Who changed it, when, and why they said they did.
Every change to every record — what changed, who changed it, and the reason they gave — written down as it happens, and impossible to alter afterwards. Including by us.
NCR-2026-0418 · Seal leak at final test
Print for inspectorNobody has to keep the log.
A trail that depends on someone remembering to write it down is a trail with holes in it — and the holes are always in the weeks that turn out to matter. Here it is recorded the moment the change is saved, whether or not anyone was thinking about the audit.
You get the specifics, not a vague note that something was edited: this field, from this value, to that value, by this person, at this time. Every record in the system has the same History tab — non-conformances, changes, audits, documents, risks, products, suppliers — so there is one place to look and one thing to learn.
Names are recorded as they were on the day. Somebody leaving the company two years later doesn’t turn their approvals into blanks.
A state change without a reason isn't evidence.
Knowing a record moved from under review to approved tells an inspector almost nothing. Knowing why the approver said it moved is the part that reconstructs a decision.
So every transition that changes a record’s disposition — approve, reject, close, reopen, cancel, obsolete, supersede, activate, deactivate — opens a confirm panel with a required reason. Not a nice-to-have field somebody can tab past: the write is refused without it.
Routine progress is left alone. Nudging an action from open to in progress saves without ceremony. The ceremony is reserved for the decisions somebody may one day have to defend.
Reason *
Trial run completed on line 2 with no dimensional drift. Engineering and QA both signed the trial report.
Approve is disabled until a reason is entered.
Nobody can quietly rewrite it. Including us.
An audit trail somebody can edit is decoration. This one cannot be changed once written — not by a user, not by your own administrator, not by anyone at QFormance with access to the servers. Corrections are new entries that sit alongside the original, never replacements for it.
That is enforced in three independent places rather than one, so a single mistake or a single compromised account doesn’t open the door. It is the difference between a log you keep and evidence you can rely on.
Which is the property that matters in an investigation: if the trail says a deviation was approved at 14:22 on the twelfth, nobody was able to go back afterwards and make it say something more comfortable.
A correction is added as a new entry, with its own author, time and reason. The original stays visible.
A printout that says what the signature meant.
A signed electronic record has to carry its signature into whatever comes out of the printer. Both export paths — Word and browser PDF — append a manifest block stating the meaning of the signature, who signed, when, the version of record, its file hash, and who printed the copy and when.
It is print-only on the PDF path, so it never clutters the screen, and it is omitted when there is no signature to manifest — a draft export doesn’t pretend to be an approved one.
Every record type also has an inspector-ready history export at its own URL, so handing over “the full history of this record” is a print, not a project.
Approved record
- Meaning
- Approved for use
- Signed by
- L. Chen · Quality Manager
- Signed at
- 12 May 2026 14:22 UTC
- Version
- 3.2
- File hash
- sha256 9f2c…a71b
- Printed by
- D. Hayes · 08 Aug 2026
Appears on the printout only — never on screen.
Who has been reading the audit trail?
Most systems can tell you who changed a record. Rather fewer can tell you who looked at the evidence — which is the question that matters when the concern is a leak rather than a falsification.
Opening a record’s history, exporting it, and pulling a controlled document’s file are each logged with the viewer, the record and the moment. So “who pulled this PDF?” has an answer, and so does “who was reading the trail the week before this went wrong?”
The security decisions, on their own feed.
Sign-in policy changes, passkey confirmations on approvals, role changes, password and multi-factor resets — the events that decide who could have done something — get their own feed rather than being buried in the general timeline.
Entries keep the detail that makes them reconstructable later: a policy change records what it was before and after, and an administrator who proceeds past a warning has the warning, and the fact they proceeded, written down beside the change.
Sign-in policy changed
passkey added to allowed methods
Passkey step-up confirmed
L. Chen · approving MOC-0119
Role changed
S. Adler: standard_user → admin
MFA reset
requested by admin · user notified
Built around 21 CFR Part 11 expectations.
Six technical controls, and what each one actually does. Read them as engineering commitments you can test, not as a compliance claim.
Always a name against it
Recorded as they were on the day, so approvals stay attributed after someone leaves.
Cannot be edited afterwards
Not by a user, not by your administrator, not by us. Corrections are new entries.
A reason on every decision
Approve, reject, close, reopen, cancel and supersede will not save without one.
The printout carries the signature
What it meant, who signed, when, which version — on the page an inspector holds.
Files provably unchanged
Every uploaded file is fingerprinted, and every download is recorded against a name.
Your records stay yours
Separation between organisations is enforced beneath the application, not just inside it.
To be explicit about what this is and isn’t: these are technical controls we build and can demonstrate. QFormance holds no regulatory certification, registration or government approval, and no software can make an organisation compliant on its own — compliance rests on your validated procedures, your training and your records. What we can do is show you exactly how each control behaves, including where it deliberately stops.
The trail is only as good as the boundary around it.
Evidence nobody can quietly rewrite, reached only by people who should reach it.
Step-up on the decisions that matter
Approvals and rejections can require a passkey at the moment of the click — Touch ID, Windows Hello, or a hardware security key — and the confirmation is written to the trail beside the decision.
Your records stay yours
Separation between organisations is enforced underneath the application, not only inside it — so a bug in a screen cannot hand one company another company's records.
One tab, every record
The same History tab appears on non-conformances, changes, audits, documents, risks, products, suppliers and more, with nothing new to learn per module.
Inspector-ready without preparation
Any record's full history prints from its own URL. Nothing to assemble, export, reconcile or reformat the week before an audit.
Evidence you don't have to assemble.
The trail is written as people work, not reconstructed the week before an audit.