SLO and Error Budget Service · View 06 of 21 · People and journeys
The trough, and what answers it
- The low point is the valid-event denominator. It is where an SLO is really defined, where it is later quietly widened, and the place two reasonable engineers disagree about client-cancelled requests for forty minutes.
- The platform's answer is refusal: a definition that leaves the denominator implicit is rejected, and so is an objective whose budget is finer than minute buckets can resolve (ADR-15).
- Dry-run over 28 days of retained history makes the argument empirical rather than theoretical before the definition merges.
What the architecture owes this journey
- The outcome cube's declared dimensions, which bound what a predicate can say and therefore what can be redefined retroactively (ADR-03).
- Versioned immutable definitions with an effective-from timestamp, so correcting a mistake produces a corrected history rather than a silent rewrite (ADR-05).
- A journey catalogue, so the unit of reliability is something a product owner recognises rather than an endpoint path.
Risks
- Ownership of the definition is left with the service team in this design. That makes targets achievable and comparability across 400 services weak — the open question the package does not close.
- The cube's dimensions are fixed at emission. A predicate the team wants later and the cube cannot express requires a change in a system this platform does not own.