Obervability
Services AudiTrace Resources Contact
Book a free audit
Audit domain · 2 checks

Dynatrace token and access audit: scopes, expiry and dormant credentials

Two checks on tenant access — API tokens with scopes wider than their use, and credentials that have not been used in months but still work.
Book a free audit All 71 checks

What these checks read

Token scopes

Every token, the scopes it carries, and whether those scopes exceed what its recent activity required.

Expiry and dormancy

Tokens with no expiry, tokens expiring imminently, and tokens unused for long enough that nobody remembers what they are for.

Why it matters

Tokens accumulate the way maintenance windows do: one per integration, one per experiment, one created during an incident at 02:00 with every scope ticked because the documentation was not to hand. None of them are reviewed, because nothing in the product asks anyone to review them.
These two checks turn that into a short, actionable list: which tokens exist, what each could do, what it has actually done recently, and which have no expiry at all. A token with write scopes that has performed no writes in ninety days is either a standby credential somebody should document, or an open door nobody is watching.
The audit itself runs under a token you issue, with read scopes, and the report tells you which scopes it used so you can verify the principle applies to us too.

Questions we get about this domain

Does the report contain our token values?

Never. It contains token names, ids, scopes, owners and last-used timestamps. Token secrets are not readable through the API after creation, and we would not include them if they were.

What scopes does the audit itself need?

Read scopes on settings, entities, problems and DQL execution against Grail. No write scope is requested, and the run is verifiable in your own audit log.

The other audit domains

Nineteen domains, 71 checks, one read-only run. Each domain is a page.
FinOps Where the money goes, and what is recoverable Kubernetes Cluster coverage, versions, recurring failures Alerting Whether an incident would actually reach a human Audit log Who changed what, when, and outside business hours Coverage What is monitored, what only looks monitored RUM Real-user monitoring reach and privacy settings Grail Buckets, retention, annualized storage cost Pipelines Ingest processing, masking, drop rules Synthetic Synthetic monitors that pass, fail, or never run Topology Entity detection quality and entity explosion OpenTelemetry OTel sources and dual instrumentation Security Token scopes, expiry, dormant credentials Workflows Automation that fails or never fires Bizevents Business event provider hygiene Dashboards Dashboard inventory Davis Root-cause attribution rate OpenPipeline Route and pipeline resolution SLO SLO definitions that break on re-detection Tagging Environment tagging convention

See what this domain finds on your own tenant.

One read-only run covers all nineteen domains. You keep the report either way.
Book a free audit See how AudiTrace works

Find out what your Obervability is actually doing.

An audit takes one run. The findings take one meeting. What you do with them is up to you.
Certified Dynatrace experts
+1
Send
Obervability
Dynatrace implementation, managed services and support. Every finding comes with the source behind it.
Services
Services AudiTrace Case study
Guides
Dynatrace audit Dynatrace cost optimization Audit case study Articles
Reach us
© 2026 Obervability · All rights reserved.
Privacy Terms of use Accessibility