Consent & Privacy Service  ·  View 17 of 22  ·  Operations

Observability

Six signal families across six stages, reduced to four alarms that a human is woken for.

Editable source SVG draw.io All views
Capture Projection Decision Propagation Rights cases Evidence Availability & latency ack p99 build lag p99 by cache hit dispatch rate intake errors replay time Freshness projection age cache staleness lag per point Correctness rejected purposes rebuild diff late ALLOW count unconsumed events reopened cases hash chain breaks Compliance SLA recipients overdue case clock at risk retention overdue Security forged-grant score purpose scope denials index reads per case admin overrides Cost writes per tenant remote-eval ratio fan-out per purpose cost per case archive retrieval Observability — Signal Families by Stage Four alarms page a human: propagation lag past the ceiling, a late ALLOW, a case clock at risk, and a broken hash chain. Everything else is a dashboard. v 1.0 · owner Security & Identity Architecture

Decisions

  • Four signals page: propagation lag past the ceiling, a late ALLOW, a case clock at risk, and a broken audit hash chain. Each maps to a distinct action by a distinct owner.
  • Propagation lag is a compliance metric rather than a performance one, which changes who is paged and what the response is: it is unlawful processing accruing, not a slow page.
  • Retention-overdue and recipients-overdue are findings against named system owners, not platform alarms. The platform detects; the owner remediates.

Assumptions

  • Decision outcomes sampled rather than fully audited; sample rate is a declared parameter with a stated detection confidence.
  • Remote-evaluation ratio is monitored and expected to stay low; steady-state decision cost is dominated by local cache hits.

Gaps

  • Freshness has no signal at Capture, Rights or Evidence, because nothing there is derived. Empty cells in this view are statements, not omissions.
  • There is no signal for "a system is using data for a purpose it never declared" other than the unregistered-use finding in view 19. That is the weakest detection in the package.