Audit trail

Who changed it, when, and why they said they did.

Every change to every record — what changed, who changed it, and the reason they gave — written down as it happens, and impossible to alter afterwards. Including by us.

app.qformance.io / non-conformances / NCR-2026-0418 / history
History

NCR-2026-0418 · Seal leak at final test

Print for inspector
WhenWhoFieldChange
12 May · 14:22L. ChenStatusUnder reviewApproved
Verification evidence attached and reviewed.
12 May · 11:07L. ChenDue date30 Apr15 May
09 May · 16:41D. HayesSeverityMinorMajor
Second occurrence on the same lot.
08 May · 09:15S. AdlerAssigneeD. Hayes
Nothing to remember

Nobody has to keep the log.

A trail that depends on someone remembering to write it down is a trail with holes in it — and the holes are always in the weeks that turn out to matter. Here it is recorded the moment the change is saved, whether or not anyone was thinking about the audit.

You get the specifics, not a vague note that something was edited: this field, from this value, to that value, by this person, at this time. Every record in the system has the same History tab — non-conformances, changes, audits, documents, risks, products, suppliers — so there is one place to look and one thing to learn.

Names are recorded as they were on the day. Somebody leaving the company two years later doesn’t turn their approvals into blanks.

NCR-2026-0418 · History
WhenWhoFieldChange
12 May · 14:22L. ChenStatusUnder reviewApproved
Verification evidence attached and reviewed.
12 May · 11:07L. ChenDue date30 Apr15 May
09 May · 16:41D. HayesSeverityMinorMajor
Second occurrence on the same lot.
08 May · 09:15S. AdlerAssigneeD. Hayes
The reason

A state change without a reason isn't evidence.

Knowing a record moved from under review to approved tells an inspector almost nothing. Knowing why the approver said it moved is the part that reconstructs a decision.

So every transition that changes a record’s disposition — approve, reject, close, reopen, cancel, obsolete, supersede, activate, deactivate — opens a confirm panel with a required reason. Not a nice-to-have field somebody can tab past: the write is refused without it.

Routine progress is left alone. Nudging an action from open to in progress saves without ceremony. The ceremony is reserved for the decisions somebody may one day have to defend.

Approve · MOC-2026-0119

Reason *

Trial run completed on line 2 with no dimensional drift. Engineering and QA both signed the trial report.

Approve is disabled until a reason is entered.

Confirm with passkeyCancel
Permanent

Nobody can quietly rewrite it. Including us.

An audit trail somebody can edit is decoration. This one cannot be changed once written — not by a user, not by your own administrator, not by anyone at QFormance with access to the servers. Corrections are new entries that sit alongside the original, never replacements for it.

That is enforced in three independent places rather than one, so a single mistake or a single compromised account doesn’t open the door. It is the difference between a log you keep and evidence you can rely on.

Which is the property that matters in an investigation: if the trail says a deviation was approved at 14:22 on the twelfth, nobody was able to go back afterwards and make it say something more comfortable.

Editing a past entry
An ordinary userRefused
Your own administratorRefused
QFormance, server-sideRefused

A correction is added as a new entry, with its own author, time and reason. The original stays visible.

Signature manifestation

A printout that says what the signature meant.

A signed electronic record has to carry its signature into whatever comes out of the printer. Both export paths — Word and browser PDF — append a manifest block stating the meaning of the signature, who signed, when, the version of record, its file hash, and who printed the copy and when.

It is print-only on the PDF path, so it never clutters the screen, and it is omitted when there is no signature to manifest — a draft export doesn’t pretend to be an approved one.

Every record type also has an inspector-ready history export at its own URL, so handing over “the full history of this record” is a print, not a project.

SOP-MX-04 v3.2 · export

Approved record

Meaning
Approved for use
Signed by
L. Chen · Quality Manager
Signed at
12 May 2026 14:22 UTC
Version
3.2
File hash
sha256 9f2c…a71b
Printed by
D. Hayes · 08 Aug 2026

Appears on the printout only — never on screen.

Reads, not just writes

Who has been reading the audit trail?

Most systems can tell you who changed a record. Rather fewer can tell you who looked at the evidence — which is the question that matters when the concern is a leak rather than a falsification.

Opening a record’s history, exporting it, and pulling a controlled document’s file are each logged with the viewer, the record and the moment. So “who pulled this PDF?” has an answer, and so does “who was reading the trail the week before this went wrong?”

Audit log access
D. HayesViewed history · NCR-2026-041808 Aug · 09:41
S. AdlerDownloaded · SOP-MX-04 v3.207 Aug · 16:02
L. ChenPrinted history · MOC-011905 Aug · 11:20
ExternalViewed history · AUD-2026-01102 Aug · 14:55
Auth activity

The security decisions, on their own feed.

Sign-in policy changes, passkey confirmations on approvals, role changes, password and multi-factor resets — the events that decide who could have done something — get their own feed rather than being buried in the general timeline.

Entries keep the detail that makes them reconstructable later: a policy change records what it was before and after, and an administrator who proceeds past a warning has the warning, and the fact they proceeded, written down beside the change.

Auth activity

Sign-in policy changed

passkey added to allowed methods

Passkey step-up confirmed

L. Chen · approving MOC-0119

Role changed

S. Adler: standard_user → admin

MFA reset

requested by admin · user notified

Built around 21 CFR Part 11 expectations.

Six technical controls, and what each one actually does. Read them as engineering commitments you can test, not as a compliance claim.

Attributable

Always a name against it

Recorded as they were on the day, so approvals stay attributed after someone leaves.

Permanent

Cannot be edited afterwards

Not by a user, not by your administrator, not by us. Corrections are new entries.

Explained

A reason on every decision

Approve, reject, close, reopen, cancel and supersede will not save without one.

Signed

The printout carries the signature

What it meant, who signed, when, which version — on the page an inspector holds.

Verifiable

Files provably unchanged

Every uploaded file is fingerprinted, and every download is recorded against a name.

Contained

Your records stay yours

Separation between organisations is enforced beneath the application, not just inside it.

To be explicit about what this is and isn’t: these are technical controls we build and can demonstrate. QFormance holds no regulatory certification, registration or government approval, and no software can make an organisation compliant on its own — compliance rests on your validated procedures, your training and your records. What we can do is show you exactly how each control behaves, including where it deliberately stops.

The trail is only as good as the boundary around it.

Evidence nobody can quietly rewrite, reached only by people who should reach it.

Step-up on the decisions that matter

Approvals and rejections can require a passkey at the moment of the click — Touch ID, Windows Hello, or a hardware security key — and the confirmation is written to the trail beside the decision.

Your records stay yours

Separation between organisations is enforced underneath the application, not only inside it — so a bug in a screen cannot hand one company another company's records.

One tab, every record

The same History tab appears on non-conformances, changes, audits, documents, risks, products, suppliers and more, with nothing new to learn per module.

Inspector-ready without preparation

Any record's full history prints from its own URL. Nothing to assemble, export, reconcile or reformat the week before an audit.

Evidence you don't have to assemble.

The trail is written as people work, not reconstructed the week before an audit.