I would like to know if anybody has managed to setup an FDA Part11 compliant Confluence system, e.g. for documenting medical devices. We are still working on this issue and I would be interested in sharing and discussing experiences.
Our requirements are:
- Traceability of any content change (who changed what and when)
- Predefined review workflows
- Ideally automatic generation of meaningful page/document ids
- Review steps that require finalization with electronic signatures
- Assurance that approved pages cannot be edited without losing their approval state.
We are using the latest Confluence version and the following plugins:
- Comalatech workflows (for review workflows with electronic signatures)
- ScrollPDF Exporter
This is how we organize our content:
- One space for each product and product version
- One document (e.g. Project Plan or Validation & Verification Plan) per Confluence page
- Each document/page is linked to a predefined Comalatech Workflow based review process with the states Editing (ends with Author approval), Reviewing (ends with Reviewer approval) and Approval (ends with Approver approval)
Our current challenges/ open issues:
If a document/page has been approved its content should be frozen. This means that as soon as the content is edited the document has to lose its Approved status. But how can the following issues be solved:
- An author can use macros that dynamically generate content when the page is loaded. So the content can change even the page is set to read-only. As a consequence, an approved page might display content that has not been subject of the review process and approval.
- You can refer to content of other pages, e.g. display an image that is an attachment of another page. Therefore, you can change the content of a read-only and approved page by updating the source image attached to the second page.
One idea to approach this problem is to automatically generate a PDF including information about the electronic signatures as soon as the page reaches the approved status. The PDF is static and cannot be changed easily. We would then argue that our employees should refer to the PDF files in their daily work and that Confluence is just used as a content editor. This is how we worked in the past (MS Word for editing document and generating PDFs files, which are printed out, signed by hand, scanned and archived in SVN and folders), but it is obviously not the way you would like to use a Confluence based system.
Has anybody managed to solve these issues or another idea how to approach this topic?
Best regards
Thorsten