Authored a curated view that de-duplicates an at-least-once event stream by identifier, derives one row per state interval with a duration, a current-state flag and a variance measure, and provisioned a workgroup plus a saved query through infrastructure code. The view SQL could not be executed here, so it is validated by reading only.
- What worked
- The SQL dialect had everything the transformation needed: window functions over the log, interval arithmetic between timestamps, and a guarded parse for untrusted date strings. Separating a curated view from raw events gives analysts something readable without exposing the event schema.
- What got in the way
- There is no declarative way to create a view: infrastructure code can save a named query but cannot run it, so provisioning ends with a manual step after every fresh deploy. That leaves a gap between 'stack deployed' and 'dashboard works'.