Data integrity is not an audit-trail report and it is not a slogan attached to electronic records. It is the ability to trust that the evidence used for a GxP action is complete, contemporaneous, attributable, preserved in its original context, and reviewed at the point where it can still influence the decision.
Seal connects the regulated activity, record, source system, audit event, user, role, reason, before-and-after value, raw data, review obligation, exception, investigation, affected population, and final decision. Reviewers assess what changed and what it meant—not thousands of isolated technical messages.
FDA's data integrity and drug CGMP guidance frames the control problem across the full data lifecycle and supports a risk-based strategy grounded in process and system understanding.
Start with the regulated record universe
The program identifies manufacturing, laboratory, quality, engineering, warehouse, and clinical records that support product quality or a regulated decision. Each record class retains its authoritative system, owner, creation path, dynamic or static form, retention, review requirement, criticality, and applicable procedure.
Interfaces, calculations, temporary storage, local instrument computers, exports, spreadsheets, and manual transcriptions remain inside the data flow. A polished final report does not erase the systems and transformations that produced it.
The data-flow map exposes where meaning can be lost
For each record class, Seal maps acquisition, transfer, processing, calculation, review, approval, reporting, archival, retrieval, and deletion controls. The map identifies where metadata can separate from content, where manual intervention occurs, and which copies are authoritative.
Validation and periodic review use the same map. A new interface, instrument software upgrade, archival change, or report configuration immediately identifies affected records, controls, and tests.
Criticality determines the review design
Risk is based on the decision supported, ability to detect an improper change elsewhere, opportunity to alter or omit data, system control strength, process frequency, and patient or product consequence. The assessment defines which audit trails require event-level review, when, by whom, and with what supporting context.
Risk-based does not mean optional. It means the review obligation and depth are justified against the actual record and process.
Audit-trail review belongs beside record review
A batch step, analytical sequence, calculation, specification decision, master-data change, or disposition should be reviewed with its relevant audit events. Seal presents the executed record and its history together, with critical changes surfaced before approval.
The reviewer does not sign a generic monthly log while the underlying batch is released elsewhere. Completion of the required audit-trail review becomes an explicit gate on the relevant record or decision.
Context separates normal work from consequential change
The same technical event can mean different things. Reprocessing chromatography after an approved method update differs from changing integration after an unexpected result. Voiding a duplicate sample differs from deleting the only failing preparation.
Seal resolves the user, role, record state, workflow step, reason, related deviation, result history, contemporaneous source data, and downstream use. Rules can prioritize changes to results, calculations, specifications, methods, identities, timestamps, permissions, sequence composition, and reportable status.
The original and every consequential version remain visible
Before-and-after values, timestamps, electronic signatures, reasons, source references, and system-generated identifiers are preserved. Where the source produces vendor-specific audit data, Seal retains the source record and normalizes only the review context.
Reprocessing, reintegration, recalculation, repeat testing, result invalidation, and report regeneration remain distinguishable. A current value never obscures how the record reached that state.
Dynamic records stay dynamic
Chromatograms, spectra, images, plate maps, calculations, and configurable reports can require more than a PDF rendering. The data-integrity plan identifies which native data, metadata, methods, software context, and viewing capability must remain available to reconstruct the activity.
Static renditions can support inspection and long-term access, but they are labeled as renditions and linked to the preserved authoritative record.
Access control is evaluated against actual capability
Accounts, roles, privileges, administrator activity, shared-account exceptions, failed logins, disabled users, service accounts, and periodic access certification connect to systems and regulated functions. The review asks what a role can do—not merely what its name implies.
Conflicting abilities such as executing and approving, changing methods and testing samples, or administering and reviewing audit trails can be identified and assessed. Emergency access has a bounded duration and retrospective review.
Time and identity must survive system boundaries
Audit evidence records time source, time zone, clock synchronization, originating system, transferred identity, service account, and interface transaction. Reviewers can distinguish when the event occurred, when it arrived, and when it was committed.
Identity mapping remains controlled when personnel, directories, instruments, and applications use different identifiers. A transfer by a service account retains the human or upstream process responsible for the source action.
Exceptions are triaged, not silently filtered
A rule can classify expected system events, review-required events, known technical noise, and potential integrity signals. Suppression rules are versioned, justified, tested, approved, and periodically challenged against omitted events.
The review queue records why an event was accepted, linked to another record, escalated, or determined not applicable. Repeated low-severity exceptions can become a trend even when no single event triggers investigation.
Investigations preserve the original concern and scope
An integrity investigation starts with the signal, systems, users, records, time window, products, studies, and decisions potentially affected. Access logs, audit trails, source files, backups, interviews, procedures, training, system configuration, and comparable activity attach without replacing the original allegation.
Scope expansion and narrowing retain evidence and approval. The conclusion distinguishes data error, procedural failure, control weakness, intentional behavior, system defect, and inconclusive evidence without turning “human error” into an endpoint.
Periodic review tests the control system
The review combines access certification, audit-trail completion, exception patterns, deviations, incidents, backup and restore evidence, interface failures, configuration changes, unresolved records, archival retrieval, vendor issues, and CAPA effectiveness.
It asks whether the data flow and control design remain valid, whether review rules still capture meaningful events, and whether the actual volume can be reviewed with the assigned resources.
Migration and archival are regulated transformations
Migration defines source and target populations, fields, metadata, relationships, transformations, excluded records, reconciliation, testing, exceptions, approval, and rollback. Counts alone do not prove that content and meaning survived.
Archives retain integrity checks, format, viewer requirements, index, legal hold, retention, access, restore tests, and disposition authorization. Retrieval is periodically demonstrated using representative difficult records.
Source systems remain authoritative for native evidence
Instrument software should retain acquisition data and vendor audit trails; controllers and historians should retain dense process history; identity systems should control authentication. Seal does not pretend to recreate those technical records.
It orchestrates the regulated record map, review obligation, contextual evidence, exception handling, investigation, impact, and approval across them. Source links and verified copies remain explicit.
Where Seal is strongest
Seal is strongest when the evidence crosses LIMS, MES, QMS, SDMS, equipment, and identity systems. Because the batch, test, method, specification, user, instrument, deviation, and disposition are related objects, an audit event arrives with the work it can affect.
That reduces two common failure modes: reviewing an enormous log without context, and releasing the record without reviewing the events that matter. If the need is only immutable file storage, an SDMS may be sufficient; if the need is defensible cross-system review and impact, the connected model is the advantage.
Prove one difficult record end to end
The first implementation should follow a chromatographic assay from sample and sequence through raw acquisition, processing, reintegration, calculation, result review, audit-trail review, OOS assessment, batch disposition, archival, and later retrieval.
Include a deleted injection, trial sequence, changed processing method, clock drift, shared-account concern, late reason entry, interface retry, disabled audit trail, restored backup, and migrated historical record. The program is credible when each event can be interpreted in context and every affected decision can be found.
