Skip to main content
Connect PagerDuty to Oleria to gain continuous visibility into who has access across your teams, services, and escalation policies. Oleria reads identity, access, and audit data from the PagerDuty REST API - mapping every user’s account role and team memberships in one place - so you can see where access is over-provisioned and take action directly from Oleria. This page provides step-by-step guidance for connecting PagerDuty to Oleria.

What Oleria discovers

Once connected, Oleria continuously discovers and maps the following from your PagerDuty account:
  • Accounts - every user in the account, along with their account-level role (owner, admin, user, limited user, observer, restricted access, read-only user, or read-only limited user).
  • Teams - all teams and their membership, including the scoped role each member holds on that team (observer, responder, or manager).
  • Account roles - the eight fixed account-level roles PagerDuty defines.
  • Services and escalation policies - every service and escalation policy, including which teams are assigned to each.
  • Audit activity - account-wide audit events such as user lifecycle changes and access configuration changes.
Audit activity requires a Business or Enterprise PagerDuty plan. On Free or Team plans, Oleria syncs without audit activity - discovery of accounts, teams, services, and escalation policies is unaffected.

Prerequisites

  • PagerDuty admin role, to create API keys or register OAuth apps
  • API token or OAuth app credentials ready before connecting in Oleria (see the next section)
Use a service account rather than a personal employee account for the integration to ensure continuity if the employee leaves or changes roles.

Connect PagerDuty to Oleria

Oleria supports two authentication methods. Choose the one that fits your environment, then follow the steps for that method end-to-end.

Verify the integration

Confirm the PagerDuty instance appears in your Oleria workspace connected integrations. After the first sync completes, you can review the discovered accounts, teams, services, and escalation policies in your Oleria workspace.
If you rotate the API token or regenerate the OAuth client secret, update the credentials in Oleria by editing the integration. Revoked or expired credentials will cause discovery to stop.

Governance actions

Beyond discovery, Oleria can act on PagerDuty access to remediate risk. Governance actions require a General Access API token or an OAuth app with write scopes.
Make sure the credentials you connect with include write access before using governance actions. A read-only API token or an OAuth app with only read scopes will connect successfully, but any governance action will fail when it runs. See the credential setup steps above to configure write access.
Session revocation has no effect on sessions managed by a SAML single sign-on (SSO) identity provider. The identity provider controls those sessions directly - this is a PagerDuty API limitation, not an Oleria gap.

Known limitations

  • No disable or suspend state - PagerDuty has no concept of a disabled or suspended user. Deleting a user is the only deprovisioning path and is permanent.
  • MFA and SSO enrollment - multi-factor authentication (MFA) and SSO enrollment status are not available via the PagerDuty API. Oleria reports these fields as unavailable, not as a false negative.
  • Audit logs - audit activity requires a Business or Enterprise plan and credentials that include audit access (a non-read-only API key, or an OAuth app with audit_records.read). If either condition is not met, Oleria syncs without audit activity and no error is shown. If you are on a paid plan and see no audit activity, check that your credentials include audit access.

Contact us

For questions about this integration, contact us at support@oleria.com.