Skip to main content
Version: 0.1 (next)

Daily audit

Namedaily-audit
Enabled by defaultYes
Steps3
Runs at onceup to 1
Catalogv0.2.0

What it does​

A morning sweep of every Product's zones. Security, reliability and performance each get their own AgentRole; each one opens issues for what it finds, and the SRE audit writes a dated summary to the internal docs. The three steps are independent: they start together when the workflow starts, and one failing does not stop the others.

When it runs​

  • On a schedule, 0 6 * * *. Every day at 06:00 in the control plane's time zone.

Steps​

Rounded steps are human gates, slanted steps are promotions, and double-edged steps run automatically.

#StepTypeRunsRequiredOn failureAttempts
1security-watchAgentRoleSecurity watchNoContinue1
2sre-daily-auditAgentRoleSRE daily auditNoContinue1
3performance-watchAgentRolePerformance watchNoContinue1

1. security-watch​

Reviews logs and observability data for security signals and raises incidents.

Starts with the workflow, alongside the other independent steps. Skipped when its AgentRole is switched off.

2. sre-daily-audit​

Audits Application health, sync status, pins, certificates and error budgets, and writes the daily audit.

Starts with the workflow, alongside the other independent steps. Skipped when its AgentRole is switched off.

3. performance-watch​

Compares latency, throughput and resource use against baselines and advises on degradation.

Starts with the workflow, alongside the other independent steps. Skipped when its AgentRole is switched off.

When it hands off to a human​

Work an agent cannot finish is dead-lettered to @platform/sre. The AgentWorkflowRun shows the step as DeadLettered until a human picks it up.