Record and query authentication_attempt_completed
Document what each authentication_attempt_completed row represents and which service sends it. Send test events to check the fields, then verify that the query answers your question.
- 1
Outcome becomes final
Identity service after the provider outcome is known emits only after authentication succeeds, fails, is challenged, or is rate limited.
- 2
Choose the fields
5 required fields preserve the declared grain: One completed authentication attempt.
- 3
Check the test event
Check types, UTC time, alternate outcomes, idempotency, and every pseudonymous or review-classified field.
- 4
Query the result
Which authentication methods, clients, and risk categories are producing failures or suspicious bursts?
Grain
One completed authentication attempt.
Owner
Identity service after the provider outcome is known
Emit when
After authentication succeeds, fails, is challenged, or is rate limited.
Field contract
Field types and data to exclude
Keep field names and types stable once production queries depend on them. Document optional fields and add them only when they answer a specific question.
| Field | Type | Required | Privacy | Meaning |
|---|---|---|---|---|
| timestamp_utc | timestamp | yes | non-sensitive | UTC time when the operation finishes. |
| event_id | string | yes | non-sensitive | Stable unique identifier used for deduplication. |
| release | string | yes | non-sensitive | Application or service version that emitted the event. |
| actor_id | string | no | pseudonymous | Stable internal actor identifier when the account is known. |
| session_id | string | no | pseudonymous | Rotating session or attempt correlation identifier. |
| auth_method | string | yes | non-sensitive | Bounded method such as password, passkey, SSO, or recovery. |
| outcome | string | yes | non-sensitive | Success, invalid_credentials, challenged, denied, or rate_limited. |
| risk_category | string | no | review | Reviewed low-cardinality risk classification, not a raw fingerprint. |
Synthetic JSON event
{
"timestamp_utc": "2026-07-29T09:12:00Z",
"event_id": "evt_auth_01",
"release": "2026.07.3",
"actor_id": "user_91ac",
"session_id": "session_b471",
"auth_method": "passkey",
"outcome": "success",
"risk_category": "normal"
}Privacy review
Review identifiers before ingestion
This example uses synthetic identifiers. Pseudonymous values can still be personal data, and review fields can expose business or provider context. Apply your own consent, retention, access, residency, and deletion requirements.
actor_id: pseudonymoussession_id: pseudonymousrisk_category: review
Validation checklist
Test the schema before building a dashboard
- Send one known authentication_attempt_completed fixture after the documented outcome boundary.
- Verify all 5 required fields arrive with the documented types.
- Retry the same event identifier and confirm the chosen deduplication behavior.
- Send a controlled failure or alternate outcome when the workflow supports one.
- Run the related SQL over a fixed window and reconcile the result to the fixture.
Common mistakes
Record one result per row
- Emitting authentication_attempt_completed before identity service after the provider outcome is known knows the final outcome.
- Mixing different kinds of results in one table, which makes counts and rates ambiguous.
- Replacing controlled categories with raw URLs, payloads, prompts, or error text.
- Changing a field type in place after saved queries and dashboards depend on it.
- Adding identifiers without a documented investigation, access, and retention need.
Use the contract
Query the event and set up monitoring
Related contracts
Send a test event before production traffic
Create a free API key, send the synthetic event, and inspect the inferred table before connecting a live workflow.