Define the boundary
Choose a service group, ownership domain, environment, critical user journey, or incident class. Record approved signals and fields, expected volume, data classification, region, retention, and notification destinations.
Mirror telemetry from a representative production boundary while your current observability and paging systems remain the control. Prove the incident outcome against an agreed scorecard before Epok earns a wider operational role.
shadow mode · independent telemetry path · current paging authoritative · no automated remediation
Choose a service group, ownership domain, environment, critical user journey, or incident class. Record approved signals and fields, expected volume, data classification, region, retention, and notification destinations.
Fan out approved telemetry through OpenTelemetry or an open shipper using an ingest-scoped key. Give the Epok destination its own queue, timeout, retry policy, and volume ceiling so it cannot disturb your existing path.
Existing telemetry destinations, monitors, dashboards, paging, and incident command remain authoritative. Epok observes, groups, and recommends; your responders decide and execute.
Use agreed production incident windows, synthetic failures, or approved failure exercises. Include enough related systems to test the cross-service topology your responders actually face.
Classify each incident as correct, incorrect, abstained, or missed. Measure alert fanout, time from first page to verified cause, false pages, telemetry coverage, and responder effort.
Review the pre-agreed quality, security, and operational gates. Expand through a separately approved change, keep the bounded deployment, or revoke the key and remove the exporter for a clean exit.
Do not combine abstentions with wrong conclusions, and do not call a trial successful because data arrived. Agree on the incident cohort and thresholds before ingest begins, then review both systems against the same windows.
Google OAuth, scoped ingest/read API keys, EU-hosted primary infrastructure, DPA on request, and timestamped alert-action history.
Capacity above published self-service limits, custom retention or residency, dedicated or self-hosted deployment, and contracted support requirements.
Microsoft login, SAML enterprise SSO, SCIM, and a completed SOC 2 Type II report. Production approval depends on your organization's requirements.
Inspect the product without signup, run a self-service workspace, or define a governed evaluation with us.