Use cases

Start with the failure mode, not the industry label.

Healthcare, payments, SaaS, privacy, and platform engineering have different regulatory and operating contexts, but the telemetry problems often reduce to the same four questions: what should be found, governed, enforced, and proven?

01Common problems

The buyer's problem should determine the first Cerbi surface.

Not every use case should begin with the same product. Discovery-heavy problems start with Scanner. Existing OTLP adoption can start at Gateway. Evidence-heavy programs may begin with the CerbiShield operating model.

01

Sensitive data exposure

Find logging patterns and fields that should not travel downstream, then enforce the appropriate redact, drop, block, or policy decision at the selected boundary.

02

Inconsistent telemetry

Turn naming, required fields, prohibited fields, and schema expectations into explicit policy instead of relying on team-by-team conventions.

03

OTLP estate adoption

Govern selected OpenTelemetry traffic through a customer-hosted Gateway when adding an application SDK everywhere is the wrong rollout strategy.

04

Audit and evidence

Keep policy, versions, targets, deployments, violations, exceptions, and audit context connected to the control instead of reconstructing them during review.

02Product proof

Use violations to move from category language to a real remediation workflow.

Regardless of industry, the product needs to show where policy failed, which workload and rule were involved, and enough context to decide what should change next.

See the Dashboard journey
CerbiShield / Violations ExplorerActual Aug 2026 preview
CerbiShield Violations Explorer
Actual release-preview UI. The preview tenant intentionally contains no fabricated customer violation activity.
03Scenario patterns
01

Healthcare

Reduce patient-data exposure in telemetry.

Constraint

PHI-sensitive logs, distributed services, audit requirements

Governance path

Scanner → policy → Stream or Gateway → Evidence

Use Scanner to find risky logging before deployment, then govern selected sensitive fields at the application or OTLP boundary while keeping the existing observability system downstream.

Useful outcomes

Reduce accidental PHI propagation
Make exceptions explicit
Retain reviewable policy and violation evidence

Supports logging controls in HIPAA-sensitive environments. It is not a HIPAA certification.

02

Payments

Keep payment and credential data out of log pipelines.

Constraint

Card data, tokens, secrets, exception payloads

Governance path

Scanner → prohibited-field policy → enforce → investigate

Find payment-field and credential risk in source, then apply policy before governed telemetry reaches long-term storage, analytics, or secondary destinations.

Useful outcomes

Constrain prohibited values
Keep required transaction context
Track where policy was active

Supports reduced cardholder-data exposure in logs. It is not a PCI DSS certification.

03

Enterprise SaaS

Standardize logging without forcing one runtime integration.

Constraint

Many teams, languages, schemas, and exception patterns

Governance path

Scanner → shared policy → mixed Stream / Gateway estate

Use a shared CerbiShield policy lifecycle while allowing selected applications to use in-process enforcement and existing OTLP workloads to use Gateway where appropriate.

Useful outcomes

Reduce schema drift
Target policy by workload
Operate one governance program across mixed boundaries

Designed for multi-team environments that need shared telemetry standards without replacing every team's logging framework.

04

Privacy & minimization

Reduce personal data copied into observability systems.

Constraint

PII, retention pressure, multiple downstream copies

Governance path

Discover → minimize → enforce → prove

Identify personal-data risk in source and govern selected fields before they continue to analytics, archives, SIEMs, or other secondary destinations.

Useful outcomes

Reduce unnecessary data propagation
Version policy and exceptions
Create evidence for privacy/security review

Supports privacy-conscious logging practices. It is not a GDPR certification or legal advice.

05

Platform engineering

Roll out governance without a platform rewrite.

Constraint

Existing loggers, existing OTel, existing destinations

Governance path

Start where the estate already is

Use Scanner for discovery, CerbiShield for policy, Stream for selected applications, and Gateway for selected OTLP estates while leaving the downstream observability strategy intact.

Useful outcomes

Choose the least disruptive boundary
Centralize policy lifecycle
Make deployment and health visible

A practical fit for platform teams responsible for standards across many services and engineering groups.

06

Security & audit

Turn a logging standard into an operating record.

Constraint

Evidence gaps, undocumented exceptions, unclear rollout state

Governance path

Policy → deployment → violations → evidence

Use CerbiShield to keep the governance lifecycle visible so reviewers can understand which control was intended, where it was active, what violated it, and what changed later.

Useful outcomes

Track policy/deployment history
Review violation context
Present bounded evidence without using Cerbi as the raw-log archive

Supports evidence for internal logging controls. It is not a SOC 2 or ISO 27001 certification.

04Evaluation pattern

Use one real workload to prove the control.

The industry context matters, but the first proof should stay bounded enough that every policy decision can be explained.

01

Find

One actual risk

02

Govern

One explicit rule

03

Enforce

One selected boundary

04

Prove

One evidence chain

Different use cases still converge on one control plane.

Whether the entry point is regulated telemetry, an OTLP estate, platform standards, or audit preparation, teams operate the same posture, enforcement, investigation, and evidence lifecycle in CerbiShield.

Current CerbiShield governance command center used across telemetry governance use cases
Real August 2026 release-preview capture. The preview tenant contains no connected customer workload or production telemetry.
NEXTChoose your next proof

Use CerbiStream inside selected applications, Cerbi Gateway at the OpenTelemetry boundary, or both. CerbiShield keeps policy, rollout, violations, audit, and evidence under one governance program.

One initial workload/Customer-hosted in Azure/Existing destinations remain
Cerbi Use Cases | Telemetry Governance by Problem | Cerbi