Alerting
Questions about alerting and problem detection in Dynatrace.
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

When are Davis Anomaly Detectors going to receive more granular permissions?

ssipes
Frequent Guest

With metric events we were able to restrict access through management zones.
A user could only edit or create metric events within the management zones they had access to.

Currently access to Davis Anomaly Detector (Custom DQL Alerts) are given through assigning the following IAM permissions:

ALLOW settings:objects:write WHERE settings:schemaId = 'builtin:davis.anomaly-detectors';
ALLOW settings:objects:read WHERE settings:schemaId = 'builtin:davis.anomaly-detectors';


This lets users create Custom DQL Alerts, but it also lets them save and overwrite existing configs that were made by other people.


"settings:objects" does support the condition of: "settings:dt.security_context"

Which I would try to use for access control.
Except Custom DQL Alerts do not have a place to assign a security context value.


This leaves me with no option to enable this feature for my users without giving them broad access to edit another persons Custom DQL Alert.

 

I can also see that Custom DQL Alerts have an "Owner" field.
Are there plans to make Custom DQL Alerts function similar to Pipelines?
Where there is a specific owner of the config that can share access to other people or groups?

ssipes_0-1790874088846.png

 


Not sure if I'm just missing something here. If I am please correct me!
This is just a very cool feature that I'd love to give my users access to.

1 REPLY 1

sujit_k_singh
Leader

Hi @ssipes 

Based on the current documentation, access to Custom DQL Alerts is controlled through IAM permissions on the builtin:davis.anomaly-detectors settings schema. Users with settings:objects:write can create and modify anomaly detector configurations

Automate alerts with API — Dynatrace Docs

I haven't found any documentation or article where Dynatrace has publicly committed to a timeline for owner-based edit restrictions or security-context support for Anomaly Detectors.

The ownership and sharing model used by Pipelines appears to address the same use case, but I haven't found any public statement confirming that a similar approach is planned for Anomaly Detectors.

However, if anyone from Dynatrace can confirm whether ownership-based access control or security-context support is planned for Anomaly Detectors, that would be greatly appreciated.

Thanks,

Sujit
Dynatrace Professional Certified

Featured Posts