OrchestrAI Live

Integration · Monitoring

Datadog + OrchestrAI

Catalog exported 2026-09-02 · Datadog website

Query Datadog metrics and logs, review incidents, and create monitors or downtimes from chat.

OrchestrAI exposes 6 Datadog operations: 3 are low-risk (read-only or low-impact), and 3 create or modify resources and run only after you confirm the plan. 3 of them also carry a step-level approval gate.

6operations
3low risk
3create or modify
0destructive
3step-level approval

What teams use it for

On-call engineers use OrchestrAI with Datadog to pull the error rate for a service during an incident, tail the matching logs, and then create a monitor so the same failure pages next time. Metric, log, and incident reads are low risk, while creating a monitor, dashboard, or downtime is medium risk and confirmed before it lands. There is no operation to edit, mute, or delete an existing monitor, and no incident write, so those changes still happen in Datadog.

Every Datadog operation, with its risk level

Datadog operations available through OrchestrAI
Operation What it does Risk Step-level approval
Get Datadog Incidents Get incidents Low risk No
Get Datadog Logs Query logs Low risk No
Query Datadog Metrics Query metrics Low risk No
Create Datadog Dashboard Create dashboard Creates resources Yes
Create Datadog Downtime Schedule downtime Creates resources Yes
Create Datadog Monitor Create monitor/alert Creates resources Yes

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

What you connect

A Datadog credential (stored as datadog). Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.

Prompts that work

  • Query Datadog for p95 latency on service:checkout-api in the last 30 minutes
  • Show Datadog logs for the payments-worker with status:error from the last hour
  • Create a Datadog monitor that alerts #oncall when 5xx rate on api-gateway goes above 2% for 5 minutes

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI mute a Datadog monitor?
Not directly. It can schedule a downtime, which is a medium-risk confirmed operation, but there is no operation to edit or mute an existing monitor.
Does OrchestrAI read Datadog incidents?
Yes. Fetching incidents is a low-risk read. Creating or updating incidents is not available, so incident management stays in Datadog.
How does OrchestrAI authenticate to Datadog?
You add a Datadog credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.