The record that answers what happened, months later.
CloudTrail records API activity across AWS accounts, producing the trail that attributes an action to a principal. Our work is configuring the evidence trail so actions by people and agents remain attributable.
CloudTrail is the audit trail for AWS. Its value is decided long before it is needed, by whether anyone configured it to retain what a question will actually require.
What it is
CloudTrail records API activity across AWS accounts, producing the trail that attributes an action to a principal.
It is for organizations who will eventually be asked what an agent, a workload, or a person did, and would rather that question have an answer.
What it does
Actions attributed to a principal
Which is the whole basis of accountability in a cloud estate.
Retention decided in advance
A trail configured after the question is asked answers nothing.
Where it fits
L3, governance and change. Evidence is a governance instrument. A permission model tells you what was allowed; the trail tells you what happened. Agents make the second question far more common, because a system acting on its own schedule cannot be asked afterwards.
What we do with it
Making the trail answer real questions
Configuring what is retained against the questions an audit or an incident will actually pose.
Attribution for non-human actors
Ensuring workloads and agents act as identities the trail can name.
Reviewing what the trail shows
Evidence is only useful if somebody reads it on a cadence.
Where it earns its place
A regulated estate with agents in production
An action taken autonomously has to be attributable, and that is a configuration decision.
An organization after an incident
The trail either covers the window or it does not, and that was decided months earlier.