Overview
This page walks Rootly administrators through the controls available for hardening a tenant against unauthorized access, lateral movement, and silent configuration drift. It is the recommended checklist when preparing Rootly for an enterprise security review, a SOC 2, or onboarding a new organization. Every recommendation below is grounded in features Rootly ships today — links lead to the relevant configuration page. The order mirrors how most teams roll out hardening: identity first, then permissions, then API surface, then monitoring.Centralized Identity
Least Privilege
Scoped API Access
Continuous Audit
Centralize Identity
The fastest single hardening step for any Rootly tenant is moving authentication behind your IdP. Once SSO is enforced, you control account lifecycle, MFA, and conditional access from one place — Rootly inherits whatever your IdP enforces.Enable SAML SSO
Enable SCIM Provisioning
Stop Allowing Direct Invitations Once SSO Is Live
Apply Least Privilege
Rootly’s role model lets you scope what a user can do down to the action level. Use it — broad admin grants are the largest unforced security risk in most tenants.Lock Down API Access
Rootly exposes a public API plus OAuth 2.0 provider endpoints. Both deserve deliberate hardening.Prefer OAuth 2.0 Over Long-Lived API Tokens
For machine-to-machine integrations, use OAuth 2.0 rather than static API tokens. OAuth tokens have explicit scopes, short lifetimes, and can be revoked from a single place. Long-lived API tokens are appropriate only for narrow internal tooling, and should be rotated on a fixed cadence.Scope API Tokens Tightly
When an API token is necessary, scope it to the minimum permission set the integration needs. A token used by a Datadog → Rootly forwarder should not have the ability to modify escalation policies or user roles.Audit Outgoing Webhook Destinations
Outgoing webhooks post to URLs you supply. Review the webhook destinations in your tenant on a recurring cadence and remove ones pointing at decommissioned receivers — orphaned destinations accumulate over time and become exfiltration risks once their hosts change ownership.Turn On Continuous Audit
Rootly’s Audit Log captures every create, update, and delete across ~60 resource types with full before-and-after field values. It is the compliance evidence layer auditors look for.Familiarize Your Team With the Audit Log UI
Use the JSON:API Export for Programmatic Review
Make High-Signal Changes Part of Your Review Cadence
Control Session And Device Posture
Harden Third-Party Integration Hygiene
Each integration you connect is a potential blast-radius vector if its credentials leak. Routine hygiene:- Rotate integration credentials on a schedule. Most providers let you regenerate API keys without recreating the integration — schedule a quarterly rotation for high-privilege integrations (PagerDuty, Slack, GitHub, Datadog).
- Disable integrations you no longer use. A connected-but-unused integration is still attack surface. Review your integrations list each quarter and disable connections to systems your team no longer relies on. The Audit Log captures recent configuration changes to each integration, which helps confirm whether one has been actively maintained.
- Limit Slack workspace access. When configuring the Slack integration, install it as a specific workspace admin rather than a personal account — that way, the integration outlives any individual user’s tenure.
- Review integration scope grants. When connecting OAuth-based integrations (Google Workspace, Microsoft 365), confirm the requested scopes match what Rootly actually needs for the features you use.
Status Page And Public Surface
If you publish status pages, treat the public surface deliberately:- Use Status Page Authentication Methods — password protection or SAML SSO — on any status page that should not be world-readable.
- Confirm Public And Private Status Pages classifications match intent — a misclassified private page is a data exposure.
- Use a Custom Domain for branded status pages so DNS and TLS sit under your control.
Compliance Posture
Rootly maintains SOC 2 Type II. Auditors and customer security teams typically request the following artifacts during review:Frequently Asked Questions
Does Rootly support MFA directly, or only through SSO?
Does Rootly support MFA directly, or only through SSO?
How long does Rootly retain audit log data?
How long does Rootly retain audit log data?
How do I rotate an API token without breaking integrations?
How do I rotate an API token without breaking integrations?
Are passwords and tokens visible in the audit log?
Are passwords and tokens visible in the audit log?
What's the right role for our compliance team?
What's the right role for our compliance team?