Bind the exact action
Authorization is bound to this batch, this subject, this protocol version, this system change — not to a role or a standing permission.
In a regulated environment the costly failure is not an unlogged action — it is an unauthorized one that already reached the validated system. AtlaSent decides whether the organization authorized an exact regulated action before it executes, and preserves evidence of that decision that a reviewer can verify without trusting us.
Where the gap is
A change control, an approval routing, a training record, an audit trail — all of these establish that a process was followed. None of them structurally prevent an action from reaching a validated system when current authority is incomplete, stale, or not bound to the exact change. That distinction is what an inspector is actually probing.
Authorization is bound to this batch, this subject, this protocol version, this system change — not to a role or a standing permission.
A missing approval, an expired authority, or a changed material field refuses the action rather than logging it after the fact.
A hash-linked, signed record an auditor verifies with a source-open offline tool, without trusting AtlaSent’s servers or our word.
Regulated actions
Batch release. Clinical unblinding. Protocol amendment. Validated-system change. Patient-linked data export. Each is routed through the same evaluate → permit → verify → evidence path before it reaches the regulated system, whether the actor is a person, a workflow, or an AI agent.
Prove an authorized action can proceed, an unauthorized action is refused, missing approval is refused, and changed or replayed work is refused. Evidence should show exactly which stage was established.
What we claim, and what we do not
AtlaSent supplies enforcement and evidence properties that map to specific requirements in 21 CFR Part 11, EU GMP Annex 11, and ICH E6(R3) — for example, that a record is attributable to a verified actor, that it is bound to the exact operation, and that it is tamper-evident and independently verifiable.
We do not claim, and you should not repeat, that AtlaSent is Part 11 compliant, Annex 11 validated, or certified. Compliance is a property of your validated process and your documented qualification of it, not of a vendor’s product. AtlaSent is a control inside that process and an evidence source for it; the mapping is stated so your QA function can qualify it, not so it can be skipped. Framework references are alignment mappings pending our own counsel review — ask us for the current status rather than inferring it from this page.