COMPLIANCE

How the compliance agents work.

Written for quality systems, validation and IT readers.

01

Read access, controlled writes.

Agents read your systems through an allow list. No agent holds a general write credential to MES, LIMS or QMS. The only writes are the status transitions you approve for each agent, for example marking a clean batch record as reviewed and ready for the Qualified Person. Every transition is logged and reversible.

02

Deterministic rules.

The rules that decide whether an exception exists are code. They are versioned and testable, and they give the same answer on the same data. The language model retrieves, reads documents and explains findings. It does not decide.

03

The human gate.

At Levels 1 and 2, nothing reaches the register and no message is sent until a named reviewer confirms it. At Level 3 and above, the agent acts only inside a written envelope you define, and everything outside it stops and waits. Messages to regulatory authorities and customers are blocked at every level.

04

Autonomy levels.

Five levels, set per agent.

Agent autonomy ladderFive autonomy levels as rising steps from Suggest only to Autonomous in the guardrails. The guardrails remain fixed at every level.Agent autonomy ladderEvery new agent starts at Level 1.Autonomy is earned on approval history, not granted by default.Level 1Suggest onlyPerson reviews allLevel 2Draft and holdPerson releasesLevel 3Act on low-riskcases, escalateWritten envelopeLevel 4Act, escalateby exceptionPerson sees summaryLevel 5Autonomous inthe guardrailsLow reversal costFixed at every levelAllow-listed system callsField maskingOutput inspectionInherited role accessNo contact with any regulatory authorityAppend-only audit trailAgents cannot promote themselves.A level change is a change control with a second approver.
Every new agent starts at Level 1.Autonomy is earned on approval history, not granted by default.
Level 1: Suggest onlyPerson reviews all
Level 2: Draft and holdPerson releases
Level 3: Act on low-risk cases, escalateWritten envelope
Level 4: Act, escalate by exceptionPerson sees summary
Level 5: Autonomous in the guardrailsLow reversal cost
Fixed at every level
  • Allow-listed system calls
  • Field masking
  • Output inspection
  • Inherited role access
  • No contact with any regulatory authority
  • Append-only audit trail
Agents cannot promote themselves.A level change is a change control with a second approver.

Level 1

Suggest only.

The agent produces a recommendation and nothing else. Every new agent starts here.

Level 2

Draft and hold.

The agent prepares the complete work product, the record, the email or the investigation, and holds it. A person reviews and releases. Time goes to judgment, not preparation.

Level 3

Act on defined low-risk cases, escalate the rest.

The agent completes actions inside a written envelope, such as marking a batch record with no exceptions as reviewed or sending an internal reminder. Anything outside the envelope stops.

Level 4

Act, escalate by exception only.

The agent is the routine operator. A person sees the exceptions and the summary. Every action is reversible and logged.

Level 5

Autonomous inside the guardrails.

Reserved for decisions where the reversal cost is low and the evidence base is long.

Autonomy is earned.

Promotion is based on the agent's approval history against a threshold you set. Agents cannot promote themselves. A level change is a configuration change with a change control record and a second approver.

05

Evidence and reasoning.

Every finding carries numbered reasoning steps and the source items it came from. Extractions from scanned pages carry a confidence score. Anything below the threshold goes to a person.

06

The audit trail.

Append-only. Agent actions and human actions are recorded side by side and can be exported.

07

Starting without integration.

Every source can run in three modes: demonstration data, a spreadsheet export, or a connection when access is available. The behavior is the same in all three.

08

What stays with you.

Disposition, certification, closure, filing and accountability.

09

Guardrails and access.

On at every level:

Field-level masking.

Named fields, such as patient identifiers, employee identifiers and commercial pricing, are replaced with a token before the model sees them.

Department filtering.

Each agent reads only the departments it serves.

Inherited access.

The agent has the permissions of the person it works for, and no more.

Allow-listed system calls.

A call to an unmapped table is refused before it reaches the system.

Output inspection.

Everything an agent produces is checked for masked values before it is shown or sent.

Authority contact block.

No agent can send to a regulatory authority domain. This is enforced at the mail gateway, not by instruction.

10

Configuration under change control.

Every change to sources, levels, models or guardrails is saved with a reason for change and written to the audit trail, consistent with 21 CFR Part 11.

What the agents never do

Release, certify or disposition a batch

Close a deviation, investigation or CAPA

File anything with an authority

Write to your systems outside the transitions you approve

Send a message without a named person's approval

Contact a regulatory authority or a customer

Promote itself to a higher autonomy level

Make you compliant. Compliance decisions and accountability stay with you.

FAQ

Common Questions

All FAQs →

Can an agent write to our MES, LIMS or QMS?

+

No agent holds a general write credential to those systems. The only writes are the status transitions you approve for each agent, and every transition is logged and reversible.

Does the language model decide whether an exception exists?

+

No. That decision comes from rules written as code, which are versioned, testable and give the same answer on the same data. The model retrieves, reads documents and explains findings.

How does an agent move to a higher autonomy level?

+

Promotion is based on the agent's approval history against a threshold you set. A level change is a configuration change with a change control record and a second approver. Agents cannot promote themselves.

Can an agent contact a regulatory authority?

+

No. Messages to regulatory authorities and customers are blocked at every level. The block is enforced at the mail gateway, not by instruction.

Do we need a system integration before we start?

+

No. Every source can run on demonstration data, a spreadsheet export, or a connection when access is available. The behavior is the same in all three.

How are configuration changes recorded?

+

Every change to sources, levels, models or guardrails is saved with a reason for change and written to the audit trail, consistent with 21 CFR Part 11.

Bring one batch.

Send an export for one batch or lot and see the workspace run on your own data.

Which of these controls would your validation lead ask about first?