Feature Store · View 14 of 21 · Runtime
Decisions
- The three inputs — table snapshot, feature versions, lookback — are pinned before the join runs and recorded in the manifest, which is what makes a training set regenerable bit-identically.
- A value outside the declared lookback returns a reason-coded null rather than reaching arbitrarily far back. Silent long-reach is how a stale value becomes a training label.
- The leakage detector warns on the dataset rather than blocking it: a feature whose ingestion lag routinely exceeds the spine's horizon is a modelling problem, not a platform error.
Assumptions
- 500M spine rows × 200 features p95 ≤ 45 min, hard ceiling 90 min; 10M × 50 p95 ≤ 5 min.
- Default maximum lookback 72 hours, per-feature override.
- Zero point-in-time violations tolerated — a value whose ingestion timestamp postdates its row timestamp is a Sev-1.
Risks
- A late-arriving event changes future training sets and never restates a generated one. Two models trained a week apart on the same spine can therefore differ legitimately, and someone will read that as a bug.