User Administration
Role-based access, electronic signature and an audit trail that holds up
Part 11 compliance is decided here. Who can do what, whose signature means what, and whether the record of both can be altered afterwards. DeepPharmaERP keeps an append-only audit trail with reason for change, separate from the transactional data and outside the reach of a system administrator.
What User Administration covers
Access
- Role-based access at module, task and operation level
- User and role rights matrix with segregation of duties checks
- Electronic signature bound to the user, the record version and the intent
- Session control, password policy and account lockout
Trail and alerts
- Date and time stamp on every user action, taken from the server
- Append-only audit trail with reason for change, not deletable by any role
- User-wise, transaction-wise and task-wise audit trail review
- Alerts and notifications matrix by event and by user
Operations
- Database backup and restore with verification
- Backdated transaction control and period locking
- Login history and report generation logging
What the system notices for you
Suggestions only. Nothing here signs, approves or dispositions anything — a qualified person decides and the audit trail records who. Every model shows the data behind its suggestion, and every feature can be switched off per site.
Access anomaly detection
Notices when a user starts behaving unlike their role and unlike themselves.
Segregation of duties analysis
Finds role combinations that let one person complete a controlled process alone.
Audit trail review assistance
Surfaces the entries in a review period that are worth a human reading.
User Administration — common questions
Can a system administrator alter the audit trail?
No. It is written to a separate append-only store with delete permission removed at the database role level, and timestamps come from the server rather than the workstation. This is deliberate and it is the foundation the rest of the compliance claim rests on.
How are electronic signatures different from a login?
A signature requires re-authentication at the moment of signing, records a stated meaning — performed by, verified by, approved by — and binds to the exact version of the record signed. A login only proves who opened the session.
Works with
Every module shares one database, so nothing below is an integration — it is the same record seen from a different desk.
Material Procurement
From indent to approved vendor, with the paper trail built in
Read more IMInventory Management
Every container, every location, every date control
Read more PDProduction Management
Plan, allocate, execute, reconcile
Read more BMeBMR — Electronic Batch Record
The batch record that cannot be back-dated, skipped or signed by the wrong person
Read moreSee it on your own floor.
Two hours with your production and QA leads. We walk one product end to end and show you where it lands in the system — then you decide whether a gap study is worth it.