SYSE.37:1 - Problem frame
Use this pattern when a measured service objective and a usable response arrangement exist, but alerts arrive too often, too late or without an action someone can take. Start with the loss that matters, the time available to respond and the person or mechanism actually able to act.
The first result is an exercised alert rule with its intended response and known blind spots, or the exact missing observation or response capability. An alert rule alone is not an operating on-call arrangement.
For budget-risk alerting, use the same service, task population, configuration and objective defined through SYSE.36. Do not borrow another service’s SLO. A directly observed critical failure may need its own alert without waiting for an aggregate budget calculation. A dashboard trend that can wait for ordinary planning does not automatically warrant an interrupting notification.