Fact 96
Nadia retains responsibility for alert semantics in the Cardinality Guardrails review path.
Source evidence (1)
000844Dec 12, 2023 / 10:36 UTC-05:00
Append this section: ## Required operating rule — narrow label-change class For production review after Dec 12, 2023, label changes that touch `metrics-router`, `shard-keeper`, or `rollup-service` must run the Cardinality Guardrails checks below before the change is treated as safe for production review. Required checks: 1. Label-cardinality preflight. - Identify new or changed label keys and changed value-shape behavior. - Show whether the value set is bounded, expected high-cardinality with an owner/budget, or effectively unbounded. - Use live canary evidence or a representative live-path fixture for live-path value-shape changes; replay evidence alone is not enough for a live-path label change. - Keep unbounded raw identifiers in logs or trace context unless a reviewed bounded metric dimension is justified. 2. Alert-source classification check. - Classify whether the relevant panel or alert signal is live-path, replay-source, mirror-source, or other validation-source evidence. - Replay or mirror movement can remain visible as investigation evidence, but it is not rollback criteria by itself. - Reviewers must not allow validation-source panels to read like live rollback triggers. Review path: - Nadia keeps alert semantics in the Cardinality Guardrails review path. - Cyrus keeps the cost/cardinality angle attached to review. - Rollup-service ownership remains with the Cyrus/data-platform side; this rule does not move enforcement ownership to data platform. Non-goals: - This is not a mature or complete Cardinality Guardrails program. - This is not a general telemetry rewrite. - This does not make Wes or any practical backup the default enforcement owner.
Message 000844 in history