Compliance API

ProBeya provides a comprehensive compliance suite covering three domains: Compliance Radar for regulatory requirement tracking, Inspection Shield for pre-inspection simulation and readiness scoring, and IFQHC for competency framework management. All endpoints enforce strict multi-tenant isolation via organizationId.

Compliance Radar

Track regulatory requirements across frameworks (EU GMP, FDA 21 CFR, ISO) with risk-level classification, periodic assessments, and a dashboard aggregation view.

Endpoints


POST /api/v1/compliance/requirements

Create a new compliance requirement representing a single clause or control from a regulatory framework.

tRPC: complianceRadar.createRequirement Auth: Bearer token required (scope: write:items) or session cookie Org context: Required

Parameters:

NameTypeRequiredDescription
frameworkstringYesRegulatory framework name (e.g., “EU GMP Annex 11”)
clausestringYesSpecific clause or section reference (e.g., “4.8”)
titlestringYesShort title for the requirement (max 500 chars)
descriptionstringNoDetailed description
categorystringNoGrouping category (e.g., “data integrity”, “access control”)
applicabilitystringNoapplicable, not_applicable, partial (default: applicable)
statusstringNocompliant, non_compliant, gap_identified, remediation_in_progress (default: gap_identified)
riskLevelstringNolow, medium, high, critical (default: medium)
ownerUserIdstringNoUser responsible for this requirement
nextAssessmentDuestringNoISO 8601 datetime for next assessment

Example:

curl -X POST -H "Authorization: Bearer probeya_sk_live_..." \
     -H "Content-Type: application/json" \
     -d '{"framework":"EU GMP Annex 11","clause":"4.8","title":"Data integrity controls","riskLevel":"high"}' \
     "https://acme.probeya.com/api/v1/compliance/requirements"

GET /api/v1/compliance/requirements

List all compliance requirements with filtering, search, and pagination.

tRPC: complianceRadar.listRequirements Auth: Bearer token required (scope: read:items) or session cookie Org context: Required

Parameters:

NameTypeRequiredDescription
frameworkstring (query)NoFilter by regulatory framework
statusstring (query)NoFilter by compliance status
riskLevelstring (query)NoFilter by risk level
categorystring (query)NoFilter by category
searchstring (query)NoCase-insensitive title search
limitnumber (query)NoResults per page (default: 20, max: 100)
offsetnumber (query)NoPagination offset (default: 0)

Response:

{
  "items": [
    {
      "id": "clx9cr001",
      "framework": "EU GMP Annex 11",
      "clause": "4.8",
      "title": "Data integrity controls",
      "status": "gap_identified",
      "riskLevel": "high",
      "applicability": "applicable",
      "nextAssessmentDue": "2026-06-01T00:00:00.000Z"
    }
  ],
  "total": 42
}

POST /api/v1/compliance/assessments

Record a point-in-time compliance assessment for a requirement. Automatically updates the parent requirement’s status and lastAssessedAt timestamp.

tRPC: complianceRadar.createAssessment Auth: Bearer token required (scope: write:items) or session cookie Org context: Required

Parameters:

NameTypeRequiredDescription
requirementIdstringYesID of the requirement being assessed
newStatusstringYesNew compliance status after assessment
findingsstringNoDetailed findings from the assessment
evidenceobjectNoEvidence collected during assessment (JSONB)
nextActionsstringNoRecommended remediation steps

GET /api/v1/compliance/dashboard

Aggregated compliance posture dashboard with counts grouped by status, risk level, and framework.

tRPC: complianceRadar.getDashboard Auth: Bearer token required (scope: read:items) or session cookie Org context: Required

Response:

{
  "total": 127,
  "byStatus": [
    { "status": "compliant", "count": 85 },
    { "status": "gap_identified", "count": 22 },
    { "status": "remediation_in_progress", "count": 15 },
    { "status": "non_compliant", "count": 5 }
  ],
  "byRiskLevel": [
    { "riskLevel": "low", "count": 40 },
    { "riskLevel": "medium", "count": 50 },
    { "riskLevel": "high", "count": 30 },
    { "riskLevel": "critical", "count": 7 }
  ],
  "byFramework": [
    { "framework": "EU GMP Annex 11", "count": 42 },
    { "framework": "FDA 21 CFR Part 11", "count": 38 }
  ]
}

Inspection Shield

Run simulated inspections using GMP, FDA, ISO, or custom checklists. Capture findings per checkpoint item, compute readiness scores, and track completion.

tRPC-Only Inspection Procedures

ProcedureTypeDescription
inspectionShield.createChecklistmutationCreate a versioned inspection checklist template
inspectionShield.listChecklistsqueryPaginated list with type/status filters and name search
inspectionShield.getChecklistqueryFull checklist details with session count
inspectionShield.updateChecklistmutationPartial update of checklist fields
inspectionShield.createSessionmutationStart a new inspection session against a checklist
inspectionShield.completeSessionmutationFinalize a session with findings and readiness score
inspectionShield.listSessionsqueryPaginated session list, optionally by checklistId
inspectionShield.getSessionquerySingle session details with checklist info

Checklist lifecycle: draft → active → archived

Checkpoint criticality levels: critical, major, minor, info

Finding results per checkpoint: pass, fail, na


IFQHC Competency Management

The IFQHC (Information-Formation-Qualification-Habitude-Confirmation) model provides a strict competency progression framework used in regulated manufacturing.

IFQHC Level Hierarchy

LevelNameMapped CompetencyDescription
IInformationtraineeInformed about the process
FFormationtraineeTrained on the procedure
QQualificationcompetentQualified to perform independently
HHabitudeproficientAutonomous with established habits
CConfirmationexpertConfirmed coach, can train others

tRPC-Only IFQHC Procedures

ProcedureTypeDescription
ifqhc.createFrameworkmutationCreate a competency framework (eu_gmp, us_fda, simple, custom)
ifqhc.listFrameworksqueryPaginated list with preset filter and search
ifqhc.getFrameworkByIdqueryFull framework with recent assessments
ifqhc.updateFrameworkmutationUpdate framework details
ifqhc.deleteFrameworkmutationDelete a framework
ifqhc.createAssessmentmutationRecord a competency assessment with IFQHC gate logic
ifqhc.listAssessmentsqueryPaginated assessment list
ifqhc.getAssessmentByIdquerySingle assessment detail
ifqhc.validateGateLogicqueryValidate IFQHC level progression prerequisites
ifqhc.revokeRecordmutationRevoke a competency record
ifqhc.suspendRecordmutationSuspend a competency record
ifqhc.reinstateRecordmutationReinstate a suspended record
ifqhc.getMatrixquery2D user-by-process competency matrix
ifqhc.getExpiringRecordsqueryRecords approaching expiry
ifqhc.getComplianceRatequeryOverall competency compliance percentage
ifqhc.getTrainingGapAnalysisqueryIdentify training gaps across processes
ifqhc.createEvaluationmutationStart a formal evaluation
ifqhc.completeEvaluationmutationComplete an evaluation with results
ifqhc.createCampaignmutationCreate an assessment campaign
ifqhc.checkLineCoveragequeryVerify line staffing meets competency requirements
ifqhc.getExpiryDashboardqueryExpiry status overview

Error Codes

CodeDescription
400Invalid input (e.g., unknown framework, invalid status)
401Missing or invalid authentication
403Insufficient permissions
404Requirement, checklist, framework, or assessment not found
409IFQHC gate logic violation (prerequisite level not met)