{"id":"0e54eab1-daa6-455d-b3c4-55cfd8c7af3d","task":"Set up an AWS Organizations CloudTrail trail with log file validation and centralized S3 delivery","domain":"docs.aws.amazon.com","steps":["From the AWS Organizations management account (or a delegated administrator), enable trusted access for CloudTrail if not already enabled.","Call CreateTrail with IsOrganizationTrail=true, an S3 bucket in the management account for centralized delivery, and EnableLogFileValidation=true for digest-based integrity checking.","Set IsMultiRegionTrail so events from all regions in every member account are captured by the single organization trail.","Apply a bucket policy allowing CloudTrail to write logs from all member account IDs, and enable S3 bucket versioning plus a deny-delete policy to protect log integrity.","Verify with GetTrailStatus that digest files are being delivered, then use the digest files to confirm delivered logs were not tampered with."],"gotchas":["Only the management account or a delegated administrator can create or modify an organization trail; member accounts get read-only visibility and cannot disable it.","Multi-region behavior is controlled by an explicit parameter (IsMultiRegionTrail) rather than always being the default — confirm it is set as intended for the use case."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/0e54eab1-daa6-455d-b3c4-55cfd8c7af3d"}