So the hierarchy looks a bit like this:
Top level = Keychain Access.app or the security CLI tool
Mid level = keychains (in flavours of files, core storage, data protection-enabled, and iCloud)
Item level = an entry inside a keychain
There is a sub-level as well, some software stores encoded data as a single item so when it's decrypted it's a bunch of different data, not a single secret, but technically the keychain system isn't aware of that anyway.