SLO and Error Budget Service · View 09 of 21 · Structure
Decisions
- Reading a verdict is open to the whole organisation; reading a team's unpublished detail is tenant-scoped; changing what the arithmetic may say is three named grants on a separate API (ADR-11).
- Ingest is a stream the platform consumes, not an API it exposes. A source cannot push a figure synchronously and get a success code, which keeps back-pressure a platform-side concern (ADR-08).
- The incident platform is inbound rather than outbound: it supplies the incident identifiers the platform correlates intervals against, and reads nothing.
Assumptions
- All machine callers authenticate with workload identity federation and short-lived tokens; no long-lived API keys anywhere.
- Monthly reporting is a batch extract, not a live query against the aggregate store.
Risks
- The verdict API is the one surface whose unavailability has an organisation-wide effect, which is why its contract includes what the caller does when it is absent (ADR-13).
- A tenant-scoped query API over a shared aggregate store is a per-request authorisation decision on every read; a scoping bug leaks another team's unpublished attainment.