| Outcome cube |
The small declared set of counter cells a source emits per SLO per minute — counts by status class and by latency bucket. |
The emission contract, and the thing that decides which future predicate changes are recomputable (ADR-03). |
"Metrics", which implies the platform receives arbitrary time series rather than a bounded, declared shape. |
| Valid-event denominator |
The explicit statement of which events count toward the SLO at all — which status classes, synthetic traffic, health checks and client-cancelled requests are in or out. |
Where an SLO is really defined, where it is later quietly widened, and the one thing admission refuses to let a definition leave implicit (ADR-15). |
"Total requests", which sounds unambiguous and is the source of most disagreement about what an SLO means. |
| Coverage |
The fraction of a window's expected minute buckets that were actually present and not no-data. |
Published alongside every figure, so a number is never read as more certain than the data behind it; below the floor the verdict becomes insufficient-data (ADR-04). |
"Data quality", which bundles completeness together with correctness and hides which one failed. |
| no-data |
A bucket state meaning no valid events were observed for that minute — neither good nor bad, and excluded from both numerator and denominator. |
The mechanism that stops a stopped metrics pipeline reading as a perfect month. |
Zero, which an arithmetic pipeline will divide by or treat as success. |
| insufficient-data |
A first-class verdict value, returned instead of a figure when coverage is below the floor or the projection is staler than the ceiling. |
The platform's way of declining to publish something it cannot substantiate; every consumer must handle it as distinct from healthy. |
An error or a null, both of which consumers routinely treat as "carry on". |
| Burn rate |
Error budget consumption per unit time, normalised so that 1× exhausts the window's budget exactly at its close. |
The only alerting signal with a defensible relationship to the objective (ADR-09). |
Error rate or error percentage, which fires on a bad minute regardless of whether any commitment is threatened. |
| Confirmation window |
A short evaluation window that must agree with the long window before an alert fires. |
What stops a single anomalous minute paging an on-call engineer. |
"For duration" or a debounce, which delays an alert without requiring a second independent agreement. |
| Verdict |
A signed, typed, time-limited document stating healthy, warning, exhausted or insufficient-data, with the figure, definition version, computation timestamp and coverage. |
The platform's entire output to machines. It is a claim, not an instruction (ADR-12). |
"Gate result" or "check status", which imply the platform performed the enforcement. |
| Watermark |
The most recent minute the budget projection has incorporated. |
What makes staleness measurable, and therefore what makes the staleness ceiling and the insufficient-data refusal possible (ADR-07). |
"Last updated", which is usually the time of the write rather than the time of the data. |
| Exclusion window |
An approved interval annotated as outside the valid-event denominator, with a reason code, two approvers and an expiry. |
The sanctioned way to say a bad interval should not count, designed so the unexcluded figure survives (ADR-11). |
"Maintenance window" or "downtime exemption", which imply the data was removed rather than annotated. |
| Sealed snapshot |
The immutable record of a calendar window's figure, written once at close with no update path. |
The compliance record, as distinct from the freely recomputable operational figure (ADR-14). |
"Monthly report", which in most systems is regenerated from current state and therefore changes between readings. |
| Fail static |
The release gate continuing to enforce its last verified cached verdict while the platform is unreachable, up to a declared staleness ceiling. |
The declared answer to the unreachable case, chosen over fail-open and fail-closed (ADR-13). |
"Fail safe", which is ambiguous here — open and closed are each the safe option under a different failure. |
| Derived state |
The budget projection, compiled alert rules and report extracts — a deterministic function of the registry and the minute buckets. |
Deliberately not backed up; its recovery objective is recompute time rather than an RPO (ADR-16). |
"Cache", which understates it — consumers read it as authoritative, so its staleness has to be published. |
| Measurement failure |
An alert class meaning the platform cannot see an SLO, as distinct from an alert meaning the service is failing. |
Routed to the platform rotation rather than the service rotation, so triage starts at the broken system (ADR-10). |
A low-severity reliability alert, which still points the reader at the wrong system. |