---
title: "Operations, security and observability"
description: "Operations, security and observability: the 4 calls this system serves, each a route of the API and a tool of the MCP server, at contract 0476e35e6e275db5."
section: systems
address: /systems/19-operations-security-and-observability
contract: 0476e35e6e275db5
---

# Operations, security and observability

Operations, security and observability: the 4 calls this system serves, each a route of the API and a tool of the MCP server, at contract 0476e35e6e275db5.

[figure: Operations, security and observability: 4 calls of the contract, by family.]

# Operations, security and observability

The 4 calls below are the whole of this system on the wire: each is one route of the API and one tool of the MCP server, with one typed input, one card as its answer and one refusal shape. Every answer carries its foot: what was read, the population and the control.

## The calls



| tool | route | takes | gives |
|---|---|---|---|
| [si.read.invoices](/reference/tools/si-read-invoices) | [POST /v1/read/invoices](/reference/read/invoices) | a period, or nothing | the invoices with their states |
| [si.read.usage_statement](/reference/tools/si-read-usage_statement) | [POST /v1/read/usage_statement](/reference/read/usage_statement) | a period | the tenant's usage of the period by kind, priced, against the plan |
| [si.view.usage](/reference/tools/si-view-usage) | [POST /v1/view/usage](/reference/view/usage) | a tenant, a kind, a provider, a window | quantity and cost by kind, by tenant, by provider and by period, with each provider's reconciliation state |
| [si.act.change_plan](/reference/tools/si-act-change_plan) | [POST /v1/act/change_plan](/reference/act/change_plan) | the plan kind | the change as a proposal, and the provider's own page for payment |



## The bars this system enforces

Every bar is a row of the parameter register: an administrator changes it, and the platform reads it by name at the place of enforcement the row records.

| parameter | family | dimension | enforced at |
|---|---|---|---|
| the longest a service may take to publish ready after starting | machinery | a time | the alarm on a service's life |
| the age at which a backup reads not current | machinery | a time, two days by default | the reader of backups |
| the beat of the restore drill, and of the proof of the trails' chains | machinery | a time | the beats |
| the ceiling on cost by kind, and the share that raises an alarm | receive | money, and a share | the reader of cost |
| how long traces and logs are kept | machinery | a time | the telemetry collector |
