Integration · Monitoring
Grafana + OrchestrAI
Catalog exported 2026-09-02 · Grafana website
List and read Grafana dashboards and create new ones from chat, without touching existing panels.
OrchestrAI exposes 3 Grafana operations: 2 are low-risk (read-only or low-impact), and 1 create or modify resources and run only after you confirm the plan.
What teams use it for
Platform teams ask OrchestrAI to find the Grafana dashboard for a service by listing what exists, read its JSON by UID, and create a new dashboard when a fresh service ships. Listing and reading are low risk, and creating a dashboard is medium risk and runs when requested. Updating or deleting an existing dashboard, managing data sources, and reading alert rules have no operation, so those stay in the Grafana UI.
Every Grafana operation, with its risk level
| Operation | What it does | Risk | Step-level approval |
|---|---|---|---|
Get Grafana Dashboard |
Get Grafana dashboard by UID | Low risk | No |
List Grafana Dashboards |
List Grafana dashboards | Low risk | No |
Create Grafana Dashboard |
Create Grafana dashboard | Creates resources | No |
Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.
What you connect
A Grafana credential (stored as grafana).
Connected-service tokens are envelope-encrypted with a per-record key wrapped by a cloud KMS.
Prompts that work
- List Grafana dashboards whose title contains kafka
- Show me the Grafana dashboard with UID a7Fk3pQ and summarize its panels
- Create a Grafana dashboard called Checkout Service with request rate, error rate, and p95 latency panels from Prometheus
Before anything runs
Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.
Frequently asked questions
- Can OrchestrAI edit an existing Grafana dashboard?
- No. The integration can list dashboards, read one by UID, and create new ones. Edits to existing dashboards are made in Grafana.
- Is creating a Grafana dashboard through OrchestrAI confirmed first?
- Creating a dashboard is medium risk and is not marked for confirmation, so it runs when you ask. It only adds a dashboard and does not change existing ones.
- How does OrchestrAI authenticate to Grafana?
- You add a Grafana credential once in the connections screen. It is envelope-encrypted with a per-record key wrapped by a cloud KMS and is only decrypted inside the run that needs it.
Related integrations
Try it on your own account
Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.
Unused credits refunded in your first 14 days.