchestration. The global administrator can manage both the current account and all managed accounts by switching between the current account view and global account view on the console.

For more information about the features and usage of Agentic SOC, see the following topics:
Configure threat detection rules: Configure predefined and custom rules for detecting events.
Security events: Handle security events to enhance the security of your cloud systems.
Response rules: Orchestrate and connect different systems or services to automate security operations and enable rapid response.
Log management: Store and query standardized logs from cloud services to accurately locate various alerts, trace attack sources, accelerate your response to potential threats, and simplify log management across multiple resources.
References
Security Center supports multi-account security management. For more information about the multi-account settings for Security Center and Agentic SOC, see Multi-account security management.
For more information about Resource Directory, see What is Resource Directory?.