Platform evidence ledger
Evidence policy
Section titled “Evidence policy”Evidence does not dictate aggregate boundaries. Each row distinguishes:
- external obligation or observed behavior;
- the narrow domain implication;
- the TechSol modelling decision; and
- what the evidence does not justify.
Public documentation remains vendor-neutral. Market-product research is used privately to discover edge cases and is reported here only as cross-product patterns, never copied terminology.
Regulatory and standards claims
Section titled “Regulatory and standards claims”| Evidence ID | Source and section | Narrow requirement | Model implication | Does not justify |
|---|---|---|---|---|
| EV-REG-001 | 21 CFR 11.10(d),(g) | Limit access to authorized individuals and use authority checks | Explicit Principal, Action, Scope and reconstructable authority evidence | One universal Role catalogue or Platform super-user |
| EV-REG-002 | 21 CFR 11.10(e) | Secure time-stamped audit trails reconstruct creation/modification/deletion without obscuring prior information | Append-only outcome/correction evidence with prior/resulting meaning | Event sourcing or generic object-diff as domain truth |
| EV-REG-003 | 21 CFR 11.50 | Signature shows signer name, execution time and meaning | Candidate ElectronicSignatureEvidence pins signer, time and product-supplied statement meaning |
Universal signature requirement or generic Approval |
| EV-REG-004 | 21 CFR 11.70 | Signature remains linked to its record and cannot be transferred | Exact target identity/revision/digest; later revision does not inherit | Moving a signature to corrected data |
| EV-REG-005 | 21 CFR 11.100/11.200/11.300 | Signature identity is unique, verified and controlled by its owner | Principal/authentication/signature ceremony remain distinct | Treating ordinary login attribution as every signature ceremony |
| EV-GCP-001 | ICH E6(R3) §4.2.2–4.2.4 | Data and metadata are attributable; corrections are traceable, timely and do not obscure original entry | Actor/source, recorded/effective time, reasoned correction lineage | One mutable “last updated by” field |
| EV-GCP-002 | ICH E6(R3) §4.3.8 | Access rights reflect duties and blinding and remain controlled | Product-bounded Action and typed Scope; blind classification separate from Role label | Responsibility automatically granting authority |
| EV-GCP-003 | ICH E6(R3) §4.3.5 | Trial-specific systems/amendments released to site only after applicable approvals | EDC owns Site System Release/readiness; Platform Study Site cannot mean activated | Platform StudySite.active as universal product readiness |
| EV-GCP-004 | ICH E6(R3) §2.12 and §3.16 | Investigator access and retained trial data must remain available under applicable responsibility | Product disable/closure must preserve declared inspection/retention access | Entitlement withdrawal deleting product evidence |
| EV-GCP-005 | ICH E6(R3) Appendix C | Essential records require identifiable versions, authors/reviewers/approvers, location, retrieval and alteration trace | Content identity/revision primitive plus eTMF-owned record meaning | Platform-owned TMF Document lifecycle |
| EV-FDA-001 | FDA Electronic Systems, Records and Signatures Q&A, Q12–Q14 | Audit includes relevant old/new values, user role, time, reason and human/system origin | Named evidence profiles; initiating human and executing system remain distinct | Auditing every keystroke or every read |
| EV-FDA-002 | FDA Q&A Q3 | Certified copy preserves context, content, structure and relevant metadata under verified process | Certified-copy verification is a distinct Candidate decision | Export/hash alone being a certified copy |
| EV-EMA-001 | EU Clinical Trials Regulation Articles 56–58 | Clinical-trial data and master file remain reliable, available and archived for applicable periods | Retention is record-class/jurisdiction/trigger policy, not one date field | One suite-wide retention duration |
| EV-EMA-002 | EMA computerised-systems guideline §§4–7 | User management, security, auditability, data lifecycle and provider oversight are governed | Separate identity/access/evidence contracts and intended-use Candidate | Tenant-wide “compliant” flag |
| EV-PRIV-001 | GDPR Articles 5, 24, 25, 29–32 | Purpose limitation, minimization, security and accountable processing | Purpose-limited Person/Profile contracts and privacy classification | Publishing all contact/profile data suite-wide |
| EV-REF-001 | ISO 3166 country codes | Governed country identifiers are distinct from localized names | CountryReference / CountryCode value |
Regulatory or Study participation lifecycle |
| EV-CDISC-001 | CDISC USDM | Rich protocol-design meaning has its own structured model | Platform Study remains a narrow registry coordinate | Importing objectives/arms/epochs/schedule into Platform Study |
Mature-product research was used privately to discover edge cases and formulate PM questions, but it is intentionally not part of the public claim ledger. No Proposed Core promotion depends on an unpublished market observation.
Evidence-driven negative conclusions
Section titled “Evidence-driven negative conclusions”No reviewed source requires or supports:
- a universal
RegulatedRecordsuperclass; - a generic
Workflow,Approval,TaskorDocumentLifecycle; - a tenant-wide Part 11 or GCP compliance flag;
- treating Study responsibility or training completion as application authority;
- auditing every keystroke or every read;
- mandatory electronic signature for every decision;
- one retention duration for all clinical records;
- backup being equivalent to archive;
- automatic target deletion when a source disappears;
- event sourcing, blockchain, WORM storage or a particular database; or
- applying manufacturing-specific guidance automatically to the whole clinical suite.
Claim-to-model review rule
Section titled “Claim-to-model review rule”A source supports an obligation or edge case. The model’s owner, Aggregate boundary and command shape remain TechSol decisions and must be validated by scenarios and product review.