Quorum and regions
The regions
Section titled “The regions”Six probe regions, one per inhabited continent: na-ewr, sa-gru, eu-fra, af-jnb, as-sgp, oce-syd. Free probes from 2 regions, Pulse from 3, Sentinel and up from all six. The network page covers the fleet architecture.
This page’s voting model applies to the eleven regional probe types. Agent and heartbeat monitors use neither probe regions nor regional quorum; their incoming signals follow their own incident rules.
Two thresholds before an alert
Section titled “Two thresholds before an alert”- Within a region, the algorithm folds fresh node results and requires 75% agreement when more than one probe node is active. The current six-region topology has one active node per region, so this layer is currently 1/1; it is not a second independent corroboration inside the region.
- Across regions, an incident opens when a quorum of regions confirms the failure: two regions by default. Recovery has its own quorum, and results older than the freshness window do not count. This is the active cross-region confirmation in the current topology.
The incident’s start time is the quorum confirmation, to the second, and the recovery boundary is the confirmed recovery. Those are the exact window boundaries your availability record uses. Nothing is rounded, nothing is backdated.
Below quorum: forming and watchlist
Section titled “Below quorum: forming and watchlist”- A forming incident (first region failing, quorum not yet reached) is visible in the product with the first failing region named, and sends exactly one quiet notification per episode.
- Sub-quorum divergences (one region drifting or one IP family failing) land on a watchlist. Node disagreement also appears there when a region has more than one active node. An entry must survive a full check interval before it is reported at all; you investigate on your schedule, not at 3 a.m.
Why an explicit, configurable rule
Section titled “Why an explicit, configurable rule”The default across-region quorum is two, and an alert profile can change that policy. The record therefore keeps the configured rule beside the resulting incident boundary. For the eleven regional types, the same explicit policy that reduces single-path alerts also defines the availability window later; it does not diagnose root cause by itself.