PlatformAudit trail and e-signatures
21 CFR Part 11 audit trail software, verified every day
Every record, provably intact. QMSdesk™ is 21 CFR Part 11 audit trail software that chains every entry, keeps the log insert-only in the database, and checks the chain every day. When someone asks how your records are protected, you show them.
9f3a…c21e4b7d…08fae21c…9b4071aa…d3e5What changes for you
01
Answers, not assurances
An auditor asks what stops an entry being edited. You open the hash chain, the database rule that refuses changes, and this morning's verification result.
02
Signatures that say what they mean
Every signature records who signed, when, and what the signature means. Nobody has to work it out later from context.
03
A review you can prove happened
Your periodic audit-trail review happens in QMSdesk, on the entries that matter, and it ends with a signature.
How the 21 CFR Part 11 audit trail stays tamper-evident
Step 1 of 4
Every entry is chained
Every audit-trail entry is SHA-256 hash-chained to the entry before it, from a fixed starting point for your tenant. A modified or deleted record breaks the chain, and the break is detectable.
Step 2 of 4
The database keeps the log insert-only
Audit-log immutability is enforced at the database layer, not only in application code. Updates and deletes are rejected for every connection, including direct database access.
Step 3 of 4
The chain is re-walked daily
A scheduled job classifies every entry. Harmless timing artifacts are reported separately, only a genuine break counts as a failure, and your administrators are alerted when one appears. They can also run the check on demand.
Step 4 of 4
Every signature is traced to its record, daily
A second job confirms each signature still resolves to the record it signed. Anything it can't confirm is reported as unverified, never counted as intact.
Detection is the point: if something ever did change, you'd know where, and when it was found.
Part 11 electronic signatures, built into every workflow
A controlled vocabulary of signature meanings
What a signature means is recorded, not inferred, including administrative actions such as role grants and deactivations. The system sets the meaning for each step, and a content hash of what was signed is kept with it.
You are signing
CC-003
Revise storage temperature monitoring, SOP-022
- Meaning
- Approved set by this step
- Signer
- Quality Manager
- Content hash
5c1e…a07b
••••••••••
The signature commits together with the change it approves.
One signature mechanism
Every signature re-authenticates the signer, with multi-factor authentication at signing when your tenant requires it. Signature authority is validated before a signature is accepted, and the signature and the record change it authorizes are committed in one database transaction.
Signed periodic audit-trail review
A risk-focused view filters the trail to signatures, role changes, deletions and configuration changes. Your reviewer records what they found and signs the review as "Reviewed by". Your own SOP sets how often.
ALCOA+ attributes, captured
Audit-trail entries capture ALCOA+ attributes: who acted, what they did, on which record, the old and new values, the reason and the time.
Access that can never sign
The Administrator holds no record-approval authority. Break-glass access and vendor support access are time-boxed and logged, and neither can ever produce a signature.
Feature index
Everything in audit trail and e-signatures
Audit-trail integrity
- SHA-256 hash chain per tenant, anchored at a genesis entry
- Insert-only audit log, enforced by a database trigger
- Daily chain verification that classifies every entry; only a genuine break fails
- On-demand chain verification, with alerts to administrators
- Daily signature-linkage verification, with "unverified" reported separately
- Signed periodic audit-trail review over a risk-focused view
- Records raised in error are cancelled with a signed reason, never deleted
- Records reaching the end of retention are archived, never hard-deleted
- Controlled-copy and closure-record downloads logged, and blocked if logging fails
Electronic signatures
- One signature mechanism for the whole platform
- Re-authentication on every signature, with multi-factor authentication where required
- A controlled vocabulary of signature meanings, set by the system for each step
- Content hash captured with the signature
- Signature and record change committed in one transaction
- Signature authority validated before a signature is accepted
- No signature prompts where nothing is being attested
- Segregation of duties checked when the signature is applied
- Signature log on controlled copies; full signature manifest on event closure records
Identity and access
- One person per account, and user IDs are never reissued
- Password history, and account lockout that doesn't reveal which accounts exist
- Multi-factor authentication for the whole tenant or by role
- Inactivity timeout and a maximum session length
- Single-use password reset links
- Tenant isolation enforced by row-level security in the database
- Inspection View: time-boxed, read-only accounts for inspectors, with every access logged
One connected system
Connected across QMSdesk
Document control: signatures at authoring, review and approval, and a signature log on the controlled copy.
Audit management: give an inspector a read-only Inspection View account for the day.
Implementation and go-live: go-live itself takes two separately signed attestations.
Regulatory profiles: 21 CFR Part 11 and ALCOA+ sit in the base profile every tenant holds.
Regulations
Regulations it's designed to support
QMSdesk's audit-trail and signature controls are designed to support:
Your procedures, intended-use validation and the §11.100(c) certification to FDA stay with you. QMSdesk's core platform is validated, and we'll walk you through the full record under a mutual NDA.
- 21 CFR Part 11: protection of records for accurate retrieval (§11.10(c)), limited system access (§11.10(d)), secure, time-stamped audit trails (§11.10(e)), signature manifestations (§11.50), signature-to-record linking (§11.70) and signatures unique to one person (§11.100(a)).
- EU GMP Annex 11: an audit trail of GMP-relevant changes, its periodic risk-based review, and controlled access.
- ALCOA+ data-integrity principles.
Questions buyers ask
Will QMSdesk support our 21 CFR Part 11 obligations?
QMSdesk provides the technical controls: a tamper-evident audit trail, signatures with re-authentication and recorded meaning, signature-to-record linking and access controls. Procedures, training, intended-use validation and the §11.100(c) certification stay with you. We'll show you each control on a screen share.
Can a database administrator change the audit trail?
The database rejects updates and deletes on the audit log from every connection, including direct access that bypasses the application. The hash chain is a second, independent layer: if an entry were ever altered or removed, the daily verification would find the break and show where it is.
What does an electronic signature record?
Who signed, the date and time, the meaning of the signature, the reason where one is required, and a hash of the content signed. The signer re-authenticates every time.
How does the periodic audit-trail review work?
A reviewer opens a filtered view of the risk-relevant entries for a chosen period: signatures, role changes, deletions and configuration changes. They record their findings and sign the review. You decide the cadence in your own SOP.