Overview
AI connectors link the SaaS tools your team already uses, such as observability platforms, code hosts, documentation systems, work trackers, feature-flag services, and cloud infrastructure. Rootly AI pulls real context from them while investigating an incident, summarizing a timeline, or answering an operational question. AI connectors are one source of context for Atlas, the context layer Rootly AI works from, alongside the Knowledge graph and Memory. They support AI SRE investigations and conversations with Rootly AI. Connector availability varies by surface. When Rootly AI answers a responder-initiated conversation or runs an AI SRE investigation, it looks up just the context it needs from each connected tool and reasons over the results alongside the available alert or incident record. A connector can also expose supported connector actions. Most built-in connectors limit calls to a Rootly-reviewed list of tools. Atlassian, Notion, Linear, Braintrust, Honeycomb, AWS, and the Cloudflare connectors pass through the provider’s full tool catalog, so the scopes, roles, and permissions you grant in the provider set the boundary. The Custom MCP connector limits calls to the tools you allowlist. Any available tool can still accept provider-defined commands or query languages that change data. Provider permissions and provider-side command controls remain authoritative. See each connector guide for its exact access and action model.How Rootly AI Uses Connectors
Each connected tool gives Rootly AI a different kind of signal.- Alert Sources — when your monitoring fires, an incident lands in Rootly. Data flows monitoring → Rootly.
- Regular Integrations — Rootly posts to Slack, creates Jira tickets, pages on-call. Data flows Rootly → tool.
- Connectors — Rootly AI looks up context in your tools while investigating. A connector tool can also change data in a provider, within what the connected provider account is allowed to do. Most built-in connectors expose a Rootly-reviewed tool list; Custom MCP tools are customer-allowlisted. Provider-defined commands or query languages can have their own write boundary, documented in the connector guide. Supported connectors can also feed derived facts, such as service identities and dependency relationships, into the Knowledge graph. Data normally flows tool → Rootly AI; a connector action flows Rootly AI → tool.
Rootly AI in Action
What Rootly AI surfaces during an incident once you’ve connected each provider:Provider Directory
/account/ai-sre/integrations to the Rootly app URL. Only Incident Response Owners, Incident Response Admins, and On-Call Admins can connect or configure connector accounts; those roles can use the same direct path without a seat. See the canonical AI & Agents permissions matrix for the complete role and seat rules. Providers connect through one-click authorization or a provider-specific configuration form. Which provider cards you see depends on what Rootly has enabled for the selected team. The native Azure Monitor connector also requires a one-time Microsoft Entra application enrollment from your Rootly account team before a Rootly admin completes the form.
One-Click Providers
Click Connect on the provider card, enter a Connection name, and follow any authorization prompt. DeepWiki requires no vendor account or authorization; the other providers open their authorization flow.Setup-Required Providers
These providers require provider-specific setup before Rootly AI can use them. Each has its own configuration form; the linked providers have dedicated setup guides. Azure Monitor additionally requires the one-time Entra enrollment described in its guide.AWS
Google Cloud
Azure Monitor (Native)
Datadog MCP
Grafana Cloud
Grafana OSS
New Relic
Dash0
Dynatrace
Honeycomb
GitLab
Semaphore
Metabase
ClickHouse
Splunk
Devin
Custom MCP
The Provider Card
The Connectors page lists your existing connections under Connected and the providers you can add under Add a connection, grouped by category. Only providers that support multiple active connections appear there again when you already have one. To add another connection to one of those providers, select it under Add a connection and give it a distinct Connection name. ClickHouse and Azure Monitor (Native) currently allow one active connection per team; an Azure Monitor connection can cover multiple subscriptions in one tenant and its native setup form has no Connection name field. Use the Search sources, signals, or vendors box to filter both lists.Data Handling
Rootly AI normally queries connectors on demand during an investigation rather than maintaining a full replica of their underlying data. Custom MCP tools are available according to the customer-managed allowlist, including during automatic AI SRE runs; Rootly doesn’t infer whether a Custom MCP tool is a read or write from its behavior. When your Rootly account team has turned on knowledge graph ingestion for your organization, Rootly also reads supported connectors when you connect or re-scope them and again in a daily sweep, then stores derived facts for the Knowledge graph:- Datadog, Grafana Cloud, Grafana OSS, New Relic, Dash0, Dynatrace, and Sumo Logic can store service identities and, except for Sumo Logic, observed dependency relationships.
- AWS can store the account, its regions, and resource inventory.
- Google Cloud can store selected project, hierarchy, Cloud Run service, and Compute Engine instance facts.
- GitHub can store infrastructure-as-code facts read from one infrastructure repository that Rootly selects. When exactly one AWS account and no more than one GitHub account are connected, Rootly uses the AWS inventory instead and skips this repository.
Best Practices
- Start with the observability and code connectors. These are the two categories that consistently show up in “what caused this?” investigations. Sentry + GitHub covers most product-tier incidents; adding Datadog or Grafana on top covers infrastructure. Everything else layers value on top.
- Connect the work-tracking connector your team uses. Pick Atlassian (Jira) or Linear. Connecting both when you only use Linear adds a source that never fires and clutters the picker.
- Don’t over-scope AWS. Rootly AI works fine with narrowly scoped IAM permissions. Start with the AWS services you operate and expand later if Rootly AI’s output is missing signal. The IAM role’s policies are the authoritative limit. When you pick specific services under AWS services the agent can read, Rootly also restricts each session to their Get, List, and Describe calls; with all services allowed, the role’s policies are the only limit.
- Keep Azure Monitor RBAC and its Rootly allowlist aligned. Grant the Rootly enterprise application only the Azure scopes responders need, then configure the same subscriptions, workspaces, resources, and capabilities on the Azure Monitor (Native) card.
- Grafana Cloud and Grafana OSS are mutually exclusive in practice. Connect Grafana Cloud if your team is on the managed offering. Connect Grafana OSS if you self-host.
- Reconnect after major credential rotations. If you rotate the API key or IAM role that Rootly AI uses, the connector stays under Connected but queries fail. Re-authenticate through Configure where the card offers it; otherwise disconnect and connect again.
- Restrict who can manage connectors. Connectors pull real customer data into investigation context. On the current team, Incident Response Owners and Admins and On-Call Admins can connect, reconfigure, rotate, or disconnect connector accounts without an Incident Response seat. Assign those roles only to users who understand what each connector exposes. See Manage User Permissions.
Troubleshooting
A connector shows Connected but Rootly AI says it can't reach the data
A connector shows Connected but Rootly AI says it can't reach the data
A provider I need isn't in the picker
A provider I need isn't in the picker
The card says I don't have permission to manage this source
The card says I don't have permission to manage this source
/account/ai-sre/integrations to the Rootly app URL. Otherwise, ask someone with an eligible role to run the setup or update your role. If you already hold an eligible role and the AWS, ClickHouse, or Azure Monitor (Native) card still shows this message, ask your Rootly account team to enable those connectors for your organization. The provider can separately require an external administrator, OAuth, or IAM permission. See Manage User Permissions.Rootly AI's investigation output doesn't cite a connector I connected
Rootly AI's investigation output doesn't cite a connector I connected
Frequently Asked Questions
What's the difference between Connectors, Alert Sources, and regular Integrations?
What's the difference between Connectors, Alert Sources, and regular Integrations?
Do I need to configure a vendor as a Connector if I already have it set up as an Alert Source or regular Integration?
Do I need to configure a vendor as a Connector if I already have it set up as an Alert Source or regular Integration?
Does Rootly store the data it queries from connectors?
Does Rootly store the data it queries from connectors?
What if my tool isn't in the catalog?
What if my tool isn't in the catalog?
Can I disconnect a connector without deleting anything else?
Can I disconnect a connector without deleting anything else?