Most data governance in observability happens after the fact. Telemetry is collected, written to storage, and then subjected to retention rules, redaction and access controls applied to data that has already landed. The window between arrival and governance is small, but it is the window in which sensitive fields sit unmasked in a store and in which retention becomes whatever the default was.
Motadata has moved that work forward in its latest release. ObserveOps Infinity, now generally available, introduces an observability pipeline that applies masking, filtering and retention policy to telemetry while it is still in motion, before any of it is written.
Governance Before Storage
The pipeline sits between telemetry sources and the store, and is included in the base platform rather than sold as a separate module.
Its processing stage covers filtering, normalisation, reduction, redaction, masking, sampling and routing. For an organisation with data that must not be written in full, the significant word there is masking, and the significant detail is when it happens. A field masked at ingest was never in the store to be discovered, exported or subpoenaed. A field masked afterwards was.
Retention is applied by policy rather than inherited from a default. Data is tiered by value across full fidelity, aggregated and dropped, and the policy can be changed without a procurement conversation. In practice, retention in many estates is not a decision at all but the setting that was configured at implementation and never revisited, which becomes a compliance exposure the moment a regulator asks what is being kept and why.
The pipeline also parses at ingest, so logs, events, traps, flows and metrics arrive as queryable fields rather than unstructured strings, and enriches events with configuration item, site, owner, environment and service context before they land. For a security operations team, the effect is that an alert arrives already carrying the information about ownership and affected service that would otherwise be assembled manually while an incident is running.
Motadata describes the pipeline as an extensible control plane rather than a fixed sequence, with the capabilities available today representing where it starts rather than where it stops.
Holding Up During the Surge
A further stage handles bursts through backpressure and sustained delivery. This addresses a failure mode with direct security consequences: telemetry lost during an event storm is telemetry missing from the record of exactly the period an investigator will later want to reconstruct.
Retention of the record through a surge is not a feature that demonstrates well, but it is one that determines whether a forensic timeline has a gap in it.
Access Controls in the Base
The release also removes the tiering that previously sat across Motadata’s product line. Four ObserveOps editions have been withdrawn in favour of one.
ObserveOps Infinity includes the complete platform from day one, and the security controls are part of that base rather than an upgrade. Single sign-on, multi-factor authentication and role-based access control are included, alongside monitoring across network, server and virtualisation, topology, service level objectives, dashboards, AIOps, correlation, runbook automation, integrations and the pipeline itself.
The base is metered by monitored device. Optional modules for flow monitoring, log monitoring, network configuration management, application performance monitoring and real user monitoring attach in any combination, each metered by its own unit. Log and flow licensing has moved from a per gigabyte per day basis to a per source basis, so an organisation is licensed by the number of things it watches rather than by the volume those things emit.
That change has a governance consequence that is easy to miss. Under a volume meter, the decision to increase logging verbosity for security purposes carries a licensing cost, which creates quiet pressure to log less than the security team would prefer. Under a source meter, that pressure is removed.
Motadata has confirmed that customers on the retired editions are not being required to migrate, and that existing contracts continue as written.
Autonomy With a Defined Blast Radius
The final element of the release concerns agentic AI, and Motadata has drawn the boundary carefully. The company’s position is that an autonomous system cannot be trusted in a production estate where the consequences of its actions are undefined, and that the prerequisites for trustworthy autonomy are structure, context and governance rather than model capability.
Shipped today are the structured and enriched telemetry described above, the governed data lifecycle covering retention and masking, AIOps with correlation and anomaly detection, and runbook automation with an approval workflow. That last item is the point at which a human authorisation step sits between an automated recommendation and an action taken in the estate.
Not shipped is the agentic layer itself. Motadata has declined to provide dates, feature names or demonstrations, and states only that agentic capabilities will release onto the same platform and the same licence without requiring a re-platforming exercise.
For security and risk functions asked to sign off on autonomous tooling, the more useful part of that statement is the part about approval workflow, which exists now and can be examined now. ObserveOps Infinity is generally available from August 2026.
