Use Cases
When an SLO breaches, you want the release that caused it. Here that takes three screens, from the alert to the commit, all on the same time range.
signal checkout p99 380 ms · threshold 200 ms
The path
The SLO is checkout p99 at or under 200 ms. Each screen below is filtered to the window where it was breached.
The rule is written against the SLO, so the notification carries the threshold, the observed value and the evaluation window. 380 ms against 200 ms, sustained across three windows.
p50 has not moved. p99 has. If the whole service were slow, p50 would move too, so the problem is one route. The route breakdown shows which: POST /checkout.
Split the same endpoint by service.version: p99 is 120 ms on abc123 and 380 ms on def456. Traces under def456 have 50 db.query spans where the earlier ones have 3.
outcome
Reverted def456 at T+9:20. p99 back under the threshold on the next evaluation window.
What it does
Keep going
One endpoint, one key. Traces, logs, metrics and sessions, linked from the first request.