[Middleware docs]: set data points so the condition must hold for N samples inside the evaluation window before the alert fires: with a 1-hour window and 1-minute roll-up, N=4 means roughly four minutes of badness. Higher N cuts flapping and false positives; lower N reacts faster but pages more. Use failure-count before alert so brief blips do not page your team. Give every rule a clear unique name, tags for routing, and a custom message with what happened, where, current value vs threshold, and the next action.

Context: A single data point makes noisy alerts. Require several before firing.