How the monitor works

The monitor is automatic. No single person decides a system's status or the global level.

Sources

  • Availability probes call each provider's public endpoints every minute and record whether they answer and how fast.
  • Provider status pages are read every minute and mapped to our four statuses.
  • Behavior canaries send fixed prompts and check the answers against expected behavior, for deception, refusal drift and unsafe actions. A failure rate far above the system's own baseline marks it as anomalous.
  • Public reports are weighted by each sender's track record. A spike far above the usual volume opens a "watching" event.

Statuses

Normal, Degraded, Anomalous behavior, Outage. An outage needs most availability probes to fail at once.

Events

Events open and close automatically. Researchers can confirm, annotate or dismiss them; every change is logged.

The level

Each active event adds to a risk score according to its category, state and confidence. The score maps to five levels: Calm, Guarded, Elevated, Severe, Critical. A manual override is possible only for a limited time, needs a written reason, and is labeled on the site.