Compliance API
Regulatory compliance tracking, pre-inspection simulations, and IFQHC competency management.
Compliance API
ProBeya provides a comprehensive compliance suite covering three domains: Compliance Radar for regulatory requirement tracking, Inspection Shield for pre-inspection simulation and readiness scoring, and IFQHC for competency framework management. All endpoints enforce strict multi-tenant isolation via organizationId.
Compliance Radar
Track regulatory requirements across frameworks (EU GMP, FDA 21 CFR, ISO) with risk-level classification, periodic assessments, and a dashboard aggregation view.
Endpoints
POST /api/v1/compliance/requirements
Create a new compliance requirement representing a single clause or control from a regulatory framework.
tRPC: complianceRadar.createRequirement
Auth: Bearer token required (scope: write:items) or session cookie
Org context: Required
Parameters:
| Name | Type | Required | Description |
|---|---|---|---|
framework | string | Yes | Regulatory framework name (e.g., “EU GMP Annex 11”) |
clause | string | Yes | Specific clause or section reference (e.g., “4.8”) |
title | string | Yes | Short title for the requirement (max 500 chars) |
description | string | No | Detailed description |
category | string | No | Grouping category (e.g., “data integrity”, “access control”) |
applicability | string | No | applicable, not_applicable, partial (default: applicable) |
status | string | No | compliant, non_compliant, gap_identified, remediation_in_progress (default: gap_identified) |
riskLevel | string | No | low, medium, high, critical (default: medium) |
ownerUserId | string | No | User responsible for this requirement |
nextAssessmentDue | string | No | ISO 8601 datetime for next assessment |
Example:
curl -X POST -H "Authorization: Bearer probeya_sk_live_..." \
-H "Content-Type: application/json" \
-d '{"framework":"EU GMP Annex 11","clause":"4.8","title":"Data integrity controls","riskLevel":"high"}' \
"https://acme.probeya.com/api/v1/compliance/requirements"
GET /api/v1/compliance/requirements
List all compliance requirements with filtering, search, and pagination.
tRPC: complianceRadar.listRequirements
Auth: Bearer token required (scope: read:items) or session cookie
Org context: Required
Parameters:
| Name | Type | Required | Description |
|---|---|---|---|
framework | string (query) | No | Filter by regulatory framework |
status | string (query) | No | Filter by compliance status |
riskLevel | string (query) | No | Filter by risk level |
category | string (query) | No | Filter by category |
search | string (query) | No | Case-insensitive title search |
limit | number (query) | No | Results per page (default: 20, max: 100) |
offset | number (query) | No | Pagination offset (default: 0) |
Response:
{
"items": [
{
"id": "clx9cr001",
"framework": "EU GMP Annex 11",
"clause": "4.8",
"title": "Data integrity controls",
"status": "gap_identified",
"riskLevel": "high",
"applicability": "applicable",
"nextAssessmentDue": "2026-06-01T00:00:00.000Z"
}
],
"total": 42
}
POST /api/v1/compliance/assessments
Record a point-in-time compliance assessment for a requirement. Automatically updates the parent requirement’s status and lastAssessedAt timestamp.
tRPC: complianceRadar.createAssessment
Auth: Bearer token required (scope: write:items) or session cookie
Org context: Required
Parameters:
| Name | Type | Required | Description |
|---|---|---|---|
requirementId | string | Yes | ID of the requirement being assessed |
newStatus | string | Yes | New compliance status after assessment |
findings | string | No | Detailed findings from the assessment |
evidence | object | No | Evidence collected during assessment (JSONB) |
nextActions | string | No | Recommended remediation steps |
GET /api/v1/compliance/dashboard
Aggregated compliance posture dashboard with counts grouped by status, risk level, and framework.
tRPC: complianceRadar.getDashboard
Auth: Bearer token required (scope: read:items) or session cookie
Org context: Required
Response:
{
"total": 127,
"byStatus": [
{ "status": "compliant", "count": 85 },
{ "status": "gap_identified", "count": 22 },
{ "status": "remediation_in_progress", "count": 15 },
{ "status": "non_compliant", "count": 5 }
],
"byRiskLevel": [
{ "riskLevel": "low", "count": 40 },
{ "riskLevel": "medium", "count": 50 },
{ "riskLevel": "high", "count": 30 },
{ "riskLevel": "critical", "count": 7 }
],
"byFramework": [
{ "framework": "EU GMP Annex 11", "count": 42 },
{ "framework": "FDA 21 CFR Part 11", "count": 38 }
]
}
Inspection Shield
Run simulated inspections using GMP, FDA, ISO, or custom checklists. Capture findings per checkpoint item, compute readiness scores, and track completion.
tRPC-Only Inspection Procedures
| Procedure | Type | Description |
|---|---|---|
inspectionShield.createChecklist | mutation | Create a versioned inspection checklist template |
inspectionShield.listChecklists | query | Paginated list with type/status filters and name search |
inspectionShield.getChecklist | query | Full checklist details with session count |
inspectionShield.updateChecklist | mutation | Partial update of checklist fields |
inspectionShield.createSession | mutation | Start a new inspection session against a checklist |
inspectionShield.completeSession | mutation | Finalize a session with findings and readiness score |
inspectionShield.listSessions | query | Paginated session list, optionally by checklistId |
inspectionShield.getSession | query | Single session details with checklist info |
Checklist lifecycle: draft → active → archived
Checkpoint criticality levels: critical, major, minor, info
Finding results per checkpoint: pass, fail, na
IFQHC Competency Management
The IFQHC (Information-Formation-Qualification-Habitude-Confirmation) model provides a strict competency progression framework used in regulated manufacturing.
IFQHC Level Hierarchy
| Level | Name | Mapped Competency | Description |
|---|---|---|---|
| I | Information | trainee | Informed about the process |
| F | Formation | trainee | Trained on the procedure |
| Q | Qualification | competent | Qualified to perform independently |
| H | Habitude | proficient | Autonomous with established habits |
| C | Confirmation | expert | Confirmed coach, can train others |
tRPC-Only IFQHC Procedures
| Procedure | Type | Description |
|---|---|---|
ifqhc.createFramework | mutation | Create a competency framework (eu_gmp, us_fda, simple, custom) |
ifqhc.listFrameworks | query | Paginated list with preset filter and search |
ifqhc.getFrameworkById | query | Full framework with recent assessments |
ifqhc.updateFramework | mutation | Update framework details |
ifqhc.deleteFramework | mutation | Delete a framework |
ifqhc.createAssessment | mutation | Record a competency assessment with IFQHC gate logic |
ifqhc.listAssessments | query | Paginated assessment list |
ifqhc.getAssessmentById | query | Single assessment detail |
ifqhc.validateGateLogic | query | Validate IFQHC level progression prerequisites |
ifqhc.revokeRecord | mutation | Revoke a competency record |
ifqhc.suspendRecord | mutation | Suspend a competency record |
ifqhc.reinstateRecord | mutation | Reinstate a suspended record |
ifqhc.getMatrix | query | 2D user-by-process competency matrix |
ifqhc.getExpiringRecords | query | Records approaching expiry |
ifqhc.getComplianceRate | query | Overall competency compliance percentage |
ifqhc.getTrainingGapAnalysis | query | Identify training gaps across processes |
ifqhc.createEvaluation | mutation | Start a formal evaluation |
ifqhc.completeEvaluation | mutation | Complete an evaluation with results |
ifqhc.createCampaign | mutation | Create an assessment campaign |
ifqhc.checkLineCoverage | query | Verify line staffing meets competency requirements |
ifqhc.getExpiryDashboard | query | Expiry status overview |
Error Codes
| Code | Description |
|---|---|
| 400 | Invalid input (e.g., unknown framework, invalid status) |
| 401 | Missing or invalid authentication |
| 403 | Insufficient permissions |
| 404 | Requirement, checklist, framework, or assessment not found |
| 409 | IFQHC gate logic violation (prerequisite level not met) |
Was this page helpful?