Skip to main content

Capabilities

Two things bound a connection: your role in the organization, and the capabilities you ticked. Both are checked on every call, so a role change or a removed membership applies on the next call. There is nothing to revoke by hand.

Capabilities only subtract from your role. Connecting a client can never widen what you are able to do.

CapabilityOn the consent screenWhat the client can doMinimum role
tenants:readSee your environmentsList the environments in this organization and which telemetry each one holdsMember
metrics:readRead your metricsRun metric queries, read results, list metrics and labelsMember
logs:readRead your logsSearch logs and read matching linesMember
traces:readRead your tracesSearch traces and read spans, including their attributesMember
dashboards:readSee your dashboardsList folders and dashboards and read their contentsMember
alerts:readSee your alerting setupRead alert rules, firing alerts and notification routingMember
dashboards:writeCreate dashboardsCreate dashboards and foldersEditor
alerts:writeCreate and pause alert rulesCreate alert rules, pause and resume themEditor

No tool deletes anything. No tool deletes a dashboard, a folder, an alert rule, a contact point or any telemetry. The dashboard tools only create. Importing the same file twice leaves two dashboards and never overwrites one that somebody else owns.

See Tools for which capability each tool needs.