Apono integrates with Grafana to replace static, always-on data source access with Just-in-Time (JIT), policy-driven authorization. Instead of granting permanent IAM roles or group memberships, engineers request time-bound access to specific Grafana data sources (logs, metrics, traces, databases). Apono evaluates requests against centralized policies, provisions temporary permissions, and automatically revokes them when the window expires. Integration with Grafana Cloud IRM allows access decisions to incorporate on-call schedules and active incident context. Key benefits include zero standing privileges, reduced blast radius from compromised credentials, full audit trails, and faster access without manual IAM updates.

5m read timeFrom grafana.com
Post cover image
Table of contents
The challenge: static access in dynamic environmentsGoverning Grafana data sources with Just-in-Time accessReference architecture: Just-in-Time access for Grafana data sources

Sort: