QA Pack

For your QA review

A working summary of TrainSync's intended use, audit trail, e-signature controls, and Part 11/Annex 11 mapping — structured for QA managers preparing a validation assessment.

Status: drafting. The full validation pack (URS, IQ, OQ, PQ scripts, traceability matrix) is in active drafting with a Q3 2026 target. The framework below is what we share with customers today. Anything labelled "drafting" or "planned" is honest about scope. For a working session on your specific validation requirements, book a 30-minute call.

🎯Intended useLive

TrainSync is the GxP training operations layer for pharma and biotech manufacturing teams. Its intended uses are:

TrainSync is not intended to:

📐GAMP 5 categorisationDraft

Our preliminary view, subject to customer QA assessment: TrainSync is best characterised as GAMP 5 Category 4 (configured product).

If your QA framework places SaaS training tools differently (e.g., Cat 4 + Cat 5 hybrid for the signature workflow), we will document it according to your conventions during the validation engagement.

📜Audit trail mechanismLive

The audit trail is implemented at the database layer using PostgreSQL triggers, not at the application layer. This means a user, even an administrator, cannot bypass the audit trail by issuing a direct API call.

AspectImplementation
Tables auditedpeople, trainings, sessions, enrollments, person_trainings, signature_documents, signature_steps
Actions capturedinsert, update, delete, sign, na, reassign, override
Fields per entrytable name, record ID, action, actor (resolved to internal person), before/after JSON, IP address, server timestamp, tenant ID
Mutabilityappend-only at the policy layer (no UPDATE or DELETE policy on audit_log)
Timestamp sourceDatabase server time (UTC). RFC 3161 trusted timestamping available on request.
Audit reviewPlanner and admin roles can read audit entries via SQL or planned audit-views UI (Week 3-4)

✍️E-signature control matrixDrafting

Mapping of TrainSync's signature workflow against 21 CFR Part 11 §11.50, §11.70, and §11.200:

ControlPart 11 referenceStatus in TrainSync
Unique user identity§11.200(a)(1)Live — Clerk enforces unique email per user
No shared accounts§11.200(a)(2)Live — enforced by Clerk; customer SOP required
Re-authentication at signature§11.200(a)(1)(ii)Drafting — currently uses active session; password re-prompt is on the roadmap
Signature meaning§11.50(a)(2)Live — each step captures role and label (trainee, trainer, supervisor, QA)
Printed name + date/time§11.50(a)(1)Live — captured automatically from authenticated user
Permanent link to record§11.70Live — signature steps are foreign-keyed to signature_documents and cannot be migrated independently
Audit trail of changes§11.10(e)Live — database-level trigger
Authority checks§11.10(g)Live — role-based access control via RLS
Reason for change§11.10(e)Live — N/A rationale, reassign reason, override reason all captured

Customer QA validates each control during the validation engagement.

🇪🇺EU GMP Annex 11 mappingDrafting

Mapping against the most frequently cited Annex 11 paragraphs:

Annex 11 paragraphTopicStatus in TrainSync
4 (Validation)System validationCustomer responsibility; validation pack drafting in Q3 2026
7 (Data)Data integrityLive — ALCOA+ controls (Attributable, Legible, Contemporaneous, Original, Accurate)
8 (Printouts)Printable copiesCSV/XLSX live; PDF in beta (Week 2)
9 (Audit trails)Audit trailLive — see audit trail section above
10 (Change & configuration)Change controlCustomer SOP required; TrainSync change log via Changelog page
12 (Security)Access controlLive — RBAC, RLS, Clerk authentication
13 (Incident management)Incident handlingDrafting — formal policy is a Week 4 deliverable
14 (Electronic signature)E-signatureSee e-signature control matrix above
17 (Archiving)Long-term archival5+ year retention; data export on request

Data retentionLive

See the data retention table in our privacy policy. Summary:

📋Template versioningDrafting

TrainSync's signature templates support versioning. Each completed record is linked permanently to the template version used at the time of signing. Templates can be:

Template approval workflow (with electronic signature for template approval itself) is a Q3 2026 roadmap item.

📦Validation pack (URS / IQ / OQ / PQ)Q3 2026

The full validation pack is in active drafting. Target completion is Q3 2026. It will include:

Until the pack is published, we share what's drafted on request during validation engagements.

Need this in a specific format for your QA team?

Validation packs, e-signature questionnaires, and Part 11 / Annex 11 mappings can be tailored to your organisation's framework. Book a 30-minute call and we'll plan the engagement.

Book a QA conversation →