Skip to main content

An official website of the United States government

Here’s how you know

Access controls

Cloud.gov Logs uses OpenSearch in a multi-tenant configuration that enforces strict isolation of customer data.

Access controls are designed to ensure users can only view logs and dashboards that correspond to their platform organization and space access.

Document access

Each log or metric is stored as a document in OpenSearch.

When Cloud.gov ingests these documents, it tags them with metadata:

FieldPurpose
@cf.orgOrganization name where the log originated
@cf.spaceSpace name where the log originated
@cf.org_id, @cf.space_idPlatform-unique identifiers

These identifiers are used to enforce document-level access through OpenSearch’s Document Level Security (DLS) feature.

What this means is that users can only see documents that match the organizations and spaces that they can access on the platform.

Dashboard objects: Tenant-based access

When you log in to Cloud.gov Logs:

  1. You are prompted to select a tenant.
  2. Each tenant maps to a platform organization that you can access.
  3. Saved searches, visualizations, and dashboards are stored inside that tenant.

Because tenants are scoped to organizations, no data or dashboard objects are shared across organizations by default.

Saved objects per tenant

Objects stored under your tenant include:

  • Saved queries
  • Dashboards
  • Visualizations

Only users with access to the same platform organization can view or modify these items.

GSA.gov

An official website of the U.S. General Services Administration

Looking for U.S. government information and services?
Visit USA.gov