ALCOA++ Coverage Matrix

Open Industrial provides two governance nodes that supply the evidence the ALCOA++ data integrity framework asks for. Whether a given deployment satisfies a principle is a determination its auditor makes.


Overview

Open Industrial provides two governance nodes that together answer the questions ALCOA++ asks of a record: what changed, who changed it, when, and why. Add the node and capture is automatic. Both are built into the platform. Records are held in Azure Blob Storage under a time-based immutability policy, isolated per workspace and per scope by container, and provisioned into the customer's own Azure subscription — so the records sit in their tenancy rather than ours.

NodePurpose
Audit Event LogAppend-only, hash-chained record of workspace configuration changes
Amendment LogDocumented corrections with reason-for-change traceability

ALCOA++ Coverage Matrix

PrincipleAudit Event LogAmendment LogTogether
AttributableUser identity on every eventUser identity on every amendmentEvery action and correction attributed
LegibleStructured JSON, before/afterReason category + justification + diffHuman-readable records with context
ContemporaneousServer-side timestampServer-side timestampAll records timestamped at time of action
OriginalAppend-only event writes (create, never upsert; a duplicate event ID is rejected). Immutable storage ships with the blob storeOriginal record preserved, never overwrittenFirst recording always accessible
Accurate (data)SHA-256 digest recomputed and its predecessor chain walked by a server-side verify endpointSHA-256 per-entity hash chain; WORM storage ships with the blob store. Approve/reject workflow enforces maker/checker separation on data corrections, server-side.Both event and amendment cryptographically verifiable; data corrections require a documented reason + second-signer approval
Accurate (config)Configuration commits captured as before/after eventsDeploy gate enforcing proposer != deployer is not built yetCommitted configuration changes are attributed, timestamped and chained
CompleteConfiguration commits across the tracked workspace collections are captured automatically -- no logging code to rememberEvery amendment requires a validated reason for changeRecorded changes carry attribution, timing and a reason
ConsistentStandardized event schemaStandardized amendment schemaUniform format across all actions
EnduringRetention periods configured per workspace (7/15/30 year and indefinite presets), with a floor keeping the configuration trail longer than the records it governs. Policy enforcement ships with the blob storeChain retained alongside the amendmentsRecords persist and are exportable for off-platform archival
AvailableQuery API + CSV/JSON exportChain query API + exportAll records accessible to authorized users
TraceableSHA-256 hash chain provides ordered sequence of all activitiesPer-entity amendment chain provides ordered sequence of all corrections per entityCryptographically verifiable chain of custody for every action and correction
TransparentOpen, queryable audit event API with CSV/JSON exportReason-for-change documents methodology; approve/reject documents governanceNo hidden processes. Complete, documented methodology

Open Industrial provides mechanisms for all 11 ALCOA++ principles, including the Traceable and Transparent principles that draft EU GMP Chapter 4 (July 2025) is formalizing into regulation.

Standards This Maps Against

These are the regulatory frameworks the governance nodes are designed against. Listing a standard here is not a claim of certification or validated compliance.

StandardScope
21 CFR Part 11FDA - Electronic Records; Electronic Signatures
EU Annex 11Computerised Systems
ICH Q7Good Manufacturing Practice for Active Pharmaceutical Ingredients
GAMP 5Good Automated Manufacturing Practice
EU AI ActAI governance for regulated industries (enforcement begins August 2026)
ICH E6(R3)Data Governance for Clinical Trials (finalized 2025; live in EU July 2025, US September 2025, Canada April 2026)
EU GMP Chapter 4 draftALCOA++ codification (July 2025)
EU Data ActData Portability (effective September 2025)
FDA CSA GuidanceComputer Software Assurance (September 2025)

Customer Data Ownership - "Fire Us and Keep Running"

  • Governance records (audit events + amendments) are queryable and exportable in full at any time, as CSV or JSON, through the API
  • If the customer stops using Open Industrial, they keep the entire compliance record -- every event, every correction, every hash
  • No vendor lock-in on regulatory data. Portable, exportable, customer-owned
  • This architecture is a trust signal for regulated industry procurement teams
  • Records are held in Azure Blob Storage under a time-based immutability policy, isolated per workspace and per scope by container, and provisioned into the customer's own Azure subscription -- so the records sit in their tenancy rather than ours. In production the policy is locked, so the storage service itself refuses a delete or an overwrite
  • The EU Data Act (September 2025) mandates data portability for SaaS providers: export within 30 days of termination. Open Industrial treats export as an everyday operation rather than an exit process, so there is no extraction window to wait out
Thinking Tip:

The EU Data Act (September 2025) mandates data portability for SaaS providers. Open Industrial treats export as an everyday operation rather than an exit process. Provisioning into the customer's own Azure subscription ships with the Provenance blob store.

Getting Started

  1. Add Audit Event Log node to workspace canvas
  2. Add Amendment Log node to workspace canvas
  3. Commit. Governance starts immediately.

For setup details, see the Audit Event Log guide and Amendment Log guide.

For the REST API reference (write, query, verify, export), see the REST API Reference.

For the public announcement, see Two Governance Gates.

For validation protocol support or compliance questions, contact your Open Industrial account team.

On this page