View cross-account executions

Updated at:

Operation Orchestration Service (OOS) integrates with Resource Directory to let a delegated administrator view execution lists and details for member accounts from a central location, without logging in to each account individually.

How it works

Cross-account viewing in OOS relies on trusted service integration with Resource Directory and consists of two stages:

  1. OOS accesses Resource Directory as a management account or delegated administrator to retrieve the organization's member list and folder structure.

  2. The management account or delegated administrator can then query execution data from each managed account.

When you view the cross-account execution list, OOS concurrently fetches and aggregates execution data from each member account.

Prerequisites

Ensure that you meet the following prerequisites:

  • Resource Directory is enabled. For more information, see Enable Resource Directory.

  • Your current account must be either the management account of Resource Directory or a delegated administrator for OOS.

Procedure

Step 1: Set up a delegated administrator

A delegated administrator can manage OOS cross-account features for the entire organization.

Important

You must perform this operation using the management account of your Resource Directory.

  1. Log on to the Resource Management console using the management account.

  2. In the navigation pane on the left, click Trusted Services.

  3. In the list of trusted services, find CloudOps Orchestration Service and click Manage.

  4. On the delegated administrator page, add a member account and designate it as the delegated administrator for OOS.

Step 2: Enable multi-account management

Log on to the OOS console as the delegated administrator and enable the Multi-Account Management feature.

  1. Log on to the OOS console.

  2. In the navigation pane on the left, click Multi-Account Management.

  3. On the Multi-Account Management page, click Enable Multi-Account Management.

Step 3: Configure managed accounts

After you enable Multi-Account Management, select the folders that contain the accounts to manage.

  1. On the Multi-Account Management page, click Configure Managed Accounts.

  2. In the list of folders, select the folders to manage.

    • If you select the Root folder, OOS will manage all member accounts in your Resource Directory.

    • If you select a specific folder, OOS will manage only the member accounts within that folder.

  3. Click OK.

You can find the folder ID on the Management page in the Resource Management console. For more information, see View basic information about a resource folder.

Step 4: View the cross-account execution list

After you configure managed accounts, view execution records for all member accounts on the Task Execution Management page.

  1. In the OOS console, click Task Execution Management in the navigation pane on the left.

  2. In the filter bar, click the Resource Directory filter and select a target folder or member account.

  3. The execution list displays the execution records for all member accounts in the selected scope. The account ID column identifies the account for each execution.

Step 5: View execution details

Viewing cross-account execution details follows the same process as for a single account, but the data comes from the target member account.

  1. In the execution list, click the target execution ID.

  2. On the execution details page, you can view the following information:

    • task execution status: The result of each task step.

    • execution logs: The complete logs for the execution.

    • Trigger History: The source and time of the trigger.