Skip to content

Correct the Enterprise page claims against ThinkWatch v2.1.0 - #33

Merged
fylorn merged 1 commit into
mainfrom
copy/enterprise-facts
Sep 30, 2026
Merged

fylorn merged 1 commit into
mainfrom
copy/enterprise-facts

Conversation

@fylorn

@fylorn fylorn commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Every factual claim on the Enterprise page (/thinkwatch, /zh-CN/thinkwatch) was checked against the ThinkWatch source at v2.1.0. Claims that did not hold were rewritten into true ones or removed. English and Chinese say the same thing. Only strings in src/i18n/index.ts change; no components are touched.

Removed items (layout may need to adapt)

  • Teams tab goes from 5 cards to 4: "Scoped API keys" and "Per-team spending limits" are removed (API keys have no team; limits and budgets attach only to users, API keys and roles). "Team workspaces" and "Per-team cost attribution" are replaced by "Teams and members" and "Analytics by team", and a new "Roles inherited from a team" card is added.
  • All other tabs keep 7 items; the MCP table keeps 8 rows and 4 cards.

Main corrections

  • Pipeline: keys identify a user (no user/team/project scoping); authorization comes from roles (including team-inherited) narrowed by the key allowlist; the budget check is described accurately; SSE jargon removed.
  • Rate limits and budgets: users, keys or roles; windows from 1 minute to 1 week; budgets count weighted tokens after the response; limits are skipped when Redis is down unless configured to refuse (the "fail closed" claim was wrong).
  • Routing: latency, success rate, or both, plus manual weights; no decision log exists.
  • Gemini is a fourth API surface; the model allowlist is the intersection of key and roles.
  • Prometheus: opt-in, on the console port, bearer-gated; the listed metric names did not exist.
  • Readiness also checks ClickHouse and an active provider; the body permission is logs:read_bodies; PII redaction at write is optional (off by default).
  • The image is not 2 MB; key hashes are HMAC-SHA256.
  • The MCP Store ships 37 templates (seed and registry), and they are not bilingual.
  • The setup wizard sets the site name and issues the first API key; it does not add a provider.

🤖 Generated with Claude Code

Every factual claim on /thinkwatch and /zh-CN/thinkwatch was checked
against the ThinkWatch source at v2.1.0 and rewritten where it did not
hold:

- API keys belong to a user; there are no team- or project-scoped keys.
- Rate limits and budgets attach to users, API keys and roles, never to
  teams. Budgets count weighted tokens after the response, and limits
  are skipped when Redis is down unless configured to refuse.
- Teams tab: drop the team-scoped keys and per-team limits cards and the
  isolation wording; describe team-scoped roles, roles inherited from a
  team, and analytics filtered by team.
- Routing modes are latency, success rate, or both, plus manual weights;
  there is no decision log.
- Gemini is a fourth API surface; model allowlists intersect key and roles.
- Prometheus metrics are opt-in on the console port, with the real
  counters; readiness also checks ClickHouse and a provider.
- Body capture permission is logs:read_bodies; PII redaction at write is
  optional. The image is not 2 MB. Keys use HMAC-SHA256.
- The MCP Store ships 37 templates, not bilingual ones.
- The setup wizard sets the site name and issues the first key; it does
  not add a provider.
- Internal jargon (SSE zero-overhead, pre-call, account_label) is spelled
  out in plain language.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@fylorn
fylorn merged commit 6d2c7b8 into main Sep 30, 2026
1 check passed
@fylorn
fylorn deleted the copy/enterprise-facts branch September 30, 2026 11:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant