Operations Security
Operations & Security
Eden's Operations & Security category puts telemetry, cost, identity, policy, approvals, evidence, and audit in the same operating model as the work.
Controls are shared across AI, data, compute, connectivity, and modernization. A capability does not gain access merely because it has a route, provider, template, runtime, or marketplace installation.
Capabilities
| Capability | What it covers | Start here |
|---|---|---|
| Metrics, logs & traces | Follow health and behavior from fleet to request. | Operations And Observability |
| Analytics & costs | Attribute usage, latency, tokens, spend, and capacity. | Analytics And Observability APIs |
| Investigations | Correlate signals, activity, recommendations, and operational context. | Analytics And Recommendations |
| Policies & approvals | Control sensitive and automated actions before they run. | Policy Bindings |
| Credentials & keys | Scope, rotate, and revoke access without exposing secret material. | Authentication |
| Evidence & audit | Explain actors, resources, routes, policy decisions, and outcomes. | Promptless Evidence |
Operations
- Metrics for services, endpoints, gateways, migrations, and runtimes
- Structured logs with resource and request context
- Distributed and LLM request traces
- Usage, latency, token, cost, and capacity analytics
- Activity history and promptless evidence
- Investigation and recommendation workflows
- Health, failover, and high-availability signals
Start with Operations And Observability and Gateway Observability.
Security and governance
- Human, service, runtime, and agent identity
- Organization and resource permissions
- Credentials, secret references, and scoped keys
- Endpoint and command policy
- Content policy profiles and policy bindings
- Access boundaries
- PII detection, masking, and redaction
- Approval gates
- Routing, execution, and migration evidence
Start with Endpoint Governance, AI Gateway Governance, and Authentication.
Evidence model
Operational records should contain safe identifiers, hashes, counts, statuses, policy decisions, route/provider/model identifiers, audit references, and correlation IDs. Credentials, raw prompts, query bodies, document contents, and unredacted sensitive values must not appear in telemetry or exports.