Skip to content

Platform invariant traceability

An invariant is not complete until its enforcing commands, stable refusal, success/refusal scenarios and evidence basis are named. Scenario identifiers refer to the verification suite.

ID Invariant Owner Enforced by Refusal / outcome Scenarios Evidence claim
PLAT-OWN-001 Every authoritative concept has exactly one semantic owner Model governance Model review; connection publication Contract not accepted VS-13, VS-14 GCP responsibility clarity; modelling decision
PLAT-OWN-002 Shared identity never implies a shared lifecycle Integration Contracts All product composition commands Owner command required VS-02, VS-11, VS-15 Product-boundary decision
PLAT-OWN-003 Platform Study never contains EDC/eTMF mutable state Study Registry Enable/disable, Study corrections Cross-owner mutation refused VS-02, VS-07 Product-boundary decision
PLAT-OWN-004 Source facts may propose target work but cannot make target decisions Integration Contracts Delivery/target commands TARGET_COMMAND_REFUSED VS-13–15 Attributable owner decisions
ID Invariant Owner Enforced by Refusal Scenarios Evidence claim
PLAT-ID-001 Every object belongs to exactly one Workspace Each owner Every creation/reference command WORKSPACE_MISMATCH VS-01, VS-04 Customer/security boundary
PLAT-ID-002 Stable identity is opaque, immutable and never derived from editable business keys Registries Register/correct/merge UNSUPPORTED_CORRECTION VS-01, VS-03, VS-04 Reconstructability
PLAT-ID-003 Similarity never establishes identity or automatic merge Party/Study Registry Registration and duplicate review Duplicate decision per policy VS-01, VS-02 Market evidence; safety decision
PLAT-ID-004 One retained Study Country exists per Study and governed country Study Registry PlanStudyCountry STUDY_COUNTRY_CONFLICT VS-17 Shared country coordinate
PLAT-ID-005 A Study Site references exactly one Study, its Study Country and one Site for life in Core Study Registry Associate/correct UNSUPPORTED_CORRECTION VS-04, VS-05 Cross-product stable scope
PLAT-ID-006 Site country equals Study Country at association time Study Registry AssociateSiteWithStudy SITE_COUNTRY_MISMATCH VS-04, VS-05 Hierarchy integrity
PLAT-ID-007 Study site number uniqueness/reservation is governed within Study Study Registry Associate/correct STUDY_SITE_NUMBER_CONFLICT VS-04 Operational convention
PLAT-ID-008 Historical identifiers remain resolvable after archive, retirement or disabling Every owner Lifecycle commands Deletion not available VS-02, VS-11 GCP/Part 11 reconstructability
ID Invariant Owner Enforced by Refusal Scenarios Evidence claim
PLAT-AUTH-001 Every Access Decision includes Principal + Product + Action + complete typed Scope Identity & Access DecideAccess NOT_AUTHORIZED VS-06, VS-15, VS-16 Authorized-access controls
PLAT-AUTH-002 Platform authority is not an EDC/eTMF wildcard Identity & Access Role revision/decision Cross-product Action refused VS-06, VS-15 Least privilege
PLAT-AUTH-003 Responsibility, title, Organization type, entitlement and route never grant an Action Identity & Access Assignment and decision NOT_AUTHORIZED VS-06 GCP delegation vs system access
PLAT-AUTH-004 Role Definitions have one home Product and their published revisions are immutable Identity & Access Role revision CROSS_PRODUCT_ACTION_NOT_ALLOWED VS-06 Historical authority reconstruction
PLAT-AUTH-005 Assignment is effective-dated, independently revocable and explicitly scoped Identity & Access Assign/end/decision EFFECTIVE_INTERVAL_CONFLICT VS-06, VS-16 Current need and access history
PLAT-AUTH-006 Delegated administrator cannot grant above product/scope authority Identity & Access AssignRole DELEGATION_SCOPE_EXCEEDED VS-06 Least privilege / market evidence
PLAT-AUTH-007 Continuity-sensitive administration changes cannot remove the last qualifying grant Identity & Access Role/Assignment/Principal change CONTINUITY_VIOLATION VS-18 Operational continuity decision
PLAT-AUTH-008 Collection authorization is applied before count, filter, facets, order and pagination Projection owner Collection decision Hidden result VS-16 Information-disclosure control
PLAT-RESP-001 A Participation has one Party, Responsibility and exact Scope Clinical Coordination Add/replace/correct Kind/scope mismatch VS-06 Responsibility clarity
PLAT-RESP-002 Identical exclusive responsibility intervals cannot overlap Clinical Coordination Add/replace EFFECTIVE_INTERVAL_CONFLICT VS-19 Temporal integrity
PLAT-RESP-003 Ending responsibility publishes no Access Assignment mutation Clinical Coordination End/replace Participation No implicit mutation VS-06 Owner separation
ID Invariant Owner Enforced by Refusal Scenarios Evidence claim
PLAT-CONT-001 Registered Content Revision bytes, digest and provenance are immutable Content Register/add revision New revision required VS-09 Record integrity
PLAT-CONT-002 Verification is a Decision over an exact revision, not mutable byte state Content Verification decision Exact digest mismatch VS-09 Traceable verification
PLAT-CONT-003 Only currently available verified revision may be bound Content BindContentRevision CONTENT_NOT_AVAILABLE VS-09 Validated content handling
PLAT-CONT-004 Content binding never creates EDC/eTMF meaning in Platform Content Bind then owner command Owner command required VS-09 Content/product boundary
PLAT-EVID-001 Regulated correction preserves prior and resulting state, actor/source, time and reason where applicable Every owner All correction commands REASON_REQUIRED VS-03–05 ICH/FDA correction requirements
PLAT-EVID-002 Business actor and authenticated executing identity remain distinct Evidence & Audit Connection/system commands Incomplete evidence refused VS-20 FDA human/system originator distinction
PLAT-EVID-003 Recorded time and effective business time are separately retained when different Every owner Evidence profiles Incomplete evidence refused VS-03, VS-06 Unambiguous time / reconstructability

Candidate electronic-signature invariants—not Core

Section titled “Candidate electronic-signature invariants—not Core”

These rows describe regulatory constraints on a future mechanism. They do not promote a signature command or ceremony until a current EDC/eTMF command and PD-PLAT-017 are accepted.

ID Candidate invariant Mechanism owner / meaning owner Future enforcement Refusal Candidate scenario Evidence claim
PLAT-SIGN-001 Signature evidence binds signer, product-supplied meaning, execution time and exact target revision/digest Evidence & Audit Candidate product sign command SIGNATURE_TARGET_STALE VS-10 21 CFR 11.50/11.70
PLAT-SIGN-002 Signature evidence is not transferred to a later target revision Evidence & Audit Candidate correct/revise/sign New ceremony required VS-10 Signature-record linkage
ID Invariant Owner Enforced by Refusal Scenarios Evidence claim
PLAT-COMP-001 Study-root admission profile keeps entitlement, enablement, authority and product policy as independent gates Suite Composition Study-root entry/commands Gate-specific refusal VS-07, VS-11, VS-15 Least privilege / owner separation
PLAT-COMP-002 Only owning product acknowledges its product root Suite Composition Enable acknowledgement Wrong product refused VS-07, VS-08 Product ownership
PLAT-COMP-003 Acknowledgement matches exact Study, Product, Operation and Contract Revision Suite Composition Acknowledge STALE_OPERATION_ACKNOWLEDGEMENT VS-08, VS-14 Idempotent reconciliation
PLAT-COMP-004 Suite disable/withdrawal coordination never issues a product-data deletion instruction Suite Composition Withdraw/disable coordination Delete instruction refused VS-07, VS-11 Retention and owner boundary
PLAT-INT-001 Delivery pins source Fact, target intent and immutable Contract Revision Integration Contracts Schedule delivery Contract mismatch VS-13, VS-14 Reproducible mapping
PLAT-INT-002 At most one accepted target outcome exists per idempotency identity Work & Integration Mechanisms Record target outcome Duplicate accepted idempotently VS-21 Idempotency
PLAT-INT-003 Retry never changes source fact, mapping or target intent Work & Integration Mechanisms Retry New delivery required VS-13, VS-14 Evidence integrity
PLAT-INT-004 Target refusal differs from retryable delivery failure Work & Integration Mechanisms Record outcome Typed outcome VS-14, VS-15 Semantic owner decision
PLAT-INT-005 Connection consumers must not regress an applied owner revision Integration Contracts Apply/reconcile Stale/gap result VS-13 Monotonic projection safety
ID Invariant Owner Enforced by Refusal Scenarios Evidence claim
PLAT-MILE-001 Baseline, planned, forecast and actual are distinct temporal meanings Study Timeline Plan/forecast/achieve/correct Date-kind refusal VS-22 Operational semantics
PLAT-MILE-002 Forecast is not a lifecycle state Study Timeline Forecast command Lifecycle unchanged VS-22 Model correction
PLAT-MILE-003 Initial type is Site Activated at Study Site scope with one retained identity Study Timeline Plan/achieve Type/scope refused VS-22 Minimum-complete model
PLAT-MILE-004 Correction/reversal preserves prior achievement evidence and never rewrites source product fact Study Timeline Correct/reverse Exact source required VS-22 Attribution and owner separation

The following invariants cannot be accepted until the product decision ledger resolves them:

  • Study duplicate admission and merge/supersession behavior after product roots exist.
  • Used-Site country correction/replacement lineage.
  • In-flight enablement behavior during entitlement withdrawal.
  • Disabled-product inspection access matrix.
  • Retention/legal-hold ownership and disposition serialization.
  • Study Country transition authority/effects beyond the accepted lifecycle vocabulary.
  • Candidate signature decision-time and ceremony policy.