Skip to main content
Connect Datadog to Oleria to see who has access across your Datadog organization: every user (human and service account), the roles and teams they belong to, and the API keys, application keys, and other credentials acting as non-human identities (NHIs). Oleria reads this data from the Datadog API. Two authentication methods are supported - API Key + Application Key for full coverage, or OAuth2 for reduced coverage - and this page walks through both.

What Oleria discovers

Once connected, Oleria continuously discovers and maps the following from your Datadog organization:
  • Accounts - every user, human and service account, with email, status, and role assignment.
  • Roles - Datadog’s built-in and custom roles, and which accounts hold each.
  • Teams - Datadog teams and their membership.
  • Non-human identities (NHIs) - API keys, application keys, personal access tokens, service account access tokens, service account application keys, and org-authorized OAuth clients, each linked to the account that owns it.
  • Activity - security-relevant Datadog Audit Trail events, such as user, role, team, and credential lifecycle changes. Only available with the API Key + Application Key method - see Choose an authentication method.
Datadog’s access model is flat: a role is granted directly to a user, with no per-resource permission grant. This integration doesn’t populate resource-level Access Graph or Access Inventory data. Datadog also doesn’t expose org-wide single sign-on (SSO) or multi-factor authentication (MFA) enforcement through any API - those are UI-only Security Settings. Per-user MFA enrollment status is available and is reported.

Prerequisites

  • A Datadog organization admin, or an account with equivalent permissions, to create the credentials below.
  • For OAuth2 only: a Datadog Partner Sandbox account. Standard Datadog organizations don’t have the Developer Platform / OAuth Apps page, so most customers should use API Key + Application Key instead.

Choose an authentication method

Connect Datadog to Oleria

1

Open the integration

Go to your Oleria workspace, select Integrations -> select Datadog.
2

Complete the connection form

Select your authentication method and fill in the connection form:
3

Save the integration

Select Authenticate to validate the credentials and save the integration.

Verify the integration

Confirm Datadog appears in your Oleria workspace’s connected integrations. After the first sync completes, you can review the discovered accounts, roles, teams, and credentials. Audit Trail activity, if available, syncs within Datadog’s retention window (90 days by default, configurable to 3, 7, 15, 30, or 90 days).
If you rotate the API key, regenerate the application key, or rotate the OAuth client secret, update the credentials in Oleria by editing the integration. A revoked or expired credential stops discovery until you do.

Remediation actions

Beyond discovery, Oleria can act on Datadog access to remediate risk, using the same credentials.

Contact us

For questions about this integration, contact us at support@oleria.com.