COMPLIANCE
Written for quality systems, validation and IT readers.
01
Read access, controlled writes.
Agents read your systems through an allow list. No agent holds a general write credential to MES, LIMS or QMS. The only writes are the status transitions you approve for each agent, for example marking a clean batch record as reviewed and ready for the Qualified Person. Every transition is logged and reversible.
02
Deterministic rules.
The rules that decide whether an exception exists are code. They are versioned and testable, and they give the same answer on the same data. The language model retrieves, reads documents and explains findings. It does not decide.
03
The human gate.
At Levels 1 and 2, nothing reaches the register and no message is sent until a named reviewer confirms it. At Level 3 and above, the agent acts only inside a written envelope you define, and everything outside it stops and waits. Messages to regulatory authorities and customers are blocked at every level.
04
Five levels, set per agent.
Level 1
Suggest only.
The agent produces a recommendation and nothing else. Every new agent starts here.
Level 2
Draft and hold.
The agent prepares the complete work product, the record, the email or the investigation, and holds it. A person reviews and releases. Time goes to judgment, not preparation.
Level 3
Act on defined low-risk cases, escalate the rest.
The agent completes actions inside a written envelope, such as marking a batch record with no exceptions as reviewed or sending an internal reminder. Anything outside the envelope stops.
Level 4
Act, escalate by exception only.
The agent is the routine operator. A person sees the exceptions and the summary. Every action is reversible and logged.
Level 5
Autonomous inside the guardrails.
Reserved for decisions where the reversal cost is low and the evidence base is long.
Autonomy is earned.
Promotion is based on the agent's approval history against a threshold you set. Agents cannot promote themselves. A level change is a configuration change with a change control record and a second approver.
05
Evidence and reasoning.
Every finding carries numbered reasoning steps and the source items it came from. Extractions from scanned pages carry a confidence score. Anything below the threshold goes to a person.
06
The audit trail.
Append-only. Agent actions and human actions are recorded side by side and can be exported.
07
Starting without integration.
Every source can run in three modes: demonstration data, a spreadsheet export, or a connection when access is available. The behavior is the same in all three.
08
What stays with you.
Disposition, certification, closure, filing and accountability.
09
On at every level:
Field-level masking.
Named fields, such as patient identifiers, employee identifiers and commercial pricing, are replaced with a token before the model sees them.
Department filtering.
Each agent reads only the departments it serves.
Inherited access.
The agent has the permissions of the person it works for, and no more.
Allow-listed system calls.
A call to an unmapped table is refused before it reaches the system.
Output inspection.
Everything an agent produces is checked for masked values before it is shown or sent.
Authority contact block.
No agent can send to a regulatory authority domain. This is enforced at the mail gateway, not by instruction.
10
Every change to sources, levels, models or guardrails is saved with a reason for change and written to the audit trail, consistent with 21 CFR Part 11.
Release, certify or disposition a batch
Close a deviation, investigation or CAPA
File anything with an authority
Write to your systems outside the transitions you approve
Send a message without a named person's approval
Contact a regulatory authority or a customer
Promote itself to a higher autonomy level
Make you compliant. Compliance decisions and accountability stay with you.
FAQ
Can an agent write to our MES, LIMS or QMS?
+
No agent holds a general write credential to those systems. The only writes are the status transitions you approve for each agent, and every transition is logged and reversible.
Does the language model decide whether an exception exists?
+
No. That decision comes from rules written as code, which are versioned, testable and give the same answer on the same data. The model retrieves, reads documents and explains findings.
How does an agent move to a higher autonomy level?
+
Promotion is based on the agent's approval history against a threshold you set. A level change is a configuration change with a change control record and a second approver. Agents cannot promote themselves.
Can an agent contact a regulatory authority?
+
No. Messages to regulatory authorities and customers are blocked at every level. The block is enforced at the mail gateway, not by instruction.
Do we need a system integration before we start?
+
No. Every source can run on demonstration data, a spreadsheet export, or a connection when access is available. The behavior is the same in all three.
How are configuration changes recorded?
+
Every change to sources, levels, models or guardrails is saved with a reason for change and written to the audit trail, consistent with 21 CFR Part 11.
Send an export for one batch or lot and see the workspace run on your own data.
Which of these controls would your validation lead ask about first?