rotascale

Blog

A Service Account Is Not a Person

TL;DR: Life sciences has the strictest record-keeping discipline in commercial software, and it was designed around people. Attributable is the first letter of ALCOA and the only one that is a property of an actor rather than a document. Autonomous software breaks it, and the usual answer, a service account, is the absence of attribution written down.

Four of the five are about the document

Attributable, legible, contemporaneous, original, accurate. Every quality professional in this sector can recite it, and computerised systems have been validated against it since before most of the people reading this were qualified.

Look at what each one constrains. Legible is about the record. Contemporaneous is about when the record was made. Original is about which copy is authoritative. Accurate is about whether it is right.

Attributable is different. It is not a property of the record at all. It is a claim about who performed the act, and the record merely carries it. Every control built around it, from unique logins to prohibitions on shared credentials to the requirement that an electronic signature identify the signer, exists to keep that claim true.

Autonomous software is the first thing in thirty years that breaks the assumption underneath the whole structure, which is that there was a person.

What a service account actually says

An agent writes a deviation record. The audit trail says the record was created by svc-quality-automation.

Read that as an attribution claim and it says: this was done by a credential, held by an unspecified number of systems, on behalf of nobody in particular, at the behest of whoever most recently deployed something that uses it.

That is not a weak attribution. It is an anti-attribution. It records precisely the fact that we do not know who is responsible, in a field designed to record who is responsible.

An inspector who understands this will ask one question, and it is not hostile: walk me from this record to a person. If the walk goes through a service account it stops there, and the next stop is the deployment ticket, and the stop after that is whoever approved the change, and by then you are discussing whether your quality system covers autonomous agents at all.

The chain that answers it

The structure that works is not complicated, and it will be familiar to anyone who has thought about delegated signing authority.

A named accountable person signs for a bounded authority: this agent may do this thing, within these limits, until this date. That authority is an object with an identity, not a role in a config file.

When the agent acts, the record cites the authority, not the credential. Attribution runs record to grant to person, and the walk terminates where it should.

When the agent delegates, and in a pharmacovigilance pipeline it will, the delegated authority is a subdivision of its parent. Narrower on every dimension, wider on none. Which means the chain of custody holds however many hops it takes, and a chain of five agents cannot end up with more authority than the person at the top of it had.

That last property is the one that matters for inspection readiness. Without it, every hop is a place where the walk can stop.

Contemporaneous is easier to claim than to prove

The second requirement worth dwelling on, because it is where most systems are weaker than they think.

Contemporaneous means the record was made at the time of the act. Most audit trails demonstrate this with a timestamp, which is a claim the system makes about itself. It is trusted because the system is validated, and that is a reasonable position for a system where a human pressed a button.

It is a weaker position when the actor is software that runs continuously and writes at machine rate. The question shifts from “is this timestamp right” to “is anything missing”, and a timestamp cannot answer that. A record can be absent without leaving a hole.

Sequencing can. If records carry a monotonic position and the positions are sealed, a gap is detectable. Not “we have no reason to think anything is missing” but “nothing is missing, and here is why”. Merkle sealing with inclusion proofs takes it one step further, so a reviewer can verify a specific record belongs to the sealed set without access to your systems at all.

That is a genuinely stronger claim than any audit trail makes today, and it is available because the volume that made the problem worse also made the mechanism affordable.

The four places it bites first

Pharmacovigilance triage. An agent reads case narratives from literature, call centres and partners, and orders what a safety physician sees. It is reading text that other people wrote, which means it is reading text that can address it. The failure is silent by construction: nobody reviews the case that was never surfaced. Whether a deprioritisation happened downstream of untrusted content is the thing the record has to say.

Regulatory submissions. A submission is an attributable act by the sponsor. An agent that can submit under no named authority has created a sponsor obligation nobody signed for.

Trial monitoring. A query rule that misfires does not produce one bad query. It produces four thousand across every site in the study, and the casualty is your relationship with the investigators. This is a bounds problem, and bounds is a limit on scale rather than on kind.

Manufacturing deviations. Write scope drawn for drafting that quietly reaches amendment. An agent that can edit a quality record is a different system from one that can draft into it, and the difference is one scope string.

What we will not claim

It would be easy to write that this makes you Part 11 compliant, or Annex 11 compliant, and vendors do write that.

It is not true and it is not ours to say. Those are obligations on your quality system, discharged by your validation, in your environment, against your intended use. Software runs single-tenant inside your estate, which is what makes qualifying it possible, and that is the honest limit of what a vendor contributes.

Nor does any of this make a clinical or safety judgement. It bounds what an agent may do and records what happened. Whether the outcome was right is a question for people qualified to answer it, and any product suggesting otherwise is selling you a feeling.

The bottom line

This sector already knows how to run software that keeps a defensible record. What it has not had to solve is a record whose first letter assumes a person, produced by something that is not one.

The fix is not a better audit trail. It is deciding, in advance and in writing, which human is accountable for what the agent may do, and making every record cite that decision rather than a credential.

Newsletter

If this was useful, the next one is too.

Notes on agent governance, what the regulations actually say, and what we are building. Roughly monthly. Double opt-in, no tracking, and unsubscribing takes one click and asks you nothing.

RSS works too and needs nothing from you · What happens to your address