Health, Education & Government Life Sciences & Pharma Quality & Regulatory Compliance

Quality Management

Regulated development and commercialization journeys where clinical, quality, and market access align.

Example organizations in this space: MasterControl Veeva QualityOne Pilgrim Software ETQ

This interactive experience is the shipped product itself — the same application code customers run in production, mounted read-only in your browser over a real sample journey. Not a video, not a mockup: because the demo and the product are one codebase, it can never drift from the real thing.

Inside this journey
  1. Pre-Sales

    Qualify and diagnose buyer context, compliance constraints, and stakeholders before full solution work.

    1. Qualification

      Confirm budget range, decision-makers, timeline, and critical regulatory or validation constraints before investing in a full discovery.

      Qualification Questions

      Regulatory & Validation Constraints (quick readiness check)

      • Which regulatory frameworks apply to the processes this QMS will govern? Select all that apply. Options: FDA 21 CFR Parts 210/211, FDA 21 CFR Part 820 (medical device), EU GMP Annex 11 or Annex 1, ISO 13485, Contains PHI or patient-identifiable data, Other (please specify)
      • Do you have required validation deliverables, templates, or an internal validation SOP we should align to (for example IQ/OQ/PQ artifacts)? Please summarize.

      Technical and Data Fit

      • Which systems will the QMS need to integrate with or replace, and what are the primary data migration sources? List key systems (for example MES, ERP, LIMS, shared drives).

      Workflow Configurability and Adoption

      • Who will be the primary day-to-day users by role and approximate headcount?
      • Which approach to configuration and adoption fits you best right now? Options: We have internal change and training resources and will co-own adoption, We can support configuration but need vendor-led validation and training, We need a low-touch, turnkey configuration plus vendor training, Unsure, would like to discuss options

      Budget, Authority, and Timeline

      • Is there an allocated budget range for this QMS initiative? Options: Less than $50,000, $50,000 to $150,000, $150,000 to $350,000, $350,000 to $750,000, More than $750,000, No budget allocated / under discussion
      • Who will approve the purchase and which roles will materially influence the decision? Select all that apply. Options: Head of Quality / VP Quality, Quality System Manager, IT Director or Head of IT, CFO / Finance, Procurement, Site Operations / Manufacturing Lead, Other (please specify)
      • What is your target go-live timeframe and is there a fixed deadline driving it (for example an inspection, contract milestone, or product launch)? Options: Within 3 months, 3 to 6 months, 6 to 12 months, More than 12 months, Driven by a fixed regulatory or audit deadline (please specify)
    2. Enterprise Discovery

      Map stakeholders, current-state quality processes, legacy data sources, integrations, and compliance risks that the solution must address.

      Discovery Questions

      Mapping Your Current Quality Picture

      • How would you briefly describe your current end-to-end quality system and where most controlled records live?
      • Tell me about the source systems that create quality evidence for manufacturing, lab, and suppliers, and which of those you consider authoritative. Options: Your MES, Your LIMS, Your ERP, Shared drives and file servers, Paper logbooks, Point solutions (legacy QMS modules), Other
      • On average, how many active controlled documents, open CAPAs, and open deviations does your quality team manage at a time? Options: <100, 100–499, 500–1,999, 2,000–5,000, >5,000
      • Walk me through the last time your team had to pull evidence for an inspection, who gathered the records, and how long it took to provide them.
      • Which single process between document control, CAPA, deviation handling, and training creates the most daily manual work for your staff? Options: Document control, CAPA management, Deviation/nonconformance handling, Training records, Change control, Supplier qualification, Audit management

      Where the Current System Actually Breaks

      • When an inspection or regulatory query lands, what single gap in your current quality setup would most likely trigger an observation or warning?
      • Give a recent example of a time your team could not produce a required record quickly, what the missing element was, and the downstream cost or delay.
      • How many users routinely bypass formal workflows because they are slower than manual workarounds? Options: None, A few power users, A departmental pattern, Across multiple sites
      • Describe what breaks downstream when training records or batch-linked documents are not current, for example release holds or repeat investigations.
      • If a regulator asked for full traceability on affected batches for the past 24 months, could your team assemble signed, time stamped evidence within 7 days? Options: Yes, Partially, with manual effort, No

      Hidden Compliance Risks That Nobody Volunteers

      • Who on your team is responsible for maintaining electronic signature, audit trail, and Part 11 or Annex 11 procedures, and where are those procedures documented?
      • Which types of quality affecting data currently live outside your primary systems and would need to be brought under control for validation purposes? Options: Paper forms, Spreadsheets, Homegrown databases, Third-party lab portals, Email attachments, Other
      • Estimate the monthly volume of paper only records that are created and the current reconciliation steps you use to capture them electronically. Options: <50 records, 50–199, 200–999, 1,000–4,999, >=5,000
      • When was the last time a documented validation gap delayed a product release or resulted in corrective actions? Options: In the last 6 months, 6–12 months ago, Over a year ago, Never
      • Is there any active regulatory hold, ongoing inspection, or legal review that would prevent starting validation work in the next 60 days? Options: Yes — detail in follow up, No

      The Options You Are Seriously Considering

      • Tell me which external vendors, incumbent systems, or internal build efforts you are currently evaluating for quality management. Options: Incumbent enterprise QMS, Point solutions or modules, Internal custom build, Spreadsheet based controls, No formal plan yet, Other
      • Rank the options you are considering for their ability to deliver complete IQ OQ PQ documentation, from most to least confident. Options: Highest confidence, High, Moderate, Low, Not confident
      • What would have to be true about keeping your current approach for you to decide not to replace it?
      • Is anyone internally advocating for a do it ourselves approach instead of buying a validated platform, and if so who would sponsor that path? Options: Yes — internal sponsor identified, Yes — proposed but no sponsor, No internal build advocacy
      • If you decided to stay with the incumbent or build internally, what single risk would most likely force you to revisit that decision within 12 months?

      Who Signs Off and Who Picks Up the Work

      • Who are the people that must sign the commercial agreement and the validation plan before go live, and what are their roles?
      • List the day to day owners for document control, CAPA, training, and integrations and their functional areas.
      • Provide the headcount in each functional owner group and indicate who will require admin level access during and after deployment. Options: 1–3, 4–10, 11–25, 26–50, >50
      • Walk me through your escalation path for a critical quality event, who is notified, and typical response times at each step.
      • Identify any person or committee with veto power over implementation or validation decisions and how that invocation works. Options: Executive steering committee, Quality head only, Legal or compliance holds, No formal veto process

      What Success Looks Like in Practice

      • Imagine overdue CAPAs falling by 50% in six months, how would that change your release timelines and audit posture?
      • Name the primary quality KPIs you will use to judge a pilot and the first 12 months of deployment. Options: Open CAPAs, Average CAPA closure time, Overdue training percentage, Deviation closure time, Audit findings, User adoption rates
      • Within what timeframe do you expect measurable improvements—3 months, 6 months, or 12 months—and which is your target window? Options: 3 months, 6 months, 12 months, More than 12 months, Unsure
      • What single acceptance criterion would compel you to sign a commercial commitment immediately following a successful pilot?
      • Assuming the pilot misses the agreed KPI targets, what decision will you take: cancel, extend, or reallocate resources to fix gaps? Options: Cancel and walk away, Extend the pilot, Allocate additional internal resources, Re-negotiate acceptance criteria

      Can Your Infrastructure and Team Support This?

      • Do you have API access and a named owner for each integration the project depends on, for example MES, LIMS, ERP, and the supplier portal? Options: Yes, owners and APIs in place, APIs available but no owner assigned, APIs not available, Partially available
      • List the systems that must be integrated and whether standard APIs, custom connectors, or manual exchange will be required. Options: Standard API available, Custom connector required, File exchange, Manual transfer, We do not know yet
      • Provide the estimated record volumes to migrate by domain, for example controlled documents, training records, CAPAs, and supplier files.
      • Name the full time internal technical contact and summarize their experience with validated SaaS integrations.
      • Are there regulatory approvals, IT security gates, or legal reviews that regularly add months to projects at your site? Options: Yes, regulatory or legal reviews, Yes, IT security or SOC reviews, Both types, No major gates exist
      • Can you commit to provisioning API access and a named owner for every required integration within 8 weeks if needed? Options: Yes, No, Need more information

      Practical Acceptance Checklist and Timing

      • Identify the single nonnegotiable test, migration reconciliation, or regulatory signoff your team requires before accepting production go live.
      • Choose the validation deliverables you require the seller to deliver as part of IQ OQ PQ and handover. Options: IQ protocol and report, OQ protocol and report, PQ protocol and report, Traceability matrix, CSV/CSV to validated system mapping, Test scripts and results
      • State your target go live date or window and list any immovable regulatory deadlines tied to that date.
      • Detail the roles and teams that must complete training and the evidence you will accept for regulatory acceptance, for example signed certificates or LMS records. Options: Signed training certificates, LMS completion records, Manager attestation, Attendance logs with assessments
      • Describe the open risks or blockers that would stop procurement or the steering committee from approving funding today.
      • State the role and title of the person authorized to sign and commit budget immediately once acceptance criteria are met.
  2. Solution Experience

    Translate the customer's quality, compliance, and usability requirements into concrete workflows and validated outcomes using real scenarios.

    Solution Experience

    • Solution Experience Session
    • Confirm the current state and its cost
    • You confirm the demonstrated deviation-to-CAPA-to-change-control flow eliminates the manual handoffs and lost approvals you described.
    • Deliver a tailored workflow prototype and a draft validation evidence checklist for the tested scenario within five business days.
    • You agree on the IQ/OQ/PQ artifacts and acceptance criteria required for this workflow to be considered validated.
    • Walkthrough: Deviation to CAPA to Change Control using a real scenario
    • Provide one representative deviation record and any related change control and CAPA artifacts for use in the prototype.
    • Review validation evidence for the scenario (IQ/OQ/PQ expectations)
    • You confirm the sample integration and data migration boundaries needed to support the workflow proof and next steps.
    • List the integration endpoints to be included in the prototype and identify the technical owner contacts for each endpoint.
    • Integration and data migration example
    • Validate: Is this what you meant when you said you needed a single auditable workflow that prevents lost approvals?
    • Solution Experience Session
    • Solution Experience Deck
    • Solution Brief — Validated Quality Workflows
    • meeting
    • slides
    • document
  3. Solution Scope

    Define modules, responsibilities, integration endpoints, data migration boundaries, validation deliverables (IQ/OQ/PQ), and acceptance criteria.

    Scope Configuration

    • Configure Document Control Workflows
    • Configure Change Control Workflows
    • Configure Deviation and Nonconformance Workflows
    • Configure CAPA Management Workflows
    • Configure Complaint Handling Workflows
    • Configure Training Management and Records
    • Configure Supplier Qualification and Controls
    • Configure Audit Management and Schedules
    • Configure Part 11 Controls (e-signatures, roles, audit trails)
    • Configure Automated Escalations and Overdue Tracking
    • Build Quality Metrics Dashboards and Reports
    • Migrate Historical Quality Data and Documents from Source Systems
    • Deliver IQ/OQ/PQ Validation Protocols and Test Scripts
    • Integrate Platform with MES, ERP, and LIMS

    Scope Questions

    Configure Document Control Workflows

    • Do you require controlled lifecycle states for documents (draft, review, approved, archived) mapped to your SOPs? Options: Yes, No
    • Which document types (SOP, batch record, manufacturing protocol, analytical method, training material) must be supported by the document control module? Options: SOP, Batch records, Manufacturing protocols, Analytical methods, Training materials, Other
    • How many approval levels are typical for a controlled document in your organization (example: author -> QA reviewer -> department head -> release)? Options: 1, 2, 3, 4+
    • What current document identifiers (document number, revision code, effective date) must be preserved during migration and visible in the system?
    • Are there retention or archival periods defined in your SOPs or by EU GMP / 21 CFR that the document control workflows must enforce? Options: Yes, No

    Configure Change Control Workflows

    • Do you need change control workflows linked automatically to CAPA records and impacted SOPs? Options: Yes, No
    • Select the change categories to template (process, equipment, software, supplier, specification). Options: Process, Equipment, Software, Supplier, Specification, Other
    • Who signs off on high-impact changes (for example QA director, head of manufacturing) and should their role be enforced by role-based approvals?
    • How should you capture risk assessments on change requests (e.g., FMEA score, criticality tag, impacted batch ranges)? Options: FMEA score, Criticality tag, Impacted batch range list, Other
    • Specify any change freeze windows (for example annual shutdowns, regulatory submission hold periods) that must block change approvals.

    Configure Deviation and Nonconformance Workflows

    • Are deviations initiated from manufacturing batch records, lab LIMS events, or supplier nonconformance reports? Options: Manufacturing batch records, LIMS events, Supplier reports, Customer complaints, Other
    • List the deviation severity levels your SOPs use (for example minor, major, critical) and any objective thresholds tied to each level.
    • Provide the expected linkage between deviations and CAPA (for example automatic create CAPA when deviation severity >= major).
    • When a deviation references a batch ID, what reconciliation or traceability fields must appear (batch number, lot number, production date)? Options: Batch number, Lot number, Production date, Operator ID, Other
    • Indicate any regulatory reporting triggers from deviations (for example events reportable to FDA or EU competent authority within X days).

    Configure CAPA Management Workflows

    • Would you like CAPA creation to be triggered automatically from deviations, complaints, or audit findings? Options: Yes, No
    • Describe the CAPA lifecycle steps your organization uses (investigation, root cause, corrective action, verification, effectiveness check) and any required timeboxes.
    • What quantitative effectiveness metrics do you require on CAPA closure (for example recurrence rate, defect reduction percentage)?
    • Who is the escalation owner when a CAPA exceeds planned timelines (for example QA director, plant manager)?
    • Specify any templates or forms (investigation checklist, RCA form) that must be available within the CAPA workflow.

    Configure Complaint Handling Workflows

    • Do complaint records need to link to device complaint regulations or MDR timelines for reporting? Options: Yes, No
    • Which complaint intake channels do you use (email, portal, phone log, distributor reports) that must feed into the complaint workflow? Options: Email, Customer portal, Phone log, Distributor reports, Other
    • How should complaints be triaged (for example patient safety, functionality, labeling) and which triage categories require immediate escalation?
    • What fields are mandatory on complaint records for regulatory audits (for example complaint ID, product lot, adverse event indicator)?
    • Indicate whether complaint investigation workflows must auto-generate MDR or vigilance reports when thresholds are met. Options: Yes, No

    Configure Training Management and Records

    • Do you require automated training assignments based on role, SOP ownership, or completed CAPA items? Options: Yes, No
    • Specify the training evidence types you accept (e-signature, certificate upload, test score) for compliance audits. Options: E-signature, Certificate upload, Test score, Attendance log, Other
    • How often must recurring refresher training be enforced for critical roles (for example annually, biennially)? Options: 6 months, Annually, Biennially, Custom schedule
    • Who owns training curricula per department (for example quality manager, site training lead)?
    • Provide any required integration points to your LMS or HR system for user records and training completions.

    Configure Supplier Qualification and Controls

    • Are supplier qualifications driven by supplier questionnaires, audit results, or certificate of analysis (CoA) reviews? Options: Questionnaire, Supplier audit, CoA review, Other
    • List the supplier risk tiers (for example critical, preferred, approved) and the acceptance tests for each tier.
    • When supplier data changes (for example site, certificate expiry) how should the system notify stakeholders and gate purchases?
    • Specify required document attachments for supplier records (for example CoA, ISO certificate, audit report) and retention periods.
    • Indicate whether supplier corrective actions (from audits or CoA failures) should create linked CAPA items. Options: Yes, No

    Configure Audit Management and Schedules

    • Do you run internal, supplier, and regulatory audits that must be scheduled and tracked in the system? Options: Internal audits, Supplier audits, Regulatory audits, Other
    • Specify how audit findings should map to corrective actions and CAPA records in your current SOPs.
    • Provide the typical audit cadence for key processes (for example annual quality system audit, semiannual supplier audits).
    • Who approves the audit schedule and should approval be enforced via e-signature for 21 CFR Part 11 compliance?
    • Describe required audit reporting outputs (for example executive summary, finding severity distribution, open findings by owner).

    Configure Part 11 Controls (e-signatures, roles, audit trails)

    • Do you require full 21 CFR Part 11 compliance including electronic signature binding to printed name and reason? Options: Yes, No
    • Select the role-based access groups that must be enforced (for example author, reviewer, approver, QA release). Options: Author, Reviewer, Approver, QA release, Admin, Other
    • Specify the audit trail retention period mandated by your corporate policy or applicable regulation. Options: 2 years, 5 years, As long as product on market, Custom
    • Confirm whether you require enforced session timeouts, multi-factor authentication, or hardware token support for privileged users. Options: Session timeouts, Multi-factor authentication, Hardware token, None
    • Indicate any legacy electronic signature records that must be ported and mapped to the new user IDs during migration.

    Configure Automated Escalations and Overdue Tracking

    • Would you like automatic escalations for overdue CAPA, deviations, or document approvals? Options: Yes, No
    • How many escalation tiers should be configured (for example owner -> manager -> director) and what are the time thresholds for each?
    • Provide examples of overdue thresholds to enforce (for example task overdue after 7 days, CAPA verification overdue after 30 days).
    • Are email and in-platform notifications both required for escalations and overdue alerts? Options: Email only, In-platform only, Both
    • Specify any SLAs tied to overdue tracking that are audited (for example maximum closure time for high-risk CAPA).

    Build Quality Metrics Dashboards and Reports

    • Which KPIs are highest priority for your leadership team (for example CAPA aging, number of open deviations, training compliance rate)? Options: CAPA aging, Open deviations, Training compliance rate, Supplier nonconformances, Other
    • Describe any regulatory reporting templates you must produce (for example trending reports for inspections, quality metrics for management review).
    • Provide the desired dashboard audiences (for example site QA, corporate quality, operations) and any role-based data restrictions.
    • Indicate whether you require scheduled export formats (PDF for audits, CSV for analytics) and their cadence. Options: PDF, CSV, Excel, Other
    • Specify any metric thresholds that should trigger alerts or corrective workflows (for example training compliance < 90%).

    Migrate Historical Quality Data and Documents from Source Systems

    • Do you have legacy sources to migrate from (for example network drives with SOPs, legacy QMS exports, LIMS exports)? Options: Network drives, Legacy QMS export, LIMS export, Spreadsheets, Other
    • How many documents and records are in scope for migration (for example number of SOPs, number of batch records, number of training certificates)? Options: Fewer than 1,000 documents/records, 1,000-10,000, More than 10,000
    • Which identifiers must be preserved and reconciled during migration (for example document number, legacy user ID, legacy CAPA ID, batch number)?
    • What acceptance criteria will confirm migration completeness and reconciliation to legacy batch records and audit trails (for example 99% metadata match, manual reconciliation report)?
    • List any documents that are explicitly out of scope for migration (for example unapproved drafts, archived HR files).
  4. Mutual Commit

    Finalize commercial and legal terms, acceptance criteria, validation responsibilities, timelines, and dependencies required to proceed.

    Agreement Modules

    • Order Form / Subscription Agreement
    • Master Services Agreement (MSA)
    • Statement of Work (SOW)
    • Acceptance Criteria & Validation Test Plan
    • Validation Responsibility Matrix (VRM)
    • Regulatory Compliance & Validation Addendum
    • Data Processing and Security Addendum (DPA)
    • Service Level Agreement (SLA)
    • Change Order Agreement
  5. Deployment

    Operationalize rollout with readiness checks, execution, and outcome validation.

    1. Pre-Deployment Readiness

      Capture concrete readiness facts the deployment depends on — environments, site owners, access, target datasets, and regulatory contacts.

      Pre-Deployment Questions

      Environment and site access

      • Deployment scope — is this a single site/environment rollout, a multi-site rollout (please confirm number of sites), or a pilot then phased rollout? (This determines sequencing and resource allocation.) Options: Single site / single environment, Multiple sites — will provide per-site details, Pilot site first, phased rollout thereafter
      • Is the target production environment provisioned and accessible for the seller's deployment work? If not, select the current state (so we can schedule provisioning and cutover windows). Options: Yes — accessible now, Partial — only staging/test accessible, No — production not yet provisioned (date to be provided)
      • Site owners and environment contacts — for each site/environment, list the site name, the named site owner, and the IT contact (so we can schedule access and approvals).

      Data and configuration

      • Primary data migration scope — which record types must be migrated into the new system? Select all that apply (these choices drive migration sizing and mapping). Options: Document control metadata, Training records and completions, CAPA history, Deviation / nonconformance records, Change control history, Supplier / vendor records, Audit findings and corrective actions, Other (please specify)
      • Is a source-of-truth owner identified for each record type who will sign migration acceptance? (This person/role will approve migration verification.) Options: Yes — owners named (will provide), No — owners TBD, Central data team will own, Multiple owners per site
      • Are field-mapping decisions and migration acceptance criteria finalized, or will mapping workshops be required? (Indicate level of readiness so we can plan mapping sprints.) Options: Finalized — ready for migration, One mapping workshop required, Multiple mapping workshops required, Not started — need the seller's assistance

      People and ownership

      • Named deployment sponsor and primary buyer owner (name and role) — who has authority to approve Go/No‑Go decisions?
      • Per-workstream owners — provide the named owner or enter 'the seller-managed' for each: system configuration, data migration, integrations, validation, and training (one line per workstream).

      Timing, integrations, and constraints

      • External systems in-scope for integrations (select all that apply). We will request endpoint and credential readiness in DeploymentConfig. Options: ERP, MES, LIMS, Identity provider / SSO, E-signature system, Other (please specify)
      • For the in-scope integrations, is a named integration owner assigned and is a test endpoint available for initial integration testing? (This indicates whether integration work can start immediately.) Options: Yes — owner and test endpoint ready, Partial — owner assigned, endpoint pending, No — the seller's assistance required to coordinate
      • Validation readiness — is the IQ/OQ/PQ approach agreed and are responsibilities assigned (buyer, the seller, or third party)? (This determines validation scheduling and deliverable ownership.) Options: Agreed — buyer owns execution, Agreed — shared buyer/the seller responsibilities, Not agreed — decision required, Buyer's third-party validation vendor will execute
      • Site blackout windows or regulatory constraints that must be avoided during the rollout (e.g., audits, production freezes). If none, select 'None'; if yes, indicate 'Yes' and we will request dates/sites. Options: None, Yes — dates and sites to follow
    2. Configuration Details

      Lock exact configuration values the deployment team will use — integration credentials, API endpoints, field mappings, and validation test plans.

      Configuration Details

      ENVIRONMENTS & API ENDPOINTS

      • Enter the production instance base URL the deployment will configure (format: https://your-subdomain.example.com)
      • Enter the staging/UAT instance base URL to be configured (format: https://your-subdomain-uat.example.com). Enter NONE if not used.
      • Select the API version to lock for all environments (Default: v1) Options: v1 (default), v2, v3
      • Enter the system timezone that all timestamps, exports, and audit logs should use (Default: UTC — use IANA name, e.g., Pacific/Auckland)

      SSO / IDENTITY PROVIDER (IdP)

      • Select the identity provider type to configure for the buyer (Default: None) Options: SAML-based IdP, OIDC-based IdP, None (no SSO)
      • If using SAML or OIDC, enter the IdP metadata or discovery URL the platform should consume (format: https://... ). Enter NONE if IdP type is None.
      • Provide the technical contact email for the IdP administrator who will approve the service-provider configuration (format: name@domain)
      • Select how the integration secret (SP private key / client secret) will be exchanged at kickoff (we will not accept the secret in this sheet) Options: Your secrets manager (recommended), Secure deployment portal, Secure email to designated owner, Other — we will coordinate
      • Enter the name of the credential owner who controls the IdP secret (person or team name; e.g., 'IT Identity Team')

      CORE INTEGRATIONS — AUTH METHODS (MES / ERP / LIMS)

      • Select the authentication method you will use for MES integrations (choose a single value) Options: OAuth2 client-id (secret exchanged later), API key name (secret exchanged later), Service account username (secret exchanged later), Mutual TLS certificate name (certificate exchanged later), None — no MES integration
      • Enter the non-secret identifier for the MES credential chosen above (client-id, API key name, service account username, or certificate name). Enter NONE if no MES integration.
      • Select the authentication method you will use for ERP integrations (choose a single value) Options: OAuth2 client-id (secret exchanged later), API key name (secret exchanged later), Service account username (secret exchanged later), Mutual TLS certificate name (certificate exchanged later), None — no ERP integration
      • Enter the non-secret identifier for the ERP credential chosen above (client-id, API key name, service account username, or certificate name). Enter NONE if no ERP integration.
      • Select the authentication method you will use for LIMS integrations (choose a single value) Options: OAuth2 client-id (secret exchanged later), API key name (secret exchanged later), Service account username (secret exchanged later), Mutual TLS certificate name (certificate exchanged later), None — no LIMS integration
      • Enter the non-secret identifier for the LIMS credential chosen above (client-id, API key name, service account username, or certificate name). Enter NONE if no LIMS integration.
      • For any integration secret above, confirm the secrets manager or channel name where the secret will be stored or handed off (e.g., 'your secrets manager', 'deployment portal')

      INTEGRATION ENDPOINTS — TYPE & HOST

      • Select MES endpoint type (the deployment uses this to choose connector logic) Options: REST API (HTTPS URL), SFTP host (hostname or IP), JDBC/ODBC database (JDBC URL), None — not connecting to MES
      • If MES endpoint type is REST API, enter the MES API base URL (format: https://host.example.com/api). If not applicable enter NONE.
      • Select ERP endpoint type (the deployment uses this to choose connector logic) Options: REST API (HTTPS URL), SFTP host (hostname or IP), JDBC/ODBC database (JDBC URL), None — not connecting to ERP
      • If ERP endpoint type is REST API, enter the ERP API base URL (format: https://host.example.com/api). If not applicable enter NONE.
      • Select LIMS endpoint type (the deployment uses this to choose connector logic) Options: REST API (HTTPS URL), SFTP host (hostname or IP), JDBC/ODBC database (JDBC URL), None — not connecting to LIMS
      • If LIMS endpoint type is REST API, enter the LIMS API base URL (format: https://host.example.com/api). If not applicable enter NONE.

      FIELD MAPPINGS & MIGRATION FILES

      • Enter the file path or URL for the Document Control migration CSV that contains field mappings (format: /path/filename.csv or https://...). If no migration, enter NONE.
      • Enter the file path or URL for the CAPA migration CSV that contains field mappings (format: /path/filename.csv or https://...). If no migration, enter NONE.
      • Enter the file path or URL for the Training records migration CSV that contains field mappings (format: /path/filename.csv or https://...). If no migration, enter NONE.
      • Specify the date format used in all migration files (Default: YYYY-MM-DD) Options: YYYY-MM-DD (default), MM/DD/YYYY, DD/MM/YYYY, Epoch seconds
      • Primary key to use for migrated records (choose one — this value will be set in the migration mapping) Options: Source record ID (default), External system ID, Custom field — specify in mapping file

      FEATURES, WORKFLOWS & COMPLIANCE SETTINGS

      • Select which lifecycle modules to enable on go‑live (multi-select) Options: Document Control, Change Control, CAPA, Deviation/Nonconformance, Training Management, Supplier Qualification, Audit Management, Risk Management
      • Electronic signature enforcement level for regulated actions (Default: Enforce on approval only) Options: Enforce on approval only (default), Enforce on submit and approval, Enforce on final sign-off only, Disabled (not recommended)
      • Select default locale for the tenant (Default: en-US) Options: en-US (default), en-GB, de-DE, fr-FR, es-ES, Other — specify below
      • If you selected 'Other' for locale above, enter the locale code you require (format: ll-CC). Enter NONE if not applicable.
      • Default retention period for closed records and audit trails in days (Default: 3650 — 10 years)

      VALIDATION (IQ / OQ / PQ) — TEST PLAN LOCKS

      • Enter the validation owner role or person who will sign IQ deliverables (e.g., 'Quality Systems Lead')
      • Enter the validation owner role or person who will sign OQ deliverables (e.g., 'Validation Engineer')
      • Number of PQ scenarios to execute and lock into the PQ test plan (Default: 5)
      • Enter the file path or URL for the approved PQ scenario list (format: /path/filename.xlsx or https://...). If none yet, enter TBD.
      • Acceptance pass threshold for validation tests as a percentage (Default: 100) Options: 100 (default), 99, 95, Other — specify below
      • If you selected 'Other' for acceptance threshold, enter the numeric percentage (format: integer between 1 and 100). Enter NONE if not applicable.
      • Enter the repository path where validation evidence will be collected (format: https://... or /shared/path). This is the authoritative evidence location.

      DATA MIGRATION RUN & RECONCILIATION

      • Number of months of historical records to migrate into the system (Numeric — Default: 36)
      • Primary owner (person or role) for migration reconciliation (format: 'Name — Role' or team name)
      • Allowed reconciliation mismatch tolerance as a percentage of migrated records (Numeric — Default: 0)
      • Primary strategy for handling primary key conflicts during migration (choose one) Options: Abort on conflict (default), Skip duplicates and log, Source wins — overwrite target, Target wins — ignore source

      OPERATIONAL LIMITS & POLICIES

      • Maximum allowed concurrent user sessions per account (Numeric — Default: 5)
      • Minimum password length for locally managed accounts (Numeric — Default: 12). If using SSO only, enter 0.
      • Audit log retention period in days (Numeric — Default: 3650)
      • Select user provisioning method to configure (Default: CSV bulk upload) Options: SCIM (automatic provisioning), CSV bulk upload (default), Manual by admin

      CONTACTS, OWNERSHIP & SIGNOFFS

      • Enter the primary technical contact for integrations (Name — Role — email)
      • Enter the primary quality contact for validation and acceptance (Name — Role — email)
      • Enter the owner who will approve final configuration build for go‑live (Name — Role)

      FINAL CONFIG LOCK & DEPLOYMENT NOTES

      • Are you ready to lock these configuration values for the deployment build? (Once locked, changes require a configuration change request) Options: Yes — lock configuration, No — still collecting values
      • If there are any one-line special instructions the deployment build must honor (e.g., 'Disable automated notifications for pilot site'), enter that instruction here. If none, enter NONE.
      • Confirm you have not provided any secret values in this sheet and that all secrets will be exchanged via the selected secrets channel (Yes/No) Options: Yes — no secrets provided, No — there are secrets here (do not proceed)
    3. Deployment

      Execute the rollout with a sequenced plan for system configuration, data migration, integrations, training, and validation test execution.

    4. Go-Live Validation & Acceptance

      Verify IQ/OQ/PQ completion, migration reconciliation, training completion, and regulatory acceptance before declaring production go-live.

      Checklist items

      • Receive signed IQ/OQ/PQ completion reports
      • Archive validation artifacts in the agreed repository
      • Execute and approve final data migration reconciliation
      • Create verified production rollback point and test rollback
      • Complete full cutover dry run with signed checklist
      • Confirm training completion and update training records
      • Validate integrations and external endpoints in production configuration
      • Verify electronic signature and audit-trail functionality
      • Obtain written regulatory/compliance acceptance where required
      • Obtain per-site production readiness sign-off
      • Hold go/no-go approval meeting and capture production release authorization
  6. Success

    Run recurring outcome reviews, track issues and enhancement requests, and maintain a shared channel for continuous compliance and usability improvements.

    Success Reviews

    • Go-Live Health Check (weeks 1-4)
    • First Outcomes Review (weeks 4-10)
    • Operational Stabilization and Issue Triage (biweekly for first 3 months, then monthly)
    • Quarterly Outcome Review
    • Annual Compliance and Continuous Improvement Review

    Issues & Enhancements

    • Publish the quarterly outcomes summary showing metric trends against Solution Scope targets and the remediation tracker for any off-target metrics.
    • Ensure runbook updates and escalation contacts are current following recent incidents.
    • Publish the updated issue burn-down chart and the prioritized enhancement list after the meeting.
    • Execute agreed hotfixes and document validation retests required before closure.
    • Update the operational runbook to reflect any new escalation or recovery steps identified.
    • Outcome dashboard vs Solution Scope targets
    • Confirm whether the two primary outcome metrics are meeting the Solution Scope targets, or agree corrective remediation with timelines.
    • Verify audit readiness status, and identify any documentation or training gaps that must be closed before the next regulatory checkpoint.
    • Align on the prioritized backlog items that will be delivered next quarter to remove persistent blockers.
    • Re-confirm deployment scope and ownership
    • Produce an audit-readiness checklist with owners and completion dates for outstanding documentation and training items.
    • Lock the prioritized enhancement delivery window for the next quarter and list acceptance criteria for each item.
    • 12-month compliance performance summary
    • Agree a one-year plan to reduce audit finding recurrence and improve training completion, with measurable targets and milestone dates.
    • Identify and commit to resolving systemic root causes that drive recurring deviations or CAPAs.
    • Confirm inspection readiness activities and update the regulatory contact and escalation list as needed.
    • Deliver the annual compliance performance report with recommended systemic fixes and a timeline for implementation.
    • Publish the prioritized continuous-improvement roadmap for the next 12 months with milestone dates.
    • Update and distribute the inspection playbook and regulatory contact list.
    • Confirm there are no unresolved critical blockers preventing core QMS workflows from running in production.
    • Agree and document remediation actions and timelines for all high-severity issues discovered during cutover.
    • Verify that migration reconciliation checks and initial IQ/OQ test executions are scheduled or completed.
    • Publish the live-issue tracker with severity, short description, and target resolution date.
    • Run and deliver the migration reconciliation report for primary datasets within 72 hours.
    • Schedule any outstanding validation retests and document expected completion dates.
    • Present first outcome data vs Solution Scope targets
    • Establish whether average CAPA closure time (days) and training completion rate (%) are trending toward targets recorded in Solution Scope or require intervention.
    • Confirm incumbent system is either decommissioned or formally retained read-only and archived, with a remediation plan for any outstanding archive items.
    • Document a prioritized corrective action plan with completion dates for all identified root causes.
    • Deliver a corrective action register with descriptions, expected completion dates, and criteria for re-measurement.
    • Produce and circulate the legacy-archive verification report confirming data accessibility and retention approach.
    • Schedule targeted training refresh sessions for roles below the required training completion threshold.
    • Status of open high-severity issues
    • Reduce the open high-severity issues count and meet the agreed burn-down trajectory for hotfix tickets.
    • Prioritize enhancement requests that directly affect compliance or major usability blockers for the next delivery window.
    • Deployment and migration validation status
    • Recurring root causes and systemic issues
    • Hotfix and ticket burn-down review
    • Root cause diagnosis for gaps
    • Compliance readiness and audit indicators
    • Backlog and enhancement delivery review
    • Enhancement request triage
    • Continuous improvement backlog and resourcing needs
    • Incumbent system decommission and archive status
    • Early adoption signals and usage patterns
    • Persistent blockers and escalation items
    • Open issues and blockers
    • Agree corrective actions and success timeline
    • Regulatory contacts and inspection readiness
    • Short-term operational actions
    • Agree immediate remediation actions and timeline
    • Confirm next checkpoint and acceptance criteria alignment
    • Update runbook and escalation paths
First-Party AI

1-2 minutes please — Your AI agent is working

First-Party AI™ can make mistakes. Always check important information.