The Problem: Uncontrolled Access Rights in GxP Systems
Access rights to GxP-relevant directories are checked in every inspection. EU GMP Annex 11 requires system access to be restricted to authorised persons and changes to critical data to remain traceable. 21 CFR Part 11 additionally requires authority checks, that is evidence of who was permitted to perform which function.
In practice this control rarely fails on the rule, it fails on the evidence. Permissions grow over years, groups are nested, stand-in rights remain in place after a project ends. A manual review across several thousand folders is neither complete nor reproducible.
The evidence has to be available at any time, not only on the day of the audit. RADAR keeps the target versus actual comparison of permissions continuously up to date and documents every deviation with a timestamp and the account responsible.
RADAR: Automated Access Rights Monitoring
Use Cases for RADAR
Laboratory Data Management Systems
Raw data folders of chromatography and LIMS systems often sit on network drives whose permissions have grown over the years. RADAR checks who may write, delete and rename, and reports rights that the permission concept does not foresee.
Production Document Management
Batch records, SOPs and validation documents are subject to a release process. RADAR monitors the associated directories and documents when a permission was changed and by whom.
Quality Management Systems
QM data requires separate rights for authoring, review and approval. RADAR evidences that separation continuously and delivers the analysis that the periodic review demands anyway.
Scope of Delivery and Operation
RADAR is not shipped as a licence file, it is introduced. You receive:
- Survey of the directories to be monitored, with criticality assessment
- Target permission concept per directory, agreed between QA and IT
- Installation and configuration in your environment
- IQ and OQ documentation for RADAR as a GxP-relevant system
- Report templates for periodic review and inspection
- Operating SOP with roles, escalation paths and response times
The introduction is handled by the same people who are responsible for IT Administration and computerised system validation in GxP environments.
Regulatory Framework
Access control over electronic GxP data is explicitly required by both major frameworks.
- EU GMP Annex 11: requires access to be restricted to authorised persons, the management of privileges and an audit trail for changes to critical data.
- 21 CFR Part 11: requires access controls and authority checks, that is evidence that only authorised persons could use a system and perform specific functions.
- ALCOA+ principle Attributable: every action must be attributable to an identifiable, authorised user.
How these requirements fit together is described under Data Integrity and ALCOA+ Compliance.
