SLO and Error Budget Service  ·  View 09 of 21  ·  Structure

Integration Surface

Three surfaces, separated by their authorisation story rather than by their protocol.

Editable source SVG draw.io All views
Inbound Indicator stream Definitions repository Reliability console Incident platform SLO & Error Budget Service Verdict API signed, typed, cacheable Budget query API budget, intervals, coverage Privileged API exclusions, overrides, policy Outbound Release gate Action groups Reporting sink buckets SLOs HTTPS incidents verdict Integration Surface — Who Calls, Who Is Called Queue / topic External / third party Application we own Interface / broker Security / platform event / async synchronous Three surfaces separated by their authorisation story: anyone may read a verdict, a team may read its own detail, and three named roles may change what the arithmetic is allowed to say. The ingest path is deliberately not an API — it is a stream the platform consumes. The audit export is omitted here and appears in views 11 and 20. v 1.0 · owner Reliability Architecture · date 2026-10

Decisions

  • Reading a verdict is open to the whole organisation; reading a team's unpublished detail is tenant-scoped; changing what the arithmetic may say is three named grants on a separate API (ADR-11).
  • Ingest is a stream the platform consumes, not an API it exposes. A source cannot push a figure synchronously and get a success code, which keeps back-pressure a platform-side concern (ADR-08).
  • The incident platform is inbound rather than outbound: it supplies the incident identifiers the platform correlates intervals against, and reads nothing.

Assumptions

  • All machine callers authenticate with workload identity federation and short-lived tokens; no long-lived API keys anywhere.
  • Monthly reporting is a batch extract, not a live query against the aggregate store.

Risks

  • The verdict API is the one surface whose unavailability has an organisation-wide effect, which is why its contract includes what the caller does when it is absent (ADR-13).
  • A tenant-scoped query API over a shared aggregate store is a per-request authorisation decision on every read; a scoping bug leaks another team's unpublished attainment.