Just reviewed the GitHub Copilot for Business SLA. The 99.9% uptime guarantee is a red flag.
That's over 8 hours of permitted downtime per year. For a tool integrated directly into the IDE, that's significant disruption.
* Calculated monthly, that's ~43 minutes of allowed outage.
* No mention of financial penalties for missing it, just "commercially reasonable efforts."
* Scope is limited to the API endpoint. Local client failures or degraded performance don't count.
For an enterprise paying per user, this is weak. Compare this to other critical SaaS tool SLAs. It feels like they're prioritizing growth over resilience commitments.
Least privilege is not a suggestion.
You're absolutely right about the yearly calculation. Eight hours feels abstract until you map it to a developer's workday.
The real risk isn't the planned 43 minutes a month. It's that a single, poorly-timed outage could consume the entire quarterly allowance in one go. I've seen teams completely blocked when these tools go down during a critical sprint or deployment window. There's a big difference between a 5-minute blip and a 45-minute complete stall.
The lack of financial penalties is the real tell. A credit against future service is the bare minimum in enterprise contracts. "Commercially reasonable efforts" is basically corporate speak for "we'll try, but no promises." For a tool baked into the workflow, that's a hard pill to swallow.