Obervability
Services AudiTrace Resources Contact
Book a free audit
AudiTrace

Audit your Dynatrace tenant. In one run.

71 checks across configuration, security, coverage and cost. Every finding comes with the source behind it and its yearly cost. Read-only, always.
Book a free audit See the 71 checks
AudiTrace overview dashboard

Measured, not estimated

Every finding carries the exact source behind it and a CSV of the objects it found.

Priced with your rate card

Savings are computed from your negotiated rates, not from list price.

Read-only, always

No write scope exists in the product. Nothing is created, changed, or deleted.

You are paying for observability. Is it observing?

Full-Stack hosts, infrastructure data
You pay the Full-Stack rate and receive infrastructure data. On one production tenant: 140 hosts.

$91,576 / year

Retention nobody chose
A default Grail bucket sitting at 462 days because it was never reviewed. Storage is billed per day, per gigabyte, forever.

462 days

Alerting that does not alert
Notifications pointing at a deleted alerting profile fail silently. Maintenance windows set once and still open years later.

1,617 windows

Personal data in cleartext logs
Email addresses landing in Grail because no masking rule was ever applied.

50 sources · ~30.7M/day

How it works

01

Connect

Read-only, through your existing SSO session. No token to create, no credential to hand over, no network path to open.
02

Run

71 checks execute against your tenant. A hard budget cap limits how much Grail data may be scanned; the run stops rather than exceed it.
03

Read

A report, an Excel workbook, and one evidence CSV per finding.
From a workstation

Audit engagement

The auditor runs the engine under your SSO session. No token to create, no install on the tenant, no network path to open.
From inside your tenant

AudiTrace for Dynatrace — native app

The engine deployed as a native Dynatrace app. Your own team runs the audit whenever they want, without an external party connecting.
Two ways to run it, one engine: every check declares both paths and produces the same verdict whichever transport is used.

What a finding contains

The money
Where it can be computed — annualized.
Business value
What the finding means in the business's own terms — what it saves, what it exposes, and what it costs to leave alone.
The evidence
A CSV listing the objects found, so remediation has a work list.
The verdict
Every one of the 71 checks comes back with a status of its own — pass, warning, fail, not applicable or error. Never a guess.
The trigger condition
The literal expression that decided the verdict.
The remediation
Which of the 21 catalogued fixes applies, its difficulty, and whether it can be automated.

What you receive

The report

Scored findings by domain and severity, each with its remediation, difficulty and — where computable — its annualized cost.

The Excel workbook

Every finding as structured data, ready for filtering, ownership assignment and progress tracking.

Evidence CSVs

One CSV per finding listing the exact objects found — so remediation starts from a work list, not a search.

The 71 checks

71 active checks across 19 domains. A check that cannot run reports blocked or not applicable — it never reports a pass it could not prove.
DomainChecksWhat it answersExample
FinOps12Where the money goes, and what is recoverableFull-Stack hosts with no monitored service behind them — 140 of them, $91,576 a year
Kubernetes11Cluster coverage, versions, recurring failuresA cluster whose operator was left behind by an upgrade, and stopped reporting quietly
Alerting8Whether an incident would actually reach a humanMaintenance windows left permanently open — 1,617 of them, suppressing alerts
Audit log7Who changed what, when, and outside business hoursA configuration change made outside business hours by an account that has since left
Coverage5What is monitored, what only looks monitoredA namespace that reports workloads but no pods — monitored on paper, blind in practice
RUM4Real-user monitoring reach and privacy settingsApplications with no traffic for 90 days — 86 of them, still licensed and configured
Grail3Buckets, retention, annualized storage costThe default metrics bucket still at 462 days, because nobody ever chose otherwise
Pipelines3Ingest processing, masking, drop rulesLog sources carrying e-mail addresses in cleartext — 50 of them, with no masking rule
Synthetic3Synthetic monitors that pass, fail, or never runA monitor that has not run since the location it used was retired
Topology3Entity detection quality and entity explosionOne service carrying hundreds of historical versions, so Davis has no continuity to reason over
OpenTelemetry2OTel sources and dual instrumentationA service instrumented twice — once by OneAgent, once by OTel — and counted twice
Security2Token scopes, expiry, dormant credentialsA token with write scope that nobody has used for a year, issued by someone who left
Workflows2Automation that fails or never firesAn automation that has failed on every run for months, with nothing watching it
Bizevents1Business event provider hygieneAn event provider sending fields that no dashboard and no query ever read
Dashboards1Dashboard inventoryA dashboard nobody has opened in a year, owned by an account that no longer exists
Davis1Root-cause attribution rateProblems closing without a root cause attributed, so the same incident recurs unexplained
OpenPipeline1Route and pipeline resolutionRecords landing on the default route, unenriched, because the rule that should have caught them was never applied
SLO1SLO definitions that break on re-detectionAn SLO whose definition stops matching after a re-detection, and quietly reports nothing
Tagging1Environment tagging conventionHosts with no cost-allocation tag — 384 of them, so no team can be charged for them

Security and trust

Read-only is enforced, not promised

No write scope exists in the product — not disabled, absent. The runner aborts if the connected context is not the intended tenant or the session is not read-only.

Your data does not leave

Aggregates only: queries on logs, spans and business events return counts and field names, not message bodies. Where a check has to match on content — personal data in logs is the one that does — it counts the matches and returns the count, and anything personal is anonymized before a human reads it.

Cost is bounded before the run

Every Grail query carries a server-side scan cap. A run has a hard budget ceiling and stops rather than exceed it. The audit reports its own cost.

Every line in the report is backed

Every finding carries its scale, its annual cost and the source behind it. That is why a single row can go straight into a budget conversation, or into the quarter’s plan, without explaining where the number came from.
Not a monitoring tool — it audits your Dynatrace configuration.
Not a replacement for Dynatrace support or your account team.
Not an agent, not a sidecar, not a daemon. It runs when you run it, and stops.

Ways to work with us

One-off

Configuration, security and cost audit

71 checks, complete report, prioritized remediation plan, findings review session. Nothing installed on your tenant. Read-only throughout.
Free of charge.
Book a free audit →
Monthly

Compliance and cost monitoring

Monthly audit run, change analysis against the previous month, remediation support, monthly review. The deliverable is remediation progress — the report is the evidence.
Sold in days per month.
The app

AudiTrace for Dynatrace

The audit engine as a native app in your own environment. Your team runs the audit whenever they want, without an external party connecting to the tenant.
Licensed per tenant, per year. Quote on request.

Frequently asked questions

Does it modify anything in our tenant?
No. There is no write path in the product. It reads, and it stops.
Do we have to install something?
No, for the audit engagement — it runs from the auditor’s workstation under your SSO session. Yes, optionally, if you want the native app so your own team can run it.
Do you see our logs?
We scan logs to find personal data that was stored in them by accident — that is exactly what the check is for: to hand you the list so you can mask it. What comes back is a count per source: how many records, and of what kind. The log content itself is never retrieved or retained.
Can we verify the findings ourselves?
Yes, and you should. Every finding ships with the exact condition that decided its verdict and the list of objects behind it. Another AudiTrace run returns the same number — that is how you check it.
How are savings calculated?
From your own contract rates, which you provide. If you do not provide them we price on the vendor’s list rate and say so explicitly in the report, so it is always clear what basis a number stands on.

Find out what your Obervability is actually doing.

An audit takes one run. The findings take one meeting. What you do with them is up to you.
Certified Dynatrace experts
+1
Send
Obervability
Dynatrace implementation, managed services and support. Every finding comes with the source behind it.
Services
Services AudiTrace Case study
Guides
Dynatrace audit Dynatrace cost optimization Audit case study Articles
Reach us
© 2026 Obervability · All rights reserved.
Privacy Terms of use Accessibility