{
 "categories": {
  "observability-platform": "Unified logs/metrics/traces backend sold as one product",
  "apm": "Application performance monitoring (traces, service maps, code-level)",
  "log-management": "Log ingest, index, search, retention",
  "metrics-backend": "Time-series storage and query (Prometheus-compatible or otherwise)",
  "tracing-backend": "Distributed trace storage and query",
  "telemetry-pipeline": "Collect, transform, reduce, route telemetry between sources and destinations",
  "siem": "Security information and event management",
  "llm-observability": "Tracing/evaluation of LLM and agent workloads (tokens, cost, quality)",
  "visualization": "Dashboards and exploration over other stores",
  "rum-synthetics": "Real-user monitoring and synthetic checks",
  "profiling": "Continuous profiling",
  "incident-management": "On-call, paging, incident workflow",
  "data-lake": "Low-cost open-format telemetry retention with query/rehydration",
  "instrumentation": "Agents, SDKs, eBPF, auto-instrumentation"
 },
 "capabilities": {
  "otlp_ingest": "Accepts OTLP (gRPC or HTTP) natively, without a proprietary agent in the path",
  "otel_collector_distro": "Ships or supports its own OpenTelemetry Collector distribution",
  "otel_semconv_native": "UI and features key off OTel semantic conventions rather than vendor fields",
  "prometheus_remote_write": "Accepts Prometheus remote_write",
  "promql": "Query with PromQL (or a compatible dialect)",
  "proprietary_agent_required": "Full functionality needs the vendor's own agent (yes = lock-in signal)",
  "ebpf_autoinstrumentation": "Zero-code instrumentation via eBPF",
  "pipeline_processing": "Parse, enrich, transform in flight before storage",
  "sampling_tail": "Tail-based trace sampling",
  "data_reduction": "Drop, aggregate, dedupe, or convert logs-to-metrics before billing",
  "pii_redaction": "Mask/redact sensitive data in the pipeline",
  "multi_destination_routing": "Route one stream to several third-party destinations",
  "persistent_queue": "Disk-backed buffering and retry under backpressure",
  "tiered_storage": "Hot/warm/cold or archive tiers priced differently",
  "open_format_archive": "Archive in an open format (Parquet, JSON, OTLP) in customer object storage",
  "rehydration": "Re-ingest archived data for search on demand",
  "federated_search": "Query data in place (object storage, other tools) without ingesting",
  "sql_query": "SQL as a query language",
  "high_cardinality": "Designed for high-cardinality attributes without pre-aggregation penalties",
  "logs": "Log management",
  "metrics": "Metrics",
  "traces": "Distributed tracing",
  "continuous_profiling": "Continuous profiling",
  "rum": "Real-user monitoring (browser/mobile)",
  "synthetics": "Synthetic monitoring",
  "llm_observability": "LLM/agent tracing, token and cost tracking, evaluations",
  "security_siem": "SIEM or security analytics",
  "alerting": "Alert rules with routing/notification",
  "slo_management": "First-class SLO/error-budget objects",
  "anomaly_detection": "Statistical/ML anomaly detection on telemetry",
  "ai_root_cause": "AI-assisted root-cause analysis or investigation agent",
  "ai_assistant_nl_query": "Natural-language query or chat assistant",
  "mcp_server": "Exposes an MCP server for agents",
  "service_map": "Auto-discovered service/topology map",
  "incident_response": "Native on-call/incident workflow",
  "rbac": "Role-based access control",
  "sso_saml": "SSO via SAML/OIDC",
  "audit_logs": "Audit log of user/admin actions",
  "usage_cost_controls": "Quotas, budgets, usage attribution to teams",
  "observability_as_code": "Terraform provider / dashboards-and-alerts as code",
  "self_hosted": "Customer can run it on its own infrastructure",
  "byoc": "Vendor-managed in the customer's cloud account",
  "saas": "Vendor-hosted SaaS",
  "fedramp": "FedRAMP authorized (state level in note)",
  "hipaa": "HIPAA-eligible (BAA available)"
 },
 "levels": {
  "yes": "Generally available and documented",
  "partial": "Exists with material limits (tier-gated, beta, one signal only) - say which in the note",
  "no": "Not offered",
  "addon": "Available only as a separately priced product or SKU",
  "unknown": "Not yet researched or not determinable from public sources"
 },
 "pricing_units": {
  "gb-ingested": "Per GB ingested (before or regardless of indexing)",
  "gb-indexed": "Per GB indexed/analyzed (may differ from ingested)",
  "gb-retained-month": "Per GB stored per month",
  "gb-scanned": "Per GB scanned by queries",
  "gb-processed": "Per GB passing through a pipeline",
  "host-month": "Per host (or node/VM) per month",
  "container-month": "Per container per month",
  "apm-host-month": "Per APM-instrumented host per month",
  "million-spans": "Per million spans ingested or indexed",
  "million-events": "Per million log events/records",
  "million-metric-samples": "Per million metric samples/datapoints",
  "custom-metric-series-month": "Per active custom metric time series per month",
  "user-month": "Per user/seat per month",
  "test-run-thousand": "Per thousand synthetic test runs",
  "session-thousand": "Per thousand RUM sessions",
  "llm-request-thousand": "Per thousand LLM requests/spans",
  "trace-thousand": "Per thousand traces (one end-to-end request or agent run, all its spans)",
  "token-million": "Per million LLM tokens observed, evaluated or generated",
  "credit": "Vendor-defined credit or compute unit (define in note)",
  "flat-month": "Flat platform/tier fee per month",
  "core-month": "Per CPU core/vCPU per month",
  "custom": "Anything else - explain in the note"
 },
 "source_kinds": {
  "vendor-pricing": "The vendor's own public pricing page or price list",
  "vendor-docs": "The vendor's own documentation",
  "vendor-marketing": "The vendor's own marketing (claims about itself)",
  "third-party": "Independent review, benchmark, press, user report"
 },
 "confidence": {
  "high": "read off a published rate card; only the workload is assumed",
  "medium": "rate card plus one or two stated conversions or allowances",
  "low": "rests on our own sizing or conversion assumptions (compute sizing, bytes per sample)"
 },
 "workload_variables": {
  "hosts": "Hosts or nodes monitored for infrastructure metrics",
  "host_memory_gib": "Memory per host, GiB (Dynatrace-style memory pricing)",
  "containers": "Average running containers",
  "apm_hosts": "Hosts running instrumented (APM / traced) services",
  "log_gb": "Log volume ingested per month, GB uncompressed",
  "log_event_bytes": "Average log event size, bytes",
  "spans_million": "Spans ingested per month, millions",
  "span_bytes": "Average span size, bytes",
  "metric_series": "Active metric time series",
  "scrape_interval_s": "Metric collection interval, seconds",
  "users": "People who use the UI (dashboards, queries)",
  "log_gib": "log_gb in GiB",
  "log_events_million": "Log events per month, millions (log_gb / log_event_bytes)",
  "span_gb": "Span volume per month, GB (spans x span_bytes)",
  "span_gib": "span_gb in GiB",
  "metric_samples_million": "Metric samples per month, millions (series x samples per series)",
  "metric_dpm": "Metric data points per minute (series x 60 / interval)",
  "hours": "Hours in a billing month (730)",
  "spans_million_dropped": "Spans dropped by vendor-side sampling, millions (0 unless the vendor samples)",
  "span_gb_dropped": "Span GB dropped by vendor-side sampling (0 unless the vendor samples)"
 },
 "licence_models": [
  "proprietary",
  "open-core",
  "open-source",
  "source-available",
  "mixed"
 ],
 "ownership_status": [
  "public",
  "private",
  "acquired"
 ]
}
