User Agreement
This agreement covers people who use CrowdSense day to day: operators in the Control Room, crew on the Companion App and Travla, and anyone with a login under a customer's account.
Last updated: August 2026
Who This Applies To
This agreement applies to you if you have been given a named user account on the CrowdSense platform — the dashboard, the Control Room, the Companion App, Travla, or any API or agent access — under an organisation's account. That organisation is our customer. You are a user under their account, not a separate contracting party.
Where anything here conflicts with the commercial agreement between CrowdSense and that customer, the commercial agreement prevails. This agreement sits alongside our Terms of Use and Privacy Policy, which also apply.
Your Account
Your credentials are personal to you. Do not share your login, password or multi-factor device with anyone, including colleagues on the same site. Shared logins break the audit trail that makes the platform useful during an incident.
- You are responsible for activity carried out under your account.
- Use a strong, unique password and keep multi-factor authentication enabled where offered.
- If you believe your credentials or device have been compromised, tell your account administrator and us immediately so access can be revoked.
- When you change role or leave the organisation, your access should be removed. Do not keep using an account you are no longer entitled to.
Roles and Permissions
Access is scoped by role and by workspace. What you can see, change, publish or export is set by your account administrator, and different sites, events or verticals may be separated into different workspaces.
Do not attempt to exceed your role — that includes probing for data outside your workspace, borrowing another person's session, using a token issued for a different purpose, or asking a colleague to perform an action you are not permitted to perform yourself. If you need broader access to do your job, ask your administrator for it.
Acceptable Use
The platform measures crowds and helps people operate sites safely. Use it for that. You must not:
- Attempt to re-identify individuals from anonymised data — including correlating anonymous signal readings, keyframes, timestamps or external records to work out who a particular person is.
- Attempt to defeat, disable or work around the anonymisation applied to imagery, or apply facial recognition, number-plate recognition or any other biometric technique to data taken from the platform.
- Export, copy or share data outside your organisation without authority to do so. That includes screenshots, exported reports and API extracts shared with media, contractors or third parties.
- Use the platform to monitor an individual worker punitively rather than to operate a site safely. Crew features exist for coordination, welfare and safety — not for surveillance of a named person.
- Interfere with nodes, signage players, mesh communications or other equipment, or use the platform to break the law, breach someone's privacy, or harass anyone.
Crew Location and Team Features
The Companion App and Travla use named accounts so crew can check in, receive tasking and be accounted for. Where your employer enables live position, the platform shows where crew are on site during a shift.
- It is there to coordinate work, reach the nearest person in an incident, and confirm everyone is accounted for during an evacuation or muster.
- Its scope is the shift. It is not a general tracking tool and it is not for use outside working hours.
- If you can see crew position, treat it as workforce information: view it for an operational reason, and do not share it beyond the people who need it.
- Questions about whether this feature is enabled, and what your employer does with it, are for your employer — they decide, and they are responsible for telling you.
Screen Takeover and Alerts
Site-wide takeover and mass alerting are powerful. A takeover replaces what is on every screen in scope; an alert reaches everyone configured to receive it. Used well, that is how a site gets a message out in seconds. Used carelessly, it erodes the trust that makes the next message work.
- Trigger takeover and mass alerts only for genuine operational or safety purposes.
- Follow your organisation's escalation procedure and authorisation levels.
- Clear a takeover once the reason for it has passed.
- Every takeover, alert and acknowledgement is logged against your account with a timestamp.
Connected Agents and API Credentials
The Brain can be reached through an MCP server, a REST API and webhooks. If you connect an AI agent or issue a token, you are responsible for what it does under your organisation's account — an automated action is treated as your action.
- Use read-only scope unless write access is genuinely needed for the task.
- Scope tokens to the narrowest workspace and dataset that will do the job.
- Never embed a token in shared code, a document, a chat message or a public repository.
- Revoke tokens you no longer use, and revoke immediately if one may have been exposed.
- Calls are logged and auditable, and any token can be revoked by the account owner.
The Decision Log
The Control Room keeps an automatic, timestamped decision log. Your acknowledgements, overrides, takeovers, threshold changes and dismissals are recorded with the time and your identity.
That log is not a performance measure of you — it is the operational record of what the site knew and what was done about it. It forms part of the customer's record and may be relied on in post-event review, incident investigation, insurance or regulatory reporting. It cannot be edited or deleted by users.
Confidentiality
Through the platform you will see information that is not public: site layouts, crowd figures, crew details, incident records, thresholds and commercial data. Treat it as confidential.
Do not disclose it outside the people who need it to do their job, and do not post platform screenshots, figures or footage-derived imagery on social media or to the press without your organisation's authority. These obligations continue after your access ends.
Not a Life-Safety System
CrowdSense is not a life-safety system. The platform informs decisions; it does not replace emergency procedures, crowd management plans or trained personnel. Sensors, cameras, networks and screens can fail or be obstructed, and readings can be delayed or wrong. Never rely on the platform alone where safety depends on it — use your eyes, your radio, your plan and your chain of command.
Suspension
We or the account owner may suspend or remove your access where this agreement is breached, where access is no longer required, or where suspension is needed to protect the platform, the data in it, or people on a site. Where practical we will tell the account owner first. Serious breaches — including attempted re-identification or unauthorised data export — may also be reported to your organisation and, where the law requires, to a regulator.
Changes
We update this agreement as the platform changes. The current version always lives on this page with the date it was last updated. Where a change materially affects users, we will tell account owners so they can pass it on. Continuing to use the platform after a change means you accept the updated agreement.
Contact
Questions about this agreement, or about something you have been asked to do on the platform, can go to hello@crowdsense.events. For access, role and permission changes, start with your own account administrator — they can act faster than we can.