Security and identity management
Scoped identity enforcement: Services must be registered with the Identity Provider using a dedicated scope exclusive to services. The collector validates this scope before accepting logs, ensuring only trusted sources can emit audit data.
Backend-agnostic access control: The OpenTelemetry collector communicates with the log storage backend using credentials such as API keys or tokens. The credentials are associated with a user that has appropriate rights in the backend. This setup ensures that services emitting logs do not need to manage backend-specific authentication or access logic. Instead, the collector handles secure transmission and access control inde-pendently.
External user management: Most supported backends include their own user and client access control sys-tems. These systems are managed outside of XProtect, meaning that users’ permissions and access to stored logs are configured directly within the backend platform.