rotascale

Solutions — sector

Attributable, legible, contemporaneous — and now the actor is an agent.

This sector has held the strictest record-keeping discipline in commercial software for thirty years, and every part of it assumes a person. An agent acting inside a GxP estate has to be attributable to somebody, and "the model did it" is not a name.

EU AI Act · GDPR · GxP expectations Medicines regulators and notified bodies clause map
Status
High-risk under the AI Act where embedded in a medical device; GxP expectations apply independently
Applies to
Pharmacovigilance, clinical operations, regulatory affairs, manufacturing quality

Attribution is the requirement everything else hangs from

ALCOA has been the spine of this sector's record-keeping for a generation: attributable, legible, contemporaneous, original, accurate. Four of the five are properties of a document. The first is a property of an actor, and it is the one autonomous software breaks.

A service account is not attribution. It is the absence of attribution, written down. What a grant does is carry the chain: a named human signs for a bounded authority, an agent acts inside it, a delegate acts inside a subdivision of it, and every record cites the grant rather than the credential.

Delegation subdivides and never multiplies
A delegated grant cannot exceed its parent on scope, window, budget, conditions or enforcement mode — the API refuses to issue one that does. So a chain of agents cannot end up with more authority than the person at the top of it had.
Revocation reaches the whole chain
Revoking a parent revokes its children, and whether anything was allowed in the interval is answered rather than assumed.
The refusal is part of the record
An agent that was stopped is evidence the control operated. In an inspection that is the more useful half, and it is the half a system built only to log successes does not have.

What this is not

Rotascale makes no claim under 21 CFR Part 11, Annex 11, or any GxP predicate rule, and ships no clause map for them. Those are obligations on your quality system, discharged by your validation in your environment — not properties a vendor can confer. Nor does the platform make a clinical or safety judgement: it bounds what an agent may do and records what happened, and whether the outcome was right is a question for the people qualified to answer it.

The agents your teams are about to ship

The unifying problem is not accuracy. It is attribution: every one of these actions lands in a record that has to say who did it, and until now the answer was always a person with a login.

  1. 1 authority Is there any authority for this?
  2. 2 status Is the grant active?
  3. 3 window Is now inside the grant's window?
  4. 4 scope Does the grant cover this action?
  5. 5 clean_context Was the context clean, where that is required?
  6. 6 bounds Do the per-action limits hold?
  7. 7 policy Does the policy on the grant permit it?
  8. 8 budget Is there room under the ceiling?
  9. 9 review Does this need a person?
Nine gates, evaluated in this order before the action. The lit ones are the gates that hold the four agents below — which is what differs between one industry and the next. The order does not.
Pharmacovigilance triage agent clean_context

Ingests adverse event reports from literature, call centres and partners, deduplicates, codes to MedDRA, and orders what a safety physician sees first.

Consequential action
Deprioritises a case below the review threshold
What goes wrong
It reads a narrative from an untrusted source and lets the content steer the triage. This failure is silent by construction — nobody reviews the case that was never surfaced.
What is recorded
Which content was untrusted, where it entered the trajectory, and whether the prioritisation downstream of it was permitted to stand.
Regulatory submission agent authority

Assembles dossier sections from source documents and prepares responses to health authority questions.

Consequential action
Submits a document to a health authority
What goes wrong
A submission is an attributable act by the sponsor. An agent submitting under no named authority creates an obligation nobody signed for.
What is recorded
The named accountable person behind the grant, its scope, and its expiry.
Clinical trial monitoring agent bounds

Watches site data for protocol deviations and data quality signals, and raises queries to sites directly.

Consequential action
Issues queries to investigator sites
What goes wrong
A query rule that misfires does not produce one bad query, it produces four thousand across every site in the study, and the sponsor's relationship with its investigators is the casualty.
What is recorded
The bound, the volume attempted, and the refusal.
Manufacturing deviation agent scope

Drafts deviation and CAPA records from batch data and operator notes.

Consequential action
Writes to the quality management system
What goes wrong
Write scope drawn for drafting that quietly reaches approval or amendment. An agent that can edit a quality record is a different system from one that can draft into it.
What is recorded
Every write with the scope that permitted it, and the refusal of every write beyond it.

Ambition is the point of these: none of them is a chatbot. Each is an agent taking an action with a consequence somebody has to answer for — which is exactly the moment a bounded authority stops being paperwork and starts being the reason the project is allowed to ship.

What an inspector will ask

Not hypothetical questions. These are the ones that arrive in writing, with a deadline, and the honest answer to most of them is a query rather than a project.

Who performed this action?
A named accountable human signed the grant the agent acted under, and the decision record cites it. Attribution runs to a person, not to a service account or a model name.
Was the record contemporaneous?
Decisions are recorded at the moment they are made, sequenced, and Merkle-sealed. A gap in the sequence is detectable rather than a matter of trusting the log.
Can you prove the record has not been altered?
Inclusion proofs a reviewer can verify without access to your systems, and the disclaimer sits inside the signed payload — so removing it invalidates the signature.
Is this validated software?
That is your validation to perform, in your environment, against your intended use. The platform runs single-tenant inside your estate, which is what makes qualifying it possible; what it will not do is arrive claiming a validated state it cannot hold on your behalf.

Identifiers this deployment verifies here

Every one of these is a checksum, not a shape. The claim is “this is a valid national identifier and the check digits agree”, not “this looks like one” — which is why the count on a screen can be cited rather than caveated.

FamilyHow it is verified
National identifier (PL, BE, NO) — scheme-specific weighted checksum
US Social Security Number — structural rules only — asserted, not observed
Australian Medicare number — weighted check digit
EU VAT number — per-state check digit where the state publishes one
Bank account (IBAN) — mod-97 over the rearranged string

And what it does not look for. Names, addresses and dates of birth in free text carry no checksum, and finding them needs a model this deployment does not run. Neither are card numbers, medical record numbers, or national schemes beyond the three above. A clean screen means no verified identifier was found — never that the payload holds no personal data.

See it on your own problem

Bring the agent that writes into a GxP system. We will show you the attribution chain from a named human down to the delegate, and what the record says when the delegate exceeds its scope.

A walkthrough is a working deployment with your QA and computer systems validation leads in the room, not a slide deck — bring the agent you are most nervous about and we will put it behind a grant while you watch. If you would rather look first, the demo needs a work address and one click.