Scrums.comPayfast
An observability overlay for Payfast

See everything.
Move nothing.

Intelligence across your entire payment estate.
Keep the systems. Connect the signals.
Understand what needs attention.

payments / day*
1M
systems moved in phase 1
0
progressive instrumentation
12 mo

INTERACTIVE CONCEPT Illustrative estate, incidents and costs. No live Payfast connections. *Daily volume from the project brief.

01 / The architecture

A new layer of understanding.
Your estate stays where it is.

Get useful answers without making a two-year migration the prerequisite.

INTELLIGENCEThe layer we add
  • Payment Health
  • Alert Correlation
  • Incident Investigator
  • Proactive Analyst
  • Transaction Journey
  • Telemetry Governance
GOVERNED ACCESSSmall, useful signals
Read-only adaptersNormalise → deduplicate → aggregate → investigateQuery budgets enforced
EXISTING ESTATENothing moves
  • Grafana
  • Prometheus
  • Loki
  • Elastic
  • Splunk
  • Sentry
  • Paging
  • Dynatrace*
  • Dynamics 365*

Logs stay at source.

Keep compact events, error families and aggregates. Fetch bounded evidence only when needed.

Operations stay independent.

Payments and critical paging continue if the overlay or a model is unavailable.

Adapters keep options open.

*Dynatrace and Microsoft Dynamics are optional examples, not confirmed systems.

Coexistence

Three retained log stacks. No forced consolidation.

Each stack keeps collecting and alerting. The overlay receives copies of events and starts in shadow mode. Stack names are a reference arrangement until the inventory is confirmed.

LOG STACK 01

Grafana + Loki + Prometheus / Alertmanager

Retained
What stays native
Operational metrics, application logs, dashboards and pages.
What the overlay adds
Alert fan-out, metric summaries and selected log evidence.
Isolation rule
Separate read credentials, query quotas and health state.
LOG STACK 02

Elastic / Kibana

Retained
What stays native
Legacy application logs, indexes, dashboards and native alerts.
What the overlay adds
Source-side aggregates, normalised rule events and bounded search.
Isolation rule
Independent index access and timeout budgets.
LOG STACK 03

Splunk

Retained
What stays native
Indexed data, search ownership and current alerts.
What the overlay adds
Approved saved searches and alert integration.
Isolation rule
Sensitive security evidence stays restricted. Only allowed summaries cross.
One timeout is not counted three times.

A signal authority registry names the preferred source for each metric and payment stage. The other sources corroborate it or show a coverage difference.

  • SOURCE-EVENT DEDUPLICATIONFinds a retried or duplicated message from the same source. The key is source instance, event ID, revision and content hash.
  • CROSS-SOURCE CORRELATIONLinks different observations of one episode. It keeps their provenance and never sums their counts.
Product surfaces

Six capabilities.
One shared core.

The surfaces share identity, configuration, data contracts, access control, evidence and cost accounting. One incident looks the same in all of them.

Payment Health

Payment operations, SRE and management

Live health by payment stage, method, route and merchant cohort. It shows business impact and data freshness.

BOUNDARYIt is a monitoring view. It is not the accounting ledger.

Alert Correlation

On-call engineers

Existing alerts grouped into incidents, with owner routing and one symptom timeline. Duplicate pages go down.

BOUNDARYIt cannot silently suppress a critical source alert.

Incident Investigator

Responders and application teams

Ranked hypotheses with supporting evidence, contrary evidence, missing evidence and the next diagnostic step.

BOUNDARYIt cannot state a root cause without sufficient evidence.

Proactive Analyst

Reliability and engineering leads

Slow regressions, emerging failure cohorts, exhaustion forecasts and prioritised work items.

BOUNDARYEach finding needs measurable evidence and a useful lead time.

Transaction Journey

Support, payment operations and engineering

A timeline for each payment and each attempt. Visibility gaps stay visible.

BOUNDARYIt cannot invent spans. Missing telemetry is never read as success.

Telemetry Governance

Platform, SRE and finance

Cost per million payments, noisy sources, coverage gaps, and expiry and sampling controls.

BOUNDARYRequired audit and security data keeps its own retention policy.

02 / Intelligence, with a budget

Classify the pattern.
Investigate the exception.

Continuous rules and statistics first. Small decisions next. Deeper reasoning when the evidence warrants it.

upstream_timeout · route_a · gateway_adapter · 4,812 repeatsSanitised template

Jev (TypeSafe) via OpenRouter

Typed classification

Gateway route
error_family
partner_timeout
retry_safety
unknown
owner
payments_ops
review_required
true
Typed result readyCache & reuse

General-purpose LLM

Evidence synthesis

Qualified cases
INVESTIGATION SUMMARY

Partner latency rose before local queue depth. This supports upstream degradation. A legacy trace gap remains; verify partner status before taking action.

Summary readyExplain & investigate

Scripted animation, not a speed benchmark. General LLMs can also return structured output. Correct types do not guarantee a correct decision.

Jev (TypeSafe) classification is routed through OpenRouter by the model gateway. The same budget, redaction and approval rules apply to it as to every model call. It starts in shadow mode, and its labels are measured before they are applied. TypeSafe launch, 15 Sep 2026 ↗ (opens in a new tab)

REPEATED ERRORS100,000occurrences of one template
MODEL REQUESTS1then reuse the classification

Budget the whole operation:
queries + storage + compute + inference.

03 / Better visibility, release by release

Useful now.
More certain over time.

The overlay starts with existing evidence. OpenTelemetry closes the gaps through normal releases.

PAYMENT API / 30 DAYSBudget watch

Reliability you can act on.

76.0% budget remaining
99.90% objective7,200 / 30,000 errors used

Complete eligible-attempt counters establish the SLO. Sampled diagnostic traces explain individual failures.

  1. Now

    Observe the existing estate

    Existing metrics, alerts and bounded logs. No application migration.

  2. Months 1–3

    Instrument one critical journey

    Stable IDs, lifecycle events and context propagation.

  3. Months 4–12

    Expand with normal deployments

    More verified boundaries. Visible coverage gaps. Controlled trace volume.

Take a look above the estate.

A working walkthrough of payment operations intelligence.

Sign in to the workspace