TL;DR: HiBob’s case study shows how telemetry growth in a global HR platform can create noise, manual tuning, and cost pressure, while Sawmills says AI-powered log filtering and routing preserved audit visibility and improved debugging. The lesson for practitioners is that telemetry governance is now an operational control problem, not just a storage problem.
NHIMG editorial — based on content published by Sawmills: How HiBob took control of their telemetry
Questions worth separating out
Q: How should security teams govern telemetry when log volume grows too fast?
A: Treat telemetry as a governed control surface, not a storage problem.
Q: Why does telemetry noise matter to IAM and security programmes?
A: Because auditability depends on usable evidence.
Q: What breaks when telemetry routing is left entirely manual?
A: Manual routing usually leads to over-collection in some places and blind spots in others.
Practitioner guidance
- Define telemetry tiers by business and security value Classify logs, metrics, and traces into tiers that preserve identity, privilege, and incident-response events even when lower-value noise is filtered out.
- Map routing rules to retention and audit needs Set routing policies so high-value security events go to the right retention path, while routine operational noise is reduced before it inflates costs.
- Measure visibility by investigation usefulness Track how quickly teams can reconstruct access changes, failures, and anomalies from the retained telemetry instead of using raw volume as the main success measure.
What's in the full article
Sawmills' full case study covers the operational detail this post intentionally leaves for the source:
- The specific telemetry management workflow HiBob used to reduce noise across environments
- How routing and filtering decisions were applied to preserve audit visibility while cutting overhead
- The before-and-after operational outcome for DevOps debugging and cost control
- The practical implementation context behind the team’s clarity and observability improvements
👉 Read Sawmills' case study on how HiBob reduced telemetry noise and cost →
Telemetry management at scale: what it means for DevOps teams?
Explore further
Telemetry sprawl is a governance failure before it is a tooling problem. When log volumes rise faster than the team can classify and route them, the organisation loses control over what gets retained, reviewed, and investigated. That creates cost pressure, but the deeper issue is that visibility becomes uneven across services and environments. For practitioners, the real benchmark is whether telemetry still supports audit and incident response when needed.
A question worth separating out:
Q: What is the difference between cost reduction and telemetry governance?
A: Cost reduction focuses on spending less on storage or ingestion. Telemetry governance focuses on deciding which signals are kept, where they go, and whether they still support detection, forensics, and compliance. A lower bill is only useful if visibility remains intact for the events that matter.
👉 Read our full editorial: HiBob’s telemetry controls show how noise, cost, and audit needs collide