Skip to content
ATLAS
Security

Engineering information deserves controlled handling.

Drilling engineering data is commercially and operationally sensitive. ATLAS is designed for organisational use, which means access, control and auditability are part of the platform's structure rather than administrative settings added later.

  1. 01

    Engineering output

    Calculated, documented result

  2. 02

    Review

    Examined by a competent engineer

  3. 03

    Approval

    Accepted under company process

  4. 04

    Auditable record

    Retained, versioned, retrievable

Security model

Six control areas.

These describe the platform's architecture and design principles for organisational deployment. Specific configuration, provisioning and hosting requirements are established during technical engagement.

01

Organisational workspaces

Controlled organisational workspaces are a core design principle: engineering work is scoped by organisation, asset and project so information stays in the context it belongs to.

02

Role-based access

The access model is designed so permissions follow engineering responsibility — what a person can see and change reflects the role they hold. Role definitions are configured per deployment.

03

Controlled repositories

The platform is architected so engineering references are managed centrally rather than circulated as attachments and personal copies.

04

Governed approvals

Review and approval are designed to follow the organisation's own process, with the outcome recorded against the work. Approval authority remains with the organisation.

05

Auditability of activity

Auditability of activity on engineering information is a design requirement of the platform, so activity can be reviewed later rather than inferred.

06

Controlled application access

The ATLAS application is provisioned per organisation rather than offered as an open self-service product.

Engineering practice

Control that reflects how engineering is governed.

Security in an engineering platform is not only about keeping people out. It is about making sure the right people can rely on what they are looking at.

Least privilege by design
Access is intended to be granted for a purpose, not as a convenience.
Separation of duties
Producing engineering work and approving it are treated as distinct actions.
Traceable change
Changes to governed information are designed to be attributable and versioned.
Hosting and residency
Hosting, residency and provisioning requirements are established per engagement.
  1. 01

    Source

    Where the value originates

  2. 02

    Evidence

    What supports it

  3. 03

    Version

    Which revision applies

  4. 04

    Decision

    What the engineer concluded

Lineage is retained so a reviewer can reconstruct how an engineering conclusion was reached.

Traceability and access control work together: a record is only defensible if it is both retained and attributable.