Compliance
21 CFR Part 11 and GxP — controlled states, electronic signatures, and the tamper-evident audit trail.
Compliance in traceunified is structural rather than bolted on: controlled states, electronic signatures, and a tamper-evident audit trail belong to the same data model as the work itself. What you choose is how much of it to enforce. Versioning and the audit trail run on every project; signatures, approval gates, and controlled states are configured per workflow, so a project with no standard to answer to simply leaves them off. Where you do enable them, the evidence an auditor asks for is a by-product of the work — captured as you go and aligned to the frameworks you develop under.
This section explains the compliance spine: how states are controlled, how signatures work, what the audit trail records, the frameworks supported, and how readiness is verified.
A spine, not a bolt-on — enforced only where you say
The defining choice in traceunified is where compliance lives: in the data model, not in a separate product you bolt on before an inspection. That has two consequences. First, enforcement is a setting rather than a migration — electronic signature is a checkbox on a workflow and it is off on a new one, so you switch it on for the workflows that need it and only those. Second, because the history is recorded either way, there is no separate “audit mode” to prepare and no reconciliation between how you work and how you prove you worked; they’re the same activity. A team with nothing to certify gets the traceability and gives up none of it. A team filing a submission enables the controls and finds the record already written.
How the pieces fit
Controlled states and workflows govern how a record is allowed to move — what can change, when, and who can change it — so a record under review can’t be quietly altered. Electronic signatures enforce accountability at each gate under the Part 11 model. The audit trail captures every change as a tamper-evident record. Together these three are the mechanism that makes a signature meaningful and a history trustworthy.
Framework alignment and proving readiness
Above that spine sits alignment to the frameworks you actually develop under — FDA, ISO, IEC, and EU expectations — so the controls map to specific obligations rather than a generic notion of “compliance.” Verification and quality analysis then let you prove readiness on demand: rather than preparing for an audit, you check the system’s current state and produce the signed evidence directly from the live records.
What’s in this section
- Controlled states & workflows — governing how records move
- Electronic signatures — the Part 11 signing model
- The audit trail — the tamper-evident record
- Frameworks — FDA, ISO, IEC, and EU alignment
- Verification & quality analysis — proving readiness
- Verify compliance & produce evidence — a step-by-step walkthrough from framework to signed evidence