Arch 02 — Governance, Streams & Standards

SME Track: Architects

Presenter: Specialist (DSR)

Date: 2026-09-23

SLB × Elastic Workshop Program

Overview

Governance — Streams standards, schema conventions, and AI agent policies across deployments.

Where this applies

These labs run on Observability Serverless — a fully managed project so you can practice without cluster operations.

The same capabilities you explore here — ES|QL, Streams, AI Assistant, Agent Builder, Workflows, and SLOs — are available on Elastic Cloud Hosted (ECH) and self-managed deployments.

Serverless mainly saves operational toil (sizing, ILM, Fleet, upgrades). Your observability skills transfer directly.

Session topics

  • Streams naming and ownership standards
  • Managed retention on Serverless vs self-managed ILM
  • ECS vs OTel semantic conventions
  • Agent Builder and AI governance

Why these features?

Elastic StreamsManaged routing and processing for telemetry
🔐API keys & accessSecure multi-team automation on any deployment
🤖Agent BuilderRepeatable AI workflows with guardrails

Use → to see why each feature matters for SLB.

Why Elastic Streams?

Managed routing and processing for telemetry

Without it

Custom ingest pipelines, index templates, and rollover policies per team — fragile, hard to govern, and different on every cluster.

With Elastic Streams

Streams define how logs, metrics, and traces are routed, processed, and retained — on Serverless, ECH, and self-managed, with a unified UI.

  • Reduce DIY pipeline + ILM work with declarative stream rules
  • Consistent ownership and naming across SLB domains
  • On self-managed/ECH you may still use ILM — Streams simplify routing either way
Ingest
Streams
Search & alerts

Why API keys & access?

Secure multi-team automation on any deployment

Without it

Shared credentials, over-privileged scripts, and no clear ownership per integration.

With API keys & access

Scoped API keys and role patterns — project keys on Serverless, deployment keys on ECH, native users on self-managed.

  • Automate dashboards and CI checks without shared passwords
  • Audit who can query vs who can configure Streams
  • Architect-friendly boundary between teams on one project
Team
API key
Scoped access

Why Agent Builder?

Repeatable AI workflows with guardrails

Without it

Ad-hoc ChatGPT sessions with no access to SLB data, no audit trail, and inconsistent answers per engineer.

With Agent Builder

Build agents that use observability context, tools, and retrieval — tuned prompts your team can trust and share.

  • Standardize "investigate service X" and "summarize deploy" playbooks
  • Connect tools (ES|QL, alerts, docs) instead of copy-paste context
  • Govern who can publish agents — architecture-friendly AI ops
Agent
Tools + data
Action

Hands-on lab

Your lab uses Elastic Observability Serverless for a zero-ops learning environment.

The steps and features are the same on ECH and on-prem — follow the assignment panel when Kibana opens.

Instruqt track: slb-sme-architects

Resources

  • Registration: events.elastic.co/slbworkshops
  • Repo: github.com/poulsbopete/slb-workshops
  • Use ← → arrow keys to navigate slides