Skip to content

Enterprise Quality Management System (QMS)

Overview (/qms)

The Enterprise QMS module provides full operational lifecycle governance across quality events, engineering change controls, controlled specifications, and compliance inspection.

Enterprise Quality Management System Interface

Dual Operating Modes

To satisfy regulatory mandates for unhindered auditor access without risk of record alteration, the interface features a persistent toggle:

1. Operational Mode (Default)

  • Provides full read-write capabilities for Quality Assurance and CSV engineers.
  • Enables logging new deviations, drafting change controls, performing CSA risk evaluations, and executing digital signatures.

2. Auditor / Inspection Mode

  • Restricts the interface to a read-only inspection posture adhering strictly to 21 CFR § 11.10 and EU Annex 11.
  • All mutation buttons, action controls, and creation forms are hidden or locked.
  • Displays a prominent high-visibility regulatory banner confirming read-only audit posture.

Core Functional Tabs

1. Compliance Dashboard

  • Displays real-time KPIs: Controlled Documents count, Traceability Coverage percentage, Open IT Deviations, Active Change Controls, and ALCOA+ Audit Trail records.
  • Renders continuous compliance posture gauges across 21 CFR Part 11, EU Annex 11, GAMP 5, and FDA CSA.
  • Monitors live connectivity to PostgreSQL, Qdrant, Memgraph, and the backend API.

2. Controlled Document Repository (DMS)

  • Searchable and filterable repository containing 505 life sciences records:
    • Standard Operating Procedures (SOPs)
    • Work Instructions (WIs)
    • Quality Policies
    • User Requirements Specifications (URS)
    • Functional Specifications (FS)
    • Qualification Test Protocols (IQ/OQ/PQ)
  • Provides raw document viewing, structured chunk breakdown, and one-click agent context loading.

3. IT Deviations & Incidents (/deviations)

  • Records system incidents, nonconformances, and validation failures.
  • Captures severity categorization (Critical, Major, Minor), lifecycle state (Open, Investigation, CAPA Required, Pending Validation, Closed), and affected qualified systems.
  • Integrates with DeviationRcaAgent for automated forensic 5-Whys deduction and Ishikawa Fishbone root cause analysis.

4. IT Change Control (/change-control)

  • Manages software patches, configuration updates, and infrastructure revisions.
  • Implements ISPE GAMP 5 software categorization (Category 1 Infrastructure, Category 3 Standard COTS, Category 4 Configured, Category 5 Custom).
  • Enforces multi-stage governance: Initiation, CAB Review, Risk Assessment, In Validation, and Closed Release.
  • Includes 21 CFR Part 11 digital signature execution modals for Change Advisory Board (CAB) approvals.

5. ALCOA+ Audit Trail & Signature Verifier (/audit-trail)

  • Relational ledger showing an immutable chronological record of all system events: timestamps, users, roles, actions, entities, and cryptographic hashes.
  • Features the Cryptographic Manifest Verifier: calls /api/qms/verify-manifest to compute and verify the SHA-256 integrity hash of any signed record.

6. Memgraph LPG Topology Explorer

  • Interactive Cytoscape.js network visualizer.
  • Allows users to explore multi-hop relationships between documents, requirements, change controls, and assets.
  • Automatically generates and displays the underlying Cypher traversal queries.

Operational Use Case Scenario Workflows

The Enterprise QMS governs high-consequence quality processes where regulatory non-compliance risks clinical holds, warning letters, or product recalls.

Scenario 1: Critical Temperature Excursion Logging & Automated 5-Whys Forensic RCA

sequenceDiagram
autonumber
actor QA as Quality Assurance Lead
participant UI as QMS Deviations Console (/deviations)
participant Agent as DeviationRcaAgent
participant PG as PostgreSQL System of Record
participant Graph as Memgraph Topology
QA->>UI: Logs deviation DEV-2026-104 (Severity: Critical, Asset: EQ-FRZ-003)
UI->>Agent: Dispatches incident context for automated RCA
Agent->>Graph: Traverses historical deviations for EQ-FRZ-003
Graph-->>Agent: Returns 2 previous compressor valve service events
Agent->>Agent: Formulates 5-Whys chain and Ishikawa Fishbone categories
Agent->>PG: Commits structured RCA, immediate containment, and CAPA mandates
UI-->>QA: Renders RCA findings and auto-generates draft CAPA plan

1. Context & Operational Pre-conditions

  • Facility: GMP Commercial Cold Storage Suite.
  • Regulated Asset: Ultra-Low Freezer EQ-FRZ-003 (-80°C nominal).
  • Incident: Temperature spiked to -58.4°C for 42 minutes during overnight storage of bulk drug substance Lot #DS-9021.

2. Deviation Logging Workflow

  1. The Quality Assurance Specialist navigates to /qms and selects the IT Deviations & Incidents tab.
  2. Clicks Log Incident / Deviation.
  3. Populates mandatory fields:
    • System/Asset: EQ-FRZ-003 (Ultralow Freezer Unit 3).
    • Severity: Critical (Direct impact on product quality and stability).
    • Governing Regulation: 21 CFR § 211.192 and EU GMP Chapter 1.
    • Immediate Actions Taken: Material quarantined under physical lockout to backup freezer EQ-FRZ-001.

3. Automated 5-Whys Forensic Deduction

Upon form submission, the UI invokes DeviationRcaAgent:

  • Why 1: Temperature rose to -58.4°C because the primary refrigeration stage failed to engage.
  • Why 2: Primary stage failed because the high-pressure safety cutout valve tripped.
  • Why 3: Cutout tripped because condenser coil airflow was reduced by 65%.
  • Why 4: Airflow was reduced because particulate accumulation clogged the external filter matrix.
  • Why 5 (Root Cause): Preventative maintenance schedule under SOP-FAC-014 had a 90-day interval, which proved inadequate during ongoing adjacent facility construction activity.

4. Ishikawa Fishbone Categorization & CAPA Generation

  • Category: Machine / Environment (External environmental dust load exceeding equipment filtration cycle).
  • Mandated CAPA:
    1. Immediate: Replaced condenser intake filters and validated pull-down curve.
    2. Preventative: Accelerated PM frequency from 90 days to 30 days during construction period in SOP-FAC-014.
    3. Continuous Monitoring: Configured real-time differential pressure telemetry alerts.

Scenario 2: GAMP 5 Category 4 Change Control & CAB Digital Signature Approval

1. Context & Operational Pre-conditions

  • Regulated System: Veeva Vault QMS / LIMS Interface.
  • Proposed Change: Update LIMS sample disposition webhooks to include electronic signature metadata tags.
  • Categorization: ISPE GAMP 5 Category 4 (Configured Commercial Off-The-Shelf Software).

2. Initiation & Risk Assessment

  1. The CSV Engineer navigates to /qms -> IT Change Control tab and clicks Initiate Change Control.
  2. Selects System LIMS, Title CC-2026-088: Configure Webhook E-Signature Metadata.
  3. System invokes CapaChangeControlAgent and RiskAssessmentAgent:
    • Computes CSA Critical Thinking rigor: Limited Scripted Testing (direct data integrity impact, configured vendor API).
    • Pre-populates regression test protocol requirements (OQ-LIMS-HOOK-01).

3. Change Advisory Board (CAB) Review & Digital Signatures

  1. The Change Advisory Board reviews the proposed changes in the QMS console.
  2. The CAB Chair opens the 21 CFR Part 11 Electronic Signature Modal:
    • System prompts for user ID, password, and signing role.
    • Selected Reason: I approve this Change Control for release to Validation.
  3. System calls /api/qms/verify-manifest to sign the change record with an immutable SHA-256 hash.
  4. Record status advances to In Validation.

Scenario 3: Unannounced Regulatory Inspection & Auditor Mode Review

1. Context & Operational Pre-conditions

  • External Inspection: Unannounced FDA cGMP Surveillance Inspection.
  • Auditor Request: Inspect all Critical Deviations and associated CAPA implementations logged during the past 12 calendar months.

2. Auditor Mode Activation

  1. The Quality Director toggles Auditor / Inspection Mode on the top navigation bar of GxPChat.
  2. System posture changes immediately:
    • High-visibility amber regulatory banner displays: Auditor Mode Active - Read-Only Inspection Posture (21 CFR § 11.10 / EU Annex 11).
    • All mutation buttons (Log Incident, Initiate Change, Execute Protocol, Sign) are hidden and disabled.
    • API middleware actively rejects non-GET HTTP requests with HTTP 403 Forbidden.

3. Auditor Inspection Walkthrough

  1. Auditor navigates to /qms -> IT Deviations & Incidents.
  2. Applies filter: Severity: Critical, Status: Closed.
  3. Opens deviation record DEV-2026-042.
  4. Examines the complete immutable event chronology, root cause 5-Whys tree, linked CAPA records, and sign-off timestamps.
  5. Clicks Verify Cryptographic Manifest: system validates the SHA-256 hash against PostgreSQL, returning Manifest Integrity Verified (Zero Tampering Detected).
  6. Exports inspection bundle as a validated PDF/A compliance package.

Scenario 4: Knowledge Graph LPG Multi-Hop Relationship Exploration

1. Context & Operational Pre-conditions

A Quality Director must identify all documentation, systems, and physical laboratory instruments impacted by a planned revision to SOP-IT-018 (Automated Backup and Continuous WAL Archiving).

2. Execution in Topology Explorer

  1. Navigate to /qms -> Memgraph LPG Topology Explorer.
  2. In the query selector, choose Root Node: SOP-IT-018 with Depth: 2 Hops.
  3. The visualizer executes the Cypher query:
    MATCH (doc:Document {code: 'SOP-IT-018'})-[r1]-(n1)-[r2]-(n2)
    RETURN doc, r1, n1, r2, n2
  4. Visual Findings:
    • Node SOP-IT-018 connects via GOVERNS_POLICY to DisasterRecoveryPolicy.
    • Connects via DEPENDS_ON to database cluster PostgreSQL-Main and RustFS-S3.
    • Connects via VERIFIED_BY to Qualification Protocol OQ-DR-001.
  5. The Quality Director clicks Export Graph Topology to embed the dependency map directly into the engineering change evaluation dossier.