Circuit Breaker: The Reporting Pipeline Can Be Shut Off Anytime

Imagine one day HQ discovers a data reporting channel at one of its branches has a problem. There's no need to send someone to that branch — they just shut down that channel from HQ's backend, effective within minutes. The front-counter display reporting and the membership system backend reporting can be switched off independently without affecting each other.

Claude Code has this same "HQ remote shutoff" capability. src/services/analytics/sinkKillswitch.ts reads a remote config to determine whether each backend is enabled:

// src/services/analytics/sinkKillswitch.ts
const SINK_KILLSWITCH_CONFIG_NAME = 'tengu_frond_boric'  // Obfuscated config key name

export function isSinkKilled(sink: SinkName): boolean {
  const config = getDynamicConfig_CACHED_MAY_BE_STALE<
    Partial<Record<SinkName, boolean>>
  >(SINK_KILLSWITCH_CONFIG_NAME, {})
  return config?.[sink] === true
}

tengu_frond_boric is a deliberately obfuscated key name ("tengu" is Claude Code's internal codename). The full name looks like a meaningless word combination, preventing outsiders who discover the key name from trying to trigger it. The sink config structure is { datadog?: boolean, firstParty?: boolean } — the two backends can be shut down independently.

Fail-open: If this config doesn't exist or its format is wrong, the sink stays open — just like when HQ can't reach a branch, the branch defaults to staying open rather than shutting down. The worst case if a data pipeline has issues is that a bit too much data gets recorded; but if all events are silently discarded because of a config format error, the product team would be completely blind to user behavior — which is far more dangerous.