Error monitoring review

Sentry Reviewer Workflow

This reviewer board ties Sentry activation proof together before provider capture can be enabled. It shows provider-boundary gates, scrub rules, sample-capture owner review, activation rehearsal, rollback paths, and production proof links without exposing DSN values, provider identifiers, event URLs, stack traces, cookies, private EVE data, or protected setup packet bodies.

Review Chain7

3 lanes are ready and 4 block capture.

Provider Gates2/10

WarpIntel-only provider setup stays protected until final owner review.

Scrub Rules7

Headers, cookies, request data, token fields, identifiers, context, and breadcrumbs are scrubbed.

Sample Criteria5

A future sample event must be non-sensitive, protected, reviewed, and removed after use.

Protected Checks3

Setup packet, dry run, and activation rehearsal remain admin-only.

Activation Rehearsal8

Protected rehearsal proves no provider mutation, no Sentry call, and no event capture.

Rollback Paths3

Provider mismatch, scrub failure, and unexpected capture activity have stop paths.

No-Secret TextReady

Public text excludes DSNs, provider identifiers, stack traces, tokens, and private data.

OffCapture
BlockedSafe to enable
OffProvider calls
OffEvent capture
16/16Proof targets
blocked-visible

WarpIntel Provider Boundary

2/10 Sentry gates are ready without exposing DSNs or provider identifiers.

Use a WarpIntel-only Sentry project and keep all provider values in protected configuration.

ready

Scrub Rules And Event Preview

7 scrub rules cover headers, cookies, request payloads, tokens, user identifiers, nested context, and breadcrumbs.

Keep local scrub preview proof protected before any provider capture is approved.

protected-review

Sample Capture Owner Handoff

6/6 owner review steps are mapped for a future non-sensitive sample event.

Record only public-safe sample-capture outcomes; keep provider event URLs and stack traces protected.

protected-review

Protected Activation Rehearsal

8 rehearsal gates and 8 proof targets stay protected and no-capture.

Run protected rehearsal before enabling capture; do not expose rehearsal bodies publicly.

gated-visible

Capture Gate

Capture is off and safe-to-enable is blocked.

Enable capture only after WarpIntel-only DSNs, owner approval, scrub proof, and sample review are complete.

ready

Rollback Paths

3 rollback paths cover provider mismatch, scrub-preview failure, and unexpected capture activity.

Keep rollback decisions visible before any live provider event is accepted.

ready

Production Proof Links

Health, status, monitoring, security, integrations, releases, and smoke targets remain linked for production review.

After any Sentry activation, rerun live smoke and record release/tracker evidence.

ready

Sentry Reviewer page

Public page renders the Sentry review workflow without protected setup bodies.

ready

Sentry Reviewer JSON

Machine-readable reviewer feed exposes aggregate Sentry review counts only.

ready

Sentry Readiness page

Readiness page shows public Sentry gates and no-secret boundaries.

ready

Sentry Readiness JSON

Readiness feed excludes DSNs, provider identifiers, event URLs, and stack traces.

ready

Protected Sentry setup packet

Protected setup route exists but stays admin-only.

ready

Protected Sentry dry run

Protected dry run validates no-provider-call boundaries.

ready

Protected activation rehearsal

Protected rehearsal keeps provider mutation and event capture off.

ready

Health JSON

Public health includes Sentry readiness and smoke counters.

ready

Status

Public status is the production operator surface.

ready

Monitoring

Monitoring readiness links Sentry capture-off proof.

ready

Integrations

Provider setup remains grouped without exposing account details.

ready

Security

Security policy is linked for capture and disclosure review.

ready

Ops Readiness

Ops readiness proves protected export boundaries.

ready

Next Actions

Next actions keeps buildable and blocked Sentry work separated.

ready

Release Readiness

Release readiness tracks deployment proof.

ready

Releases

Release notes record each production change.

public-no-secret

Visibility

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

public-readiness-and-protected-route-labels-only

Source Data

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Dsn Values

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Provider Org Identifiers

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Provider Project Identifiers

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Event Urls

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Stack Traces

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Cookies

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Authorization Headers

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Eve Tokens

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Private Account Data

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Raw Pasted Inputs

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

linked-not-expanded

Protected Setup Bodies

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Provider Calls

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Provider Mutations

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Event Capture

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

disabled

Database Writes

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

excluded

Separate Project Accounts

Kept out of public pages, health snapshots, smoke logs, screenshots, and readiness feeds.

No-Secret Sentry Reviewer Rule

Public Sentry reviewer exposes aggregate provider-boundary counts, scrub-rule counts, sample-capture criteria counts, owner-handoff counts, activation-rehearsal counts, rollback counts, protected packet labels, production proof links, and no-secret safety booleans only; it does not expose DSN values, provider org identifiers, provider project identifiers, event URLs, stack traces, cookies, authorization headers, EVE tokens, private account data, raw pasted inputs, separate-project account details, or protected setup packet bodies, and it does not call Sentry, capture events, mutate provider state, upload sourcemaps, write database rows, or start EVE OAuth.