SLO and Error Budget Service · View 01 of 21 · Context and scope
Decisions
- The platform's output is a derived figure and a signed verdict — never a collected metric and never an enforcement action. Both the measurement plane above and the release gate to the right are outside the boundary (ADR-02).
- The release gate is modelled as an actor rather than an integration, because it is the only consumer that acts on a verdict with no human reading it. That is what forces the verdict to be signed, typed and time-limited (ADR-12).
- The definitions repository is an inbound dependency: the registry is a projection of reviewed text, not a system of authorship (ADR-05).
Assumptions
- 1,200 SLOs across 400 services and 60 critical user journeys at launch, growing 30% a year.
- Upstream aggregation reduces 2.5 million requests/second of measured traffic to ≤ 25,000 samples/second entering the platform.
- Both the incident platform and the paging system already exist and are owned elsewhere.
Deliberately omitted
- Key custody and the audit ledger, which would crowd this view; they are drawn in views 19 and 20.
- Dashboards and trace storage, which belong to the observability platform and are not a gap in this design.