Prompt
What would you use for logs if engineers and support both need access but with different permissions?
Latest observation
Oct 11, 2026
OpenAI APIWeb search: off
I’d usually use a centralized log platform with role-based access control (RBAC).
Best fit
Use something like:
- Datadog Logs
- Splunk
- Elastic / OpenSearch
- Cloud-native logging like CloudWatch, GCP Cloud Logging, or Azure Monitor
These let you:
- give engineers broader access for debugging and querying
- give support more limited access, such as:
- read-only access
- access only to specific environments or applications
- access to redacted/sanitized fields
- prebuilt dashboards/searches instead of raw log access
Good practice
If support doesn’t need full raw logs, a better pattern is:
- engineers: full log access
- support: filtered views, dashboards, or case-based access
- sensitive fields: masked before logs are stored
If you want a simple recommendation
- Small/medium org: Datadog or CloudWatch with RBAC
- Large/complex org: Splunk or Elastic/OpenSearch with strict access controls
If you want, I can also suggest the best option based on your stack and whether this is for SaaS, on-prem, or cloud.