Error budgets
How much unreliability you can spend — using budget to balance velocity and reliability.
An error budget is the gap between 100% and your SLO. If the SLO is 99.9% success over 30 days, the budget is the allowed failure fraction in that window.
Budget is a decision tool
While budget remains, you can ship features, experiments, and risky changes — within reason. When budget is exhausted, prioritize reliability work: freeze risky releases, fix classes of failure, improve tests and rollouts.
Without a budget, every outage is drama and every release is either reckless or frozen by fear.
Spending is expected
Perfect reliability is not the goal. Planned maintenance, canaries gone wrong, and dependency blips spend budget. The point is conscious spend, not zero spend.
Do not game the math
Excluding outages after the fact, shrinking the window, or redefining “success” mid-incident empties the practice of meaning. Change SLOs deliberately, with product agreement.
Connect to release policy
Write the policy: what happens at 50% budget burned, at 0%, during a sustained burn. Policies that live only in a slide deck fail at 3 a.m.