Skip to content

[C2] 21 CFR Part 11 electronic signatures #115

Description

@anmolg1997

Workstream: gxp | Estimate: 8d normal → 4d AI-assisted | Phase: 2 | MVP gate 🔴

Why

Every eBR competitor advertises this; reports cannot be finalized without it. §11.50/70/200/300: two components, name+time+meaning displayed, permanently record-linked.

Scope

  • Signing ceremony (re-auth + meaning selection)
  • Signature block on PDF reports; record-linked, non-detachable
  • Password policy + unauthorized-use detection hooks

Acceptance criteria

  • Signed report displays signer/time/meaning; record hash binds signature
  • Second component required at signing even with active session

From the enterprise-readiness backlog (codebase audit + pharma/GxP research + tooling survey, 2026-06-12).

Metadata

Metadata

Assignees

No one assigned

    Labels

    mvp-gateBlocks first POC salephase-2GxP + deploy — sellable POC (wk3-6)ws:gxpWS-C GxP Compliance Layer

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions