ALCOA++ Coverage Matrix
Open Industrial provides two governance nodes that supply the evidence the ALCOA++ data integrity framework asks for. Whether a given deployment satisfies a principle is a determination its auditor makes.
Overview
Open Industrial provides two governance nodes that together answer the questions ALCOA++ asks of a record: what changed, who changed it, when, and why. Add the node and capture is automatic. Both are built into the platform. Records are held in Azure Blob Storage under a time-based immutability policy, isolated per workspace and per scope by container, and provisioned into the customer's own Azure subscription — so the records sit in their tenancy rather than ours.
| Node | Purpose |
|---|---|
| Audit Event Log | Append-only, hash-chained record of workspace configuration changes |
| Amendment Log | Documented corrections with reason-for-change traceability |
ALCOA++ Coverage Matrix
| Principle | Audit Event Log | Amendment Log | Together |
|---|---|---|---|
| Attributable | User identity on every event | User identity on every amendment | Every action and correction attributed |
| Legible | Structured JSON, before/after | Reason category + justification + diff | Human-readable records with context |
| Contemporaneous | Server-side timestamp | Server-side timestamp | All records timestamped at time of action |
| Original | Append-only event writes (create, never upsert; a duplicate event ID is rejected). Immutable storage ships with the blob store | Original record preserved, never overwritten | First recording always accessible |
| Accurate (data) | SHA-256 digest recomputed and its predecessor chain walked by a server-side verify endpoint | SHA-256 per-entity hash chain; WORM storage ships with the blob store. Approve/reject workflow enforces maker/checker separation on data corrections, server-side. | Both event and amendment cryptographically verifiable; data corrections require a documented reason + second-signer approval |
| Accurate (config) | Configuration commits captured as before/after events | Deploy gate enforcing proposer != deployer is not built yet | Committed configuration changes are attributed, timestamped and chained |
| Complete | Configuration commits across the tracked workspace collections are captured automatically -- no logging code to remember | Every amendment requires a validated reason for change | Recorded changes carry attribution, timing and a reason |
| Consistent | Standardized event schema | Standardized amendment schema | Uniform format across all actions |
| Enduring | Retention periods configured per workspace (7/15/30 year and indefinite presets), with a floor keeping the configuration trail longer than the records it governs. Policy enforcement ships with the blob store | Chain retained alongside the amendments | Records persist and are exportable for off-platform archival |
| Available | Query API + CSV/JSON export | Chain query API + export | All records accessible to authorized users |
| Traceable | SHA-256 hash chain provides ordered sequence of all activities | Per-entity amendment chain provides ordered sequence of all corrections per entity | Cryptographically verifiable chain of custody for every action and correction |
| Transparent | Open, queryable audit event API with CSV/JSON export | Reason-for-change documents methodology; approve/reject documents governance | No hidden processes. Complete, documented methodology |
Open Industrial provides mechanisms for all 11 ALCOA++ principles, including the Traceable and Transparent principles that draft EU GMP Chapter 4 (July 2025) is formalizing into regulation.
Standards This Maps Against
These are the regulatory frameworks the governance nodes are designed against. Listing a standard here is not a claim of certification or validated compliance.
| Standard | Scope |
|---|---|
| 21 CFR Part 11 | FDA - Electronic Records; Electronic Signatures |
| EU Annex 11 | Computerised Systems |
| ICH Q7 | Good Manufacturing Practice for Active Pharmaceutical Ingredients |
| GAMP 5 | Good Automated Manufacturing Practice |
| EU AI Act | AI governance for regulated industries (enforcement begins August 2026) |
| ICH E6(R3) | Data Governance for Clinical Trials (finalized 2025; live in EU July 2025, US September 2025, Canada April 2026) |
| EU GMP Chapter 4 draft | ALCOA++ codification (July 2025) |
| EU Data Act | Data Portability (effective September 2025) |
| FDA CSA Guidance | Computer Software Assurance (September 2025) |
Customer Data Ownership - "Fire Us and Keep Running"
- Governance records (audit events + amendments) are queryable and exportable in full at any time, as CSV or JSON, through the API
- If the customer stops using Open Industrial, they keep the entire compliance record -- every event, every correction, every hash
- No vendor lock-in on regulatory data. Portable, exportable, customer-owned
- This architecture is a trust signal for regulated industry procurement teams
- Records are held in Azure Blob Storage under a time-based immutability policy, isolated per workspace and per scope by container, and provisioned into the customer's own Azure subscription -- so the records sit in their tenancy rather than ours. In production the policy is locked, so the storage service itself refuses a delete or an overwrite
- The EU Data Act (September 2025) mandates data portability for SaaS providers: export within 30 days of termination. Open Industrial treats export as an everyday operation rather than an exit process, so there is no extraction window to wait out
The EU Data Act (September 2025) mandates data portability for SaaS providers. Open Industrial treats export as an everyday operation rather than an exit process. Provisioning into the customer's own Azure subscription ships with the Provenance blob store.
Getting Started
- Add Audit Event Log node to workspace canvas
- Add Amendment Log node to workspace canvas
- Commit. Governance starts immediately.
For setup details, see the Audit Event Log guide and Amendment Log guide.
For the REST API reference (write, query, verify, export), see the REST API Reference.
For the public announcement, see Two Governance Gates.
For validation protocol support or compliance questions, contact your Open Industrial account team.