What Oleria discovers
Once connected, Oleria continuously discovers and maps the following from your Datadog organization:- Accounts - every user, human and service account, with email, status, and role assignment.
- Roles - Datadog’s built-in and custom roles, and which accounts hold each.
- Teams - Datadog teams and their membership.
- Non-human identities (NHIs) - API keys, application keys, personal access tokens, service account access tokens, service account application keys, and org-authorized OAuth clients, each linked to the account that owns it.
- Activity - security-relevant Datadog Audit Trail events, such as user, role, team, and credential lifecycle changes. Only available with the API Key + Application Key method - see Choose an authentication method.
Datadog’s access model is flat: a role is granted directly to a user, with no per-resource permission grant. This integration doesn’t populate resource-level Access Graph or Access Inventory data. Datadog also doesn’t expose org-wide single sign-on (SSO) or multi-factor authentication (MFA) enforcement through any API - those are UI-only Security Settings. Per-user MFA enrollment status is available and is reported.
Prerequisites
- A Datadog organization admin, or an account with equivalent permissions, to create the credentials below.
- For OAuth2 only: a Datadog Partner Sandbox account. Standard Datadog organizations don’t have the Developer Platform / OAuth Apps page, so most customers should use API Key + Application Key instead.
Choose an authentication method
- Option A: API Key + Application Key (Recommended)
- Option B: OAuth2
1
Create an API key
Log in to Datadog as an admin and go to Organization Settings -> API Keys -> New Key. Give it a name (for example,
Oleria) and copy the generated value.2
Create an application key
Go to Organization Settings -> Application Keys -> New Key. Give it a name and copy the value immediately.
Connect Datadog to Oleria
1
Open the integration
Go to your Oleria workspace, select Integrations -> select Datadog.
2
Complete the connection form
Select your authentication method and fill in the connection form:
3
Save the integration
Select Authenticate to validate the credentials and save the integration.
Verify the integration
Confirm Datadog appears in your Oleria workspace’s connected integrations. After the first sync completes, you can review the discovered accounts, roles, teams, and credentials. Audit Trail activity, if available, syncs within Datadog’s retention window (90 days by default, configurable to 3, 7, 15, 30, or 90 days).If you rotate the API key, regenerate the application key, or rotate the OAuth client secret, update the credentials in Oleria by editing the integration. A revoked or expired credential stops discovery until you do.

