Log the final result
Record the event only when the service knows the final status, duration, and business identifier.
Define what one row represents
Use one row per request, job, payment attempt, or completed milestone to avoid counting it twice.
Use stable IDs and exclude private data
Prefer route templates and stable IDs. Exclude raw URLs, emails, prompts, payloads, credentials, and stack traces.
Complete contracts
Choose the result your service records
user_signed_upWhich signup cohorts activate and retain?
An event for a completed signup, with acquisition and plan fields. Use a pseudonymous account identifier and review marketing attribution fields for privacy before collecting them.
- Grain
- One accepted signup per user and account.
- Fields
- 7 documented
product_milestone_completedWhich accounts complete the milestones you use to define activation?
A generic milestone envelope for stable product outcomes such as connecting a source, running a first query, or publishing a dashboard.
- Grain
- One completed milestone per actor, account, and occurrence.
- Fields
- 8 documented
api_request_completedWhere do errors and slow requests affect customers?
An event sent when a request finishes. Use route templates instead of raw URLs, choose errors from a fixed list, and measure latency at the service.
- Grain
- One completed API request.
- Fields
- 10 documented
llm_request_completedWhat does each successful AI workflow cost and how well does it perform?
Record a completed model call with its model, token usage, latency, allocated cost, and tool outcome. Exclude prompts and generated content.
- Grain
- One completed model-provider request.
- Fields
- 10 documented
background_job_completedWhich jobs fail, retry, wait, or run slowly?
A final job event that records the final outcome and attempt count once, avoiding the overcounting caused by one row per retry.
- Grain
- One terminal outcome per logical job.
- Fields
- 11 documented
invoice_payment_completedWhich billed amounts succeed, fail, or recover?
A payment outcome event that keeps provider identifiers pseudonymous and separates billed amount from recurring-revenue definitions.
- Grain
- One terminal payment attempt.
- Fields
- 9 documented
webhook_delivery_completedWhich destinations fail permanently, which status codes recur, and which deliveries recover after retries?
Record a completed delivery with attempt_count, final status_code, response_body_bytes, and a content type from an allowed list. Exclude customer URLs, headers, authorization, response bodies, and payloads.
- Grain
- One final outcome per logical webhook delivery.
- Fields
- 11 documented
incident_impact_observedWhich accounts and workflows were affected during an incident?
An event that links a declared incident to an affected customer workflow. Keep request payloads out of the incident record.
- Grain
- One affected operation associated with a declared incident.
- Fields
- 9 documented
authentication_attempt_completedWhich authentication methods, clients, and risk categories are producing failures or suspicious bursts?
An event sent when a sign-in attempt finishes, with method, result, and risk values from fixed lists. Exclude credentials, tokens, raw IP addresses, and free-form provider errors.
- Grain
- One completed authentication attempt.
- Fields
- 8 documented
browser_performance_observedWhich routes, releases, and device classes have degraded user-visible performance?
A sampled browser measurement with a named metric, numeric value, route template, and release context. Raw URLs, user agents, and DOM content stay outside the event.
- Grain
- One sampled browser metric observation.
- Fields
- 8 documented
database_operation_completedWhich operation fingerprints, releases, and database roles are slow or failing?
A completed database operation represented by a reviewed fingerprint and coarse operation metadata. SQL text, bound values, credentials, and customer records are excluded.
- Grain
- One completed application-owned database operation.
- Fields
- 9 documented
kubernetes_workload_observedWhich workloads, clusters, and releases are restarting, unavailable, or resource constrained?
A periodic workload snapshot with normalized Kubernetes coordinates and aggregate state. Pod logs, environment variables, secret names, and annotations are excluded.
- Grain
- One workload snapshot per cluster, namespace, and interval.
- Fields
- 8 documented
ai_agent_run_completedWhich agent versions complete the intended task, require handoff, loop, or fail?
Record how each agent run ends, its workflow version, tool use, cost, and reviewed result. Exclude prompts, completions, tool arguments, and retrieved content.
- Grain
- One terminal outcome per logical agent run.
- Fields
- 10 documented
agent_tool_authorization_decidedWhich agent tool actions are allowed, denied, or routed to human approval?
Record the policy decision before an agent calls a tool that can change data or take action. Use approved tool, risk, decision, and policy values. Exclude prompts, arguments, results, credentials, and customer content.
- Grain
- One final authorization decision per logical tool-call attempt.
- Fields
- 12 documented
feature_rollout_evaluatedHow do rollout cohorts differ in adoption, reliability, and customer outcomes?
A versioned feature assignment record that makes exposure rules queryable without copying targeting expressions or personal attributes.
- Grain
- One effective feature evaluation per actor, feature, assignment version, and material change.
- Fields
- 9 documented
agent_tool_call_completedWhich tools fail, retry, loop, or add latency before an agent reaches a useful outcome?
An event sent when a tool call finishes, for checking agent reliability. Keep arguments and results in the trace system. Send only approved categories and identifiers to link related events.
- Grain
- One completed tool-call attempt within an agent run.
- Fields
- 11 documented
rag_retrieval_evaluatedWhich retrieval and prompt versions produce relevant context and grounded accepted answers?
A versioned RAG evaluation event that separates retrieval scores, answer review, latency, and cost without storing source text, prompts, or generated answers.
- Grain
- One evaluator result per eligible query, retrieval version, evaluator, and candidate run.
- Fields
- 11 documented
subscription_changedHow much recurring revenue is new, expanded, contracted, churned, or reactivated?
A revenue movement event emitted from committed billing state. Store normalized plan and movement values rather than invoice bodies or payment-provider payloads.
- Grain
- One committed recurring-revenue movement per account, subscription, and effective change.
- Fields
- 10 documented
usage_meter_recordedWhich accounts are approaching a quota, and can metered usage be reconciled to the billing ledger?
An idempotent usage-meter record with quantity, unit, meter version, and billing period. Keep raw source payloads and customer content outside the analytical event.
- Grain
- One accepted usage increment per idempotency key and meter.
- Fields
- 10 documented
telemetry_delivery_observedAre application events arriving completely, promptly, and without retry amplification?
An event your app records for a telemetry delivery attempt. Send it to a separate destination or sample a limited number of attempts so logging a delivery does not create another delivery event indefinitely.
- Grain
- One sampled or aggregated observation per delivery attempt or delivery window.
- Fields
- 11 documented
Review each field before collecting it
Pseudonymous identifiers can still be personal data when they relate to a person. Fields labeled for review can expose acquisition or provider details. Check these schemas against your retention, access, consent, deletion, residency, and contractual requirements before using them in production.