Amendment Log

Goal: Document corrections to existing records with reason-for-change traceability, preserving the original record and maintaining a complete amendment chain.


What is an Amendment Log?

AspectDescription
PurposeDocument corrections with reason-for-change and full traceability
WorkflowSelect entity → choose reason category → enter justification → review diff → submit
OriginalOriginal records are never modified
ChainLinked-list history from original through each correction
ComplianceSatisfies ALCOA+ Attributable, Legible, Original, Accurate requirements

Original records are never modified. Amendments create new records linked to the original. The full chain is always traceable — from the first version through every correction.


Prerequisites

  • Workspace admin or editor permissions
  • Amendment Log node on the workspace canvas
  • (Recommended) Audit Event Log active for complete ALCOA+ coverage

Option A: Using the UI

Step 1: Add Amendment Log to Workspace

  1. Open workspace canvas
  2. Find Amendment Log in the Node Bank (scroll icon, under Governance)
  3. Drag onto canvas
  4. Name it (e.g., "production-amendments")
  5. Commit to activate

Step 2: Initiate an Amendment

When you need to correct a value:

  1. Select the entity to amend (e.g., a Connection, Surface configuration, etc.)
  2. Open Inspector → click Amend button
  3. The Reason-for-Change modal opens

Step 3: Document the Reason

FieldDescriptionRequired
Reason CategoryValidated dropdown (see categories below)Yes
JustificationFree-text explanationYes
Amended FieldsAuto-populated from the change diffAuto

Reason Categories:

CategoryWhen to Use
data-entry-errorTypo, wrong value entered
transcription-errorMisread from paper record or instrument
equipment-malfunctionSensor failure, device error
protocol-deviationProcedure or workflow change
recalculationFormula update, unit conversion
delayed-entryLate data entry from manual records
otherProvide detailed justification

Step 4: Review the Diff

Before submitting, review the field-level diff:

FieldOriginal ValueAmended Value
temperature.threshold72.575.0
humidity.alerttruefalse
Thinking Tip:

The diff shows exactly which fields changed and their before/after values. Review carefully — once submitted, the amendment is part of the permanent chain.

Step 5: Submit

Click Submit Amendment. The amendment is recorded with:

  • Your user identity
  • Server timestamp
  • Reason category + justification
  • Full field-level diff
  • Link to the previous version in the chain

Step 6: Browse Amendment Chain

Click the Amendment Log node → Inspector → search for an entity:

  • View the linked-list history showing original → amendment 1 → amendment 2 → ...
  • Each entry shows who, when, why, and what changed
  • Click any entry to see the full diff at that point in time

Two-Person Authentication (EU Annex 11)

When enabled on the Amendment Log node, corrections require a second signer:

How It Works

  1. User A submits an amendment with reason-for-change → Status: Pending
  2. User B reviews the amendment in the approval queue
  3. User B approves or rejects:
    • Approve → amendment becomes Approved, correction takes effect
    • Reject → amendment becomes Rejected, requires rejection reason

Maker/checker separation: the approver cannot be the same person who submitted the amendment. This is enforced at the API level — not just a UI constraint.

Approval Queue

The approval queue shows all pending amendments awaiting review:

ColumnDescription
EntityWhat was amended
Submitted ByWho submitted the correction
Submitted AtWhen the correction was submitted
ReasonCategory + justification
DiffField-level changes
ActionsApprove / Reject buttons

Status Lifecycle

[Submitted] ──→ Pending ──→ Approved (correction effective)
                   └──→ Rejected (with reason, preserved in chain)

Both approved and rejected amendments are preserved in the append-only chain. Rejected amendments document that a correction was proposed and why it was denied — this is itself compliance evidence.

Thinking Tip:

When two-person auth is NOT enabled, amendments are auto-approved at submission. Enable it in the IntegrationsModal → Governance tab for environments that require maker/checker separation.


How It Fits: Two Governance Gates

Open Industrial provides two distinct compliance gates for two categories of change:

What ChangesFirst GateSecond Gate
Recorded data (values, results, measurements)Amendment creation with reason-for-changeApprove/reject (this page)
Workspace configuration (nodes, connections, settings)Proposal → CommitDeploy with RequireDeployApproval

Both are fully audited. Track 4's Audit Event Log auto-captures every workspace state change — including proposal creation, commits, deploys, amendment creation, and amendment approval/rejection. You do not need to manually log any of these events.

Proposals do not need separate lineage. Every mutation to a proposal is a workspace state change, and the audit trail records who changed what and when. The audit log is the compliance record — proposals are work-in-progress.

Amendment Log governs corrections to recorded data. Audit Event Log governs everything. Deploy approval governs configuration promotion. Together: every change to every layer is documented, attributed, and traceable.


Option B: Ask Azi

Example prompts:

  • "Amend the temperature threshold on sensor-config-01 because of the Q2 calibration update"
  • "Show me the amendment chain for production-sensors"
  • "Who changed the alert configuration and why?"
  • "What corrections were made to brew-data this month?"

Original Record Preservation

[Original v1] ──→ [Amendment v2] ──→ [Amendment v3]
  (never modified)    (links to v1)     (links to v2)
PrincipleHow It Works
Original preservedv1 is never modified — amendments create new linked records rather than overwriting a field
Chain linkedEach amendment links to its predecessor
Tamper-evidentSHA-256 per-entity hash chain — any insertion, deletion, or reorder is cryptographically detectable
Full historyAny version can be retrieved by chain position
Diff availableEach amendment stores the exact field-level changes

This is the digital equivalent of "don't use white-out." Cross it out, write the correction next to it, initial it, date it, explain why. Same principle, digital execution.


Best Practices

  • Always select the most specific reason category (avoid "Other" when possible)
  • Write clear justifications that a compliance auditor would understand
  • Use Amendment Log alongside Audit Event Log for complete coverage
  • Review the diff carefully before submitting — amendments are permanent
  • Export amendment chains regularly for compliance archival

Next Steps

If you want to...Go to...
Set up an audit trailAudit Event Log →
Query amendments via APIREST API → Amendment Logs →
Understand ALCOA+ principlesGovernance Overview →
See the complete compliance picturePharma Factory Journey →

Corrections are a sign of good governance, not failure. What matters is that every correction is documented, justified, traceable, and the original is preserved. That's ALCOA+ in practice.

On this page