Electronic signatures¶
GxPValidate's electronic signatures are designed for 21 CFR Part 11 and EU GMP Annex 11.
What a signature records¶
Each signature records:
- the signer's printed name;
- the meaning: Authored, Reviewed, Approved or Executed;
- the date and time in UTC;
- the record's version;
- how the signer re-authenticated (password, SSO or passkey);
- a SHA-256 hash and the canonical text snapshot of exactly what was signed.
A signature counts only while that hash still matches the record. If the record changes, the signature stops counting, and the record shows content changed after signing. Signatures are write-once.
Re-authentication¶
Every signature re-authenticates the signer, even moments after signing in (Annex 11 §13.3, 21 CFR 11.200). Being signed in is never enough. Depending on how your organization signs in, you confirm with one of:
| Method | How it works | Offered when |
|---|---|---|
| Passkey | Confirm with a passkey (WebAuthn) on your device. The device must verify you with a fingerprint, face or PIN. | You have registered a passkey. |
| Password | Re-enter your password in the signing dialog. | Your account has a password and your organization does not enforce SSO. |
| SSO step-up | Choose Re-authenticate with SSO. Your identity provider opens (in a pop-up, or the whole page) and makes you sign in again; an existing IdP session does not count. Back on the signing page, choose Sign. | Your organization uses OIDC single sign-on. |
If more than one method is available, you choose. There is no "signed in recently" shortcut: each signature needs its own re-authentication. An SSO step-up must be completed within about 5 minutes and is good for one signature, on that record and action only.
Recording results in bulk (importing a pytest-gxp report, or recording an automated run) signs one execution per test after a single re-authentication.
If your organization enforces SAML single sign-on, register a passkey: SSO step-up is available for OIDC only, and enforced SSO turns off password signing.
The method is stored on the signature. For a passkey, the signature also records which passkey was used, that the device verified you, and the passkey's signature counter.
Register a passkey¶
Open Passkeys in your user menu and choose Add passkey. You re-authenticate first, then follow your browser's prompt. You can register several (for example a laptop and a phone). Remove deactivates a passkey so it can no longer sign; signatures already made with it are unaffected.
Independence¶
- An author cannot review or approve their own document.
- Review must be signed before approval.
- A rejection or a revision invalidates earlier signatures on the document.
- The person who raised a deviation cannot close it.
Locks¶
Locks are enforced on the data itself, not only on the screens:
- Documents in review or approved, and their requirements and test cases, cannot be edited.
- Executions, evidence and signatures are write-once.
- A closed deviation cannot be edited.
Part 11 and Annex 11 controls¶
| Control | How GxPValidate meets it |
|---|---|
| Signature manifestation (11.50) | Printed name, meaning and UTC time on every signature, shown with the record and in print/PDF. |
| Signature/record linking (11.70) | SHA-256 hash and text snapshot of the signed content; the signature counts only while the hash matches. |
| Re-authentication (11.200, Annex 11 §13.3) | Every signature re-authenticates by password, SSO step-up or passkey. |
| Audit trail (11.10(e), Annex 11 §9) | Every change recorded with user, time, reason for change and field-level diff. |
| Authority checks (11.10(g)) | Per-system roles; authors cannot approve their own work. |
| Session control (Annex 11 §12) | Sessions end after a configurable idle time (default 30 minutes). |
| Automated agents | AI assistants over MCP can edit drafts but can never sign. See MCP. |
Validating GxPValidate for your intended use, and the procedural controls around it (training, account management, signature agreements), remain your responsibility.