GxP & E-Signatures API

The GxP API provides compliance dashboard data, audit trail management, and electronic signature capabilities for FDA 21 CFR Part 11 regulated environments. All procedures require organization-level authentication (orgProcedure).

gxp.getComplianceStatus

Get the overall GxP compliance status for the organization dashboard.

Input: None

Output:

{
  overallStatus: "compliant" | "partial" | "non-compliant";
  categories: Array<{
    name: string;                // e.g., "Audit Trail", "E-Signatures", "Access Control"
    status: "compliant" | "partial" | "non-compliant";
    completionPercentage: number;
    findings: number;
  }>;
  lastAuditDate: Date | null;
}

gxp.getAuditTrail

Get paginated audit trail with comprehensive filtering.

Input Schema:

{
  entityType?: string;          // Filter by entity type (e.g., "action", "item")
  entityId?: string;            // Filter by specific entity
  userId?: string;              // Filter by user
  action?: string;              // Filter by action type (create, update, delete)
  startDate?: string;           // ISO date range start
  endDate?: string;             // ISO date range end
  page?: number;
  limit?: number;
}

gxp.exportAuditTrail

Export filtered audit trail to CSV or PDF format.

Input Schema:

{
  format: "csv" | "pdf";
  filters?: {
    entityType?: string;
    startDate?: string;
    endDate?: string;
  };
}

Output: Returns a download URL for the generated export file.

eSignatures.sign

Create an electronic signature on a record with identity verification.

Input Schema:

{
  entityType: string;           // Type of record being signed
  entityId: string;             // ID of record being signed
  meaning: string;              // "approved" | "reviewed" | "authored" | "witnessed"
  password: string;             // Password re-entry for identity verification
}

Output: Returns the created signature record with timestamp and user identity.

eSignatures.verify

Verify the integrity of an electronic signature.

Input Schema:

{
  signatureId: string;
}

Output:

{
  valid: boolean;
  signature: {
    id: string;
    userId: string;
    userName: string;
    meaning: string;
    signedAt: Date;
    entityType: string;
    entityId: string;
  };
}

eSignatures.getHistory

Get signature history for a specific record.

Input Schema:

{
  entityType: string;
  entityId: string;
  page?: number;
  limit?: number;
}

Permissions

ProcedureRequired Role
gxp.getComplianceStatusAdmin or Quality role
gxp.getAuditTrailAdmin or Quality role
gxp.exportAuditTrailAdmin or Quality role
eSignatures.signAny authenticated member
eSignatures.verifyAny authenticated member
eSignatures.getHistoryAny authenticated member