Skip to content

Build2 publishers2 min readPublished

CloudWatch Omni opens incident investigation to staff without AWS console access

AWS's CloudWatch Omni, generally available since September 23, lets Okta and Entra ID users investigate incidents without AWS console access. CloudWatch dashboard sharing has let outsiders view prebuilt graphs since 2020, so what Omni adds is the investigation itself, one of the reasons teams paid for third-party platforms.

The Engineer · Build desk

Illustration accompanying CloudWatch Omni opens incident investigation to staff without AWS console access

What happened

  • Each organization gets its own Omni URL, and accounts in Okta, Entra ID or a similar provider sign in through AWS IAM Identity Center.
  • Existing alarms, dashboards, APIs and console workflows keep working, and nobody moves to Omni until they opt in with the "Try CloudWatch Omni" button.
  • For AI agents, Omni captures end-to-end traces, scores correctness, coherence, retrieval and tool selection, and builds test datasets from production traffic.
  • CloudWatch now recommends OpenTelemetry Metrics over its Classic model, a split that began with native OpenTelemetry support in June 2026, and Omni is built on OpenTelemetry.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • capability Database engineers and managers outside the AWS account can query logs, metrics and traces in natural language during an incident, so the person who spots an anomaly can also chase it.
  • constraint Omni leaves the setup work in place: cross-account and cross-Region data still has to be routed with CloudWatch centralization rules before an Omni space shows it.
  • constraint A mixed AWS and Azure estate gets Azure application and agent telemetry today, with deeper multicloud support still to come, so broad multicloud coverage remains an argument for a third-party platform.
  • decision A team that bought a third-party tool mainly so non-console staff could investigate now has an AWS option to trial before its next renewal.

CloudWatch has shown data to people outside an AWS account since September 2020, through dashboard sharing [5]. It offered three routes: specific email addresses, a public link, or a third-party single sign-on provider [5]. That makes it six years older than Omni [1]. A shared viewer gets a prebuilt dashboard and can report that a graph looks wrong, a contribution that is usually accurate and always brief [6]. Rewriting a query, following a trace or digging into logs is outside what the feature was designed for, according to the dev.to comparison [6].

The permissions underneath were the harder problem. Sharing needs metric retrieval and EC2 tag lookups that cannot be scoped down [7]. Anyone holding a shared dashboard can therefore query every metric in the account and read the names and tags of every EC2 instance [7]. The SSO route shares every dashboard in the account at once [8]. Logs Insights widgets stay hidden from shared users until someone adds permissions to the sharing IAM role [8]. Giving an outside responder one service's logs meant widening a role that already exposed the whole account's metrics [7][8].

Omni ties access to a signed-in person instead of a shared dashboard [2]. The investigator arrives with an account from the company's own directory, brokered by IAM Identity Center. Where no identity provider exists, they use an IAM user or role [2][4]. The AWS News Blog says SREs, developers, database engineers and managers then share the same data and investigation context [19]. Neither source describes how permissions are scoped inside an Omni space. So this evidence does not show whether Omni closes the account-wide metric exposure that came with dashboard sharing [7].

The agent features address a separate gap. According to InfoQ, Daniel Abib, an AWS senior specialist solutions architect, said: "Agent behavior is non-deterministic: a prompt change can degrade response quality even when standard metrics show no errors." [13] Omni uses OpenInference and AWS Distro for OpenTelemetry, and supports frameworks including LangChain, LangGraph, CrewAI and Strands [15]. It also accepts third-party evaluators such as Braintrust, DeepEval and Ragas [15]. InfoQ also lists agent-focused platforms that combine tracing, evaluation, prompt experimentation and datasets, among them LangSmith, LangFuse and Arize AI Phoenix [18].

I think the sign-in design is the right call. Identity stays in the directory the company already manages, and the investigator never needs the AWS Management Console [2][3]. The dev.to comparison claims only that Omni narrows the gap with third-party observability platforms. It ties that claim to teams that chose one so people without console access could help investigate [20].

What to watch

  • AWS documentation of permission scoping inside an Omni space, to see whether outside responders inherit the account-wide metric reach that dashboard sharing granted.
  • The deeper multicloud support AWS has promised beyond today's Azure application and agent telemetry.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories