Governance

Goal: Understand how Open Industrial governance nodes provide ALCOA+ compliance for regulated industries.


What is Governance in Open Industrial?

Governance nodes provide regulatory compliance capabilities as first-class workspace features:

NodePurposeALCOA+ Principles
Audit Event LogAppend-only, hash-chained record of workspace configuration changesAttributable, Contemporaneous, Original, Complete
Amendment LogDocumented corrections with full traceabilityAttributable, Legible, Original, Accurate

In regulated industries (pharma, life sciences, manufacturing), every data change must be attributed, timestamped, and traceable. Open Industrial governance nodes satisfy 21 CFR Part 11 and EU Annex 11 requirements by design.


ALCOA+ Principles

PrincipleMeaningHow Open Industrial Satisfies It
AttributableWho performed the action?User identity on every event
LegibleCan the record be read and understood?Structured JSON with before/after diffs
ContemporaneousWas it recorded when it happened?Server-side timestamping (client timestamps rejected)
OriginalIs this the original record?Append-only event writes; immutable storage ships with the blob store
AccurateIs the record correct?E-signature hash verification
CompleteAre all actions captured?Platform captures all state changes automatically
ConsistentIs the format standardized?Standardized event schema across all actions
EnduringWill the record persist?Configurable retention policy
AvailableCan authorized users access it?Query API + CSV/JSON export

When to Use Each Node

ScenarioNodeWhy
"I need a record of everything that happened"Audit Event LogCaptures all state-change events
"I need to correct a value with documentation"Amendment LogReason-for-change workflow with chain traceability
"Compliance audit is coming"BothAudit trail + amendment evidence together

Getting Started

If you want to...Go to...
Set up an audit trailAudit Event Log →
Document correctionsAmendment Log →
Understand ALCOA+ termsGlossary →

Governance nodes work alongside your data nodes. The same canvas that manages connections and queries also manages compliance — no separate system, no export-and-import, no compliance afterthought.

On this page