SLO and Error Budget Service · View 11 of 21 · Data
Decisions
- Anything rebuildable from the record and the retained input is not backed up at all. Its recovery objective is stated in minutes of compute rather than as an RPO, because a backup of derived state is a slower way to get a staler answer (ADR-16).
- The evidence zone has no update path at all — immutable blob with time-based retention and tamper-evident ledger tables. An auditor's question is answerable without trusting the platform's own access control (ADR-14).
- Quarantined batches are a retained store rather than a dead-letter queue, because the operational act is "look at it, fix the source, replay" rather than "discard" (ADR-08).
Targets
- Registry and audit ledger RPO ≤ 1 minute, RTO ≤ 15 minutes. SLI aggregates RPO ≤ 5 minutes — all assumed.
- Minute buckets 13 months; snapshots and audit 5 years; alert decisions 13 months; cold archive tiered at 90 days — assumed.
- Derived state restored within 90 minutes of regional recovery, by recompute.
Risks
- A recovery path only exercised in an incident is a claim, not a capability. Shadow verification exists to keep the recompute honest (view 15).
- Write-once retention is irreversible by design: a retention policy set wrongly cannot be corrected, and the blast radius is five years of evidence.