How the key works
Your network team creates an API key at read level in your monitoring platform and gives it to us once. We store an opaque reference to it; the secret itself lives in a secrets manager and is resolved only when a job runs.
Read level is a design decision, and it is what keeps the ask small. Write access on a customer's monitoring system would turn a two-week integration into a two-quarter security review, and it would buy nothing a cost question needs.
Binding an interface to a service
Some platforms expose no stable interface index, so the practical key is the device host plus the sensor name. That is a reconciliation problem rather than an algorithm, and treating it as one is how utilisation ends up attached to the wrong service.
We auto-bind on an exact match between a confirmed service identifier and the interface description. Everything else opens a review item with ranked candidates. Bindings are dated, so a rebind starts a new period and leaves reported history intact.




