Term | Description |
trail | A trail is used to deliver events to an OSS bucket or a Simple Log Service Logstore for storage and further analysis. ActionTrail supports single-account trails, multi-account trails, and trails for the Inner-ActionTrail feature. These types of trails vary based on the creator, effective scope, and delivery content. |
single-account trail | An individual user can create a single-account trail to deliver events to Simple Log Service or OSS. An individual user can create multiple single-account trails to perform the following operations: Assign different types of events to different roles for auditing. Manage the audit data for multiple regions in a compliant manner. Create multiple replicas for an event.
For more information about single-account trails, see Single-account trail overview. |
multi-account trail | After an enterprise user creates a resource directory, the management account of the resource directory can create a multi-account trail to deliver the events of all members in the resource directory to a Simple Log Service Logstore or an OSS bucket. For more information about multi-account trails, see Overview. |
trail for the Inner-ActionTrail feature | An individual user can create a trail for the Inner-ActionTrail feature to deliver events that are generated when the Alibaba Cloud O&M team maintains services of the user to a Simple Log Service Logstore. For more information, see the Inner-ActionTrail overview. |
management account | A management account is used to enable a resource directory and serves as the super administrator of the resource directory. The management account has all administrative permissions on the resource directory and the members in the resource directory. You can use only an Alibaba Cloud account that passed enterprise real-name verification as a management account. Each resource directory can have only one management account. |
member | A member serves as a container for resources and is also an organizational unit in a resource directory. A member indicates a project or application. The resources of different members are isolated. You can use a management account to grant RAM users, user groups, or RAM roles the permissions to access the resources of members. You can also use the management account to create a member in the resource directory or invite an Alibaba Cloud account to join the resource directory as a member. |
delegated administrator account | The management account of a resource directory can be used to specify a member in the resource directory as a delegated administrator account of a trusted service. After a member is specified as a delegated administrator account of a trusted service, the member can be used to access information about the resource directory in the trusted service. The information includes the structure and members of the resource directory. The member can also be used to manage business within the resource directory. For more information about delegated administrator accounts, see Manage a delegated administrator account. |