Task · CFO-0003

Access identity logins collector (REST access_requests)

Description

Poll /access/logs/access_requests every few minutes with a persisted cursor. REST reach is about a day (doc-0003 trap 3).

Acceptance Criteria

Definition of Done

Implementation Notes

Parked AC3/4: cf1AccessLoginsRawGroups lacks connection and action dimensions, so the Groups-backed login metric cannot carry both; raw REST counting would violate the rate contract. Live Access API had zero login rows in the last 3h, so Loki live login proof is absent. Resume with source activity and an approved dimension contract.

Decision 2026-09-23 (Rob): AC3 reworded. Correction to the wave 1 report: REST access_requests is a census, not an adaptive sampled dataset (doc-0003 trap 6 applies to *Adaptive datasets), so counting its rows is exact and does not break the Groups rule. Keep the Groups metric (31d retention, covers service tokens) and add the REST-exact identity-login counter for the connection/action dimensions Groups lacks. The REST counter only covers what the ~1 day REST reach allows; an outage longer than that loses those counts.

View the source file on GitHub