Skip to main content
Connect the Azure DevOps organization, project, and repository to a Veridical workspace. The credential needs Code Read and Pull Request Threads Read & Write only when comment publication is enabled. Configure a service hook for pull-request created and updated events. Preserve the pull-request URL and immutable commit IDs: Veridical reviews the head/base pair recorded by the event, not a moving branch name. Use a dedicated service identity, rotate its credential through the selected secret backend, and restrict egress to the approved Azure DevOps organization.
Last modified on July 28, 2026