Skip to content

Technical insights

Making an instrument audit-ready

Most instruments in a regulated facility measure well and record badly. These are working notes on the second problem — attribution, audit trails, electronic signatures, integration and validation — and on why the answer is an architecture rather than a product.

Written by the engineers who had to make it pass an inspection.

Architecture Data integrity

One compliance architecture, any instrument

Most instruments in a regulated facility face the same problem: the measurement is fine, the record around it is not. That problem is not specific to any one instrument, and neither is the solution.

4 min read
Architecture Data integrity

One design, three compliance tiers: matching record-keeping to obligation

Full 21 CFR Part 11 capability on an instrument that does not need it is money spent on a finding you were never going to get. The tier should be chosen by obligation, not by budget.

3 min read
Data integrity Regulatory

What 21 CFR Part 11 and EU Annex 11 actually require

Both regulations are short, readable and widely misquoted. Most of what gets sold as compliance is a login screen and a log file, which is neither of the things the text asks for.

3 min read
Security & access Data integrity

Role-based access control for regulated instruments

Access control on a regulated instrument is not a security feature bolted on at the end. It is the mechanism that makes every record the instrument produces attributable to a person.

3 min read
Security & access Integration

Directory-based login: one identity across every instrument

Local user accounts on instruments look simple until you have twenty instruments and staff turnover. Directory integration is less a convenience than a data integrity control.

3 min read
Data integrity Security & access

Electronic signatures and security policy in practice

A signature that records only a name and a timestamp is a stored click. What makes it a signature is meaning, binding, and the inability to sign twice for yourself.

3 min read
Integration Data integrity

Connecting instruments to LIMS and MODA without transcription

Every manual step between an instrument and the system of record is a place where a number can change. Integration is less about convenience than about removing those places.

3 min read
Automation Data integrity

Removing the manual steps from a regulated workflow

Automation in a regulated environment is not about speed. Each manual step removed is a category of human error and a gap in the record that no longer exists.

3 min read
Automation Security & access

Remote operation without losing attribution

Operating an instrument from outside the room is straightforward. Doing it so that every remote action is still attributable to a named person is the part that needs designing.

3 min read
Industry outlook Architecture

Where instrument compliance is heading

The direction of travel is clear enough: fewer manual steps, records that leave the device immediately, and instruments that answer to enterprise systems rather than to a clipboard.

3 min read
Sampling methods Architecture

Detecting the failure the instrument cannot see

An instrument can execute a technically perfect cycle and produce a worthless result. Sensing that catches this at the moment it happens is a general principle, not an air sampling trick.

3 min read
Sampling methods

Passive vs active air sampling: choosing a method

Settle plates and volumetric sampling answer different questions. Most monitoring programmes need both, and the common mistake is treating one as a cheaper version of the other.

2 min read
Sampling methods Regulatory

Environmental monitoring in pharmaceutical manufacturing

Monitoring exists to demonstrate that an area was under control while product was being made. That framing decides how a programme should be designed and what its records have to support.

3 min read

Question these articles do not answer?

Send it over. If it is a good question we will probably write it up.

Ask an engineer