Terms of Use
By accessing or using DevAtlas, you agree to these Terms of Use. DevAtlas is provided for internal knowledge-discovery purposes only. Please read these terms carefully before using the platform.
1. Internal Use Only
DevAtlas is an internal enterprise tool made available exclusively to authorised employees and contractors of the organisation. Access is granted solely for legitimate business purposes related to knowledge discovery, documentation, and organisational learning.
You must not:
- Share access credentials, session tokens, or API keys with any external or unauthorised party
- Access DevAtlas from unauthorised devices not managed by the organisation
- Use DevAtlas for purposes unrelated to your professional responsibilities
- Attempt to make DevAtlas available to the public or external parties
Violation of this restriction may result in access revocation and disciplinary action in accordance with organisational policies.
2. Acceptable Use
DevAtlas may be used for the following approved purposes:
- Searching for engineering documentation, runbooks, ADRs, and technical guides
- Discovering team ownership, onboarding resources, and organisational best practices
- Asking questions about system architecture, incident history, and engineering processes
- Submitting and curating knowledge entries for the shared knowledge base
- Navigating linked sources in Azure DevOps, SharePoint, Confluence, or connected systems
The following uses are prohibited:
- Using DevAtlas to process, infer, or store personal data of individuals
- Querying or submitting content that contains confidential customer data, financial data, or regulated information unless explicitly approved
- Attempting to extract, scrape, or bulk-export the knowledge index
- Submitting false, misleading, or malicious knowledge entries
- Using DevAtlas to circumvent or undermine information security controls
- Automated or scripted bulk querying without prior approval from the platform owner
3. User Responsibilities
As a DevAtlas user, you are responsible for:
- Account security: protecting your authentication credentials and reporting any suspected compromise to the security team immediately.
- Accurate submissions: ensuring that any knowledge entries you submit are accurate, current, and appropriate for internal sharing.
- Appropriate queries: framing queries in a professional manner consistent with your organisation's code of conduct.
- Information handling: treating knowledge retrieved from DevAtlas with the same confidentiality classification as the original source material.
- Incident reporting: reporting incorrect, outdated, or potentially harmful information in the knowledge base to the DevAtlas platform owner.
4. Limitations of AI-Generated Responses
DevAtlas uses Retrieval-Augmented Generation (RAG) powered by Azure OpenAI to synthesise answers from indexed knowledge sources. You must understand and accept the following limitations:
- AI responses may be incomplete or inaccurate. The system retrieves relevant passages and generates a synthesised answer, but it does not guarantee correctness, completeness, or currency of the information provided.
- Responses reflect the indexed knowledge base, not real-time state. Source documents may have been updated since indexing. Always verify against the original authoritative source.
- AI can hallucinate. Language models may generate plausible-sounding but incorrect statements, particularly when source coverage is limited.
- Citations indicate retrieval, not endorsement. Cited sources are retrieved by relevance scoring and do not imply that the cited document fully supports the generated answer.
5. Verification Requirement
DevAtlas is a discovery and navigation tool — it helps you find the right information faster, but it does not replace the authoritative source of truth.
You must verify DevAtlas responses before:
- Making technical decisions that affect production systems or customer-facing services
- Executing operational procedures (deployments, runbooks, incident response steps)
- Making security-relevant decisions (credential rotation, access changes, firewall rules)
- Making business or financial decisions
- Representing organisational policy to colleagues, partners, or auditors
- Preparing compliance documentation or audit evidence
Before acting on any information provided by DevAtlas, you are required to verify that information against the original authoritative source.
The organisation, DevAtlas platform team, and AI service providers accept no liability for decisions made solely on the basis of unverified DevAtlas output.
6. Intellectual Property
All content indexed and made available through DevAtlas — including documentation, runbooks, architecture records, and knowledge entries — is the intellectual property of the organisation or its licensors.
- Content retrieved through DevAtlas may not be reproduced, distributed, or published outside the organisation without explicit written approval.
- Knowledge entries submitted by users become part of the organisation's internal knowledge base and are subject to the same ownership and classification rules as other internal documentation.
- The DevAtlas platform itself, including its source code, AI models, and search indexes, is the property of the organisation.
7. Compliance Requirements
Use of DevAtlas must comply with all applicable organisational policies, including:
- Acceptable Use Policy (AUP) — governing use of organisational IT systems
- Information Security Policy — governing data classification and handling
- Data Protection Policy — governing personal data and GDPR / applicable privacy regulation requirements
- Code of Conduct — governing professional behaviour and communications
- Change Management Policy — governing how information from DevAtlas may be used to inform or support change requests
Where these terms conflict with a more specific organisational policy, the more specific policy takes precedence. Users are responsible for knowing which policies apply to their role and function.
8. Security Requirements
To maintain the security of DevAtlas and the knowledge it contains:
- Use only organisation-managed devices and networks (or approved VPN) to access DevAtlas.
- Do not cache, screenshot, or export knowledge index content to unmanaged or personal storage.
- Report security vulnerabilities discovered in DevAtlas immediately to the security team via the standard vulnerability disclosure process — do not exploit them.
- Do not attempt to bypass authentication, authorisation, rate limiting, or any other security control.
- Log out or lock your session when leaving an unattended workstation.
Any suspected security incidents involving DevAtlas should be reported through the standard security incident response channel.
9. Limitation of Liability
DevAtlas is provided "as is" for knowledge-discovery purposes only. To the fullest extent permitted by applicable law and organisational policy:
- The organisation makes no warranty that DevAtlas will be continuously available, error-free, or that the information it provides is accurate, complete, or current.
- The organisation, the DevAtlas platform team, and Azure AI service providers accept no liability for any loss, damage, or adverse outcome resulting from reliance on DevAtlas output without independent verification.
- DevAtlas is a supplementary tool and does not replace subject-matter expert review, peer review, or formal approval processes required by your organisation's change management and governance frameworks.
These terms may be updated by the DevAtlas platform owner. Users will be notified of material changes through standard internal communication channels. Continued use of DevAtlas constitutes acceptance of the current terms. Effective date: 16 July 2026.