SigNoz
Connect SigNoz as access review source using an API service account with the SigNoz-Admin role so that the platform can list the members of your organization.
The platform reads your organization’s SigNoz members through SigNozAPI so you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- A SigNoz user holding the SigNoz-Admin (
signoz-admin) role. SigNoz declares the requirement as a role with the transactions necessary to create a service account, attach a role to it and create its keyAPI.signoz-adminis the only managed role that carries them - A service account assigned the SigNoz-Admin (
signoz-admin) role, so that the key can list the members of the organization. The end point that the platform reads is only administrator, and SigNoz's finite access control does not yet cover the user resource, so no narrower role can read the members - The Base URL is the address
httporhttpsthat you use to reach SigNoz: on SigNoz Cloud which is your court URL (e.g.https://your-instance.signoz.cloud), and on a self-hosted implementation is your own server address. Include the basic path when SigNoz is served under one, for examplehttps://example.com/signoz. Leave any query or fragment, and make sure that the court is publicly accessible on the internet
Collected Fields
Section entitled “Collected Fields”| the platform field | SigNoz field | Notes |
|---|---|---|
| Name | displayName |
|
email |
A user without an email address is ignored | |
| Role | role |
ADMIN and signoz-admin maps at Admin, EDITOR and signoz-editor at Editor, VIEWER and signoz-viewer at Viewer. A custom role is kept verbally, and matching is accurate, so a role that contains only “admin” is not promoted |
| Admin | isRoot, role |
Tagged as administrator when ___ZBT_I18N_RUNTIME_BLOCK_188__ is true or when ___ZBT_I18N_RUNTIME_BLOCK_189__ is resolved in Admin |
| Status | status |
active is listed as an asset, pending_invite and deleted as inactive. Any other value leaves the state unknown |
| MFA | Not supported | |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track your account through reviews |
| Created at | createdAt |
When the user was created in the organization |
SigNoz lists pending invitations in the same Members table as active users, so someone who has been invited but has not yet accepted appears in the campaign, marked inactive.
Step 1: Create a Service Account API Key
Step 1: Create a Service AccountAPIKey- Signed with, signed with SigNoz-Admin role, open Settings şi du-te la Service Accounts.
- Click New Service Account, enter a name (only the bottom letters, numbers and inscriptions, for example
probo-access-review), and click on Create. - Open the account. in Overview tab, use the Roles Dropdown pentru a atribui SigNoz-Admin role, then click Save.
- Open the Keys tab, click Add Key, names the key (e.g.
Probo Access Review), leaves the expiration date empty so that the key remains valid until it is revoked, then click CreateCopy the key and store it securely. SigNoz displays it only once.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find SigNoz, click API KeyPress the key and enter. Base URL (the address of the instance on which the key was created) and click Connect.
The platform names the source after your organization SigNoz and attracts its members to your campaigns.
Troubleshooting
Section “Troubleshooting”- Key rejected. Confirm that it is a service account Settings > Service Accounts Rather than a key Settings > Ingestion Settingshas not expired or has been revoked, and Base URL where the key was created.
- No members appear. Membership of the organization requires SigNoz-Admin role. Open the service account’s Overview Tab, check if the role is assigned, and then sync the source again.
- Key creation is unavailable. By default, only the
signoz-adminrole can create service accounts and their keys. Ask a SigNoz administrator to create the key. On SigNoz Cloud and Self-Hosted Enterprise an administrator can instead assign a custom role covered by that service account. - Connect fails on a self-hosted instance. The platform is called Base URL from its own infrastructure, so it cannot connect to a SigNoz implementation that is accessible only on a private network or on
localhost.