SLO and Error Budget Service · View 19 of 21 · Assurance
Decisions
- Reading a verdict is deliberately easy and organisation-wide. The two privileges that can make a breached objective appear met sit behind separation of duties and an append-only record (ADR-11).
- The verdict carries a validity period because a signed document is otherwise replayable forever — the replayed-verdict risk in the untrusted zone is rejected on valid_until, not on signature (ADR-12).
- The signing key is non-exportable in a managed HSM. The platform can be compromised without the ability to mint a verdict that survives verification elsewhere.
Assumptions
- Four independently assignable privileges: author a definition, approve an exclusion, grant an override, read budget state — assumed as the minimum viable split.
- A second approver is required for an exclusion beyond 60 minutes — assumed threshold.
- SLI aggregates carry no personal data, enforced by rejecting definitions whose label dimensions would introduce user identifiers.
Risks
- Two colluding approvers defeat the entire exclusion control. Nothing in this architecture detects collusion; the override register and exclusion-minutes metric make it visible after the fact, which is the accepted residual.
- The query API is tenant-scoped on a shared aggregate store, so authorisation is a per-request decision on every read. A scoping bug leaks another team's unpublished attainment.