Products

RADAR: Automated Monitoring of File Access Rights in GxP Systems

RADAR monitors file and folder permissions in GxP directories automatically. The in-house development by cube one GmbH continuously compares actual rights against the approved target state, logs every change and produces the access evidence required by EU GMP Annex 11 and 21 CFR Part 11.

In-house development by cube one GmbH

The Problem: Uncontrolled Access Rights in GxP Systems

Access rights to GxP-relevant directories are checked in every inspection. EU GMP Annex 11 requires system access to be restricted to authorised persons and changes to critical data to remain traceable. 21 CFR Part 11 additionally requires authority checks, that is evidence of who was permitted to perform which function.

In practice this control rarely fails on the rule, it fails on the evidence. Permissions grow over years, groups are nested, stand-in rights remain in place after a project ends. A manual review across several thousand folders is neither complete nor reproducible.

The evidence has to be available at any time, not only on the day of the audit. RADAR keeps the target versus actual comparison of permissions continuously up to date and documents every deviation with a timestamp and the account responsible.

RADAR: Automated Access Rights Monitoring

Automated Scanning
Recurring scan of all configured directories, including nested groups and inherited rights, against the approved permission concept.
Compliance Reporting
Reports on the current state of all access rights, ready for periodic review, internal audit and regulatory inspection.
Alerting & Escalation
Notification on deviation from the target state, with configurable escalation levels and defined response times.
Audit Trail
Logging of every change to access rights with timestamp, previous and new permission and the executing account.

Use Cases for RADAR

Laboratory Data Management Systems

Raw data folders of chromatography and LIMS systems often sit on network drives whose permissions have grown over the years. RADAR checks who may write, delete and rename, and reports rights that the permission concept does not foresee.

Production Document Management

Batch records, SOPs and validation documents are subject to a release process. RADAR monitors the associated directories and documents when a permission was changed and by whom.

Quality Management Systems

QM data requires separate rights for authoring, review and approval. RADAR evidences that separation continuously and delivers the analysis that the periodic review demands anyway.

Scope of Delivery and Operation

RADAR is not shipped as a licence file, it is introduced. You receive:

  • Survey of the directories to be monitored, with criticality assessment
  • Target permission concept per directory, agreed between QA and IT
  • Installation and configuration in your environment
  • IQ and OQ documentation for RADAR as a GxP-relevant system
  • Report templates for periodic review and inspection
  • Operating SOP with roles, escalation paths and response times

The introduction is handled by the same people who are responsible for IT Administration and computerised system validation in GxP environments.

Regulatory Framework

Access control over electronic GxP data is explicitly required by both major frameworks.

  • EU GMP Annex 11: requires access to be restricted to authorised persons, the management of privileges and an audit trail for changes to critical data.
  • 21 CFR Part 11: requires access controls and authority checks, that is evidence that only authorised persons could use a system and perform specific functions.
  • ALCOA+ principle Attributable: every action must be attributable to an identifiable, authorised user.

How these requirements fit together is described under Data Integrity and ALCOA+ Compliance.

RADAR FAQ

Why is monitoring access rights in GxP systems so important?
Inspectors check whether access to GxP-relevant systems is restricted and whether the evidence is documented. Without documentation the control counts as unproven. Unclear permissions are therefore among the common data integrity findings.
How frequently does RADAR scan the configured directories?
The scan interval is set per directory, from continuous monitoring to a periodic scan. The frequency follows the criticality of the data and is justified in the permission concept.
Which systems and operating systems are supported?
RADAR is designed for Windows environments and reads permissions from Active Directory as well as local NTFS rights. For different infrastructures we assess the connection beforehand.
Does RADAR itself have to be validated?
Yes. RADAR produces evidence for GxP decisions and is therefore a computerised system under Annex 11. We supply the validation documentation and carry out installation and qualification in your environment.

Next Step: RADAR Demo

Tell us the number and type of directories to be monitored. We show the target versus actual comparison on an example from your environment.