Solutions

Three sectors, in the order we can actually serve them

Each of these exists because the implementations behind it exist. Sectors we would like to be in, but have nothing built for, are not listed. The order is the order we would pursue them, and it is deliberate.

Organisation types

Where this sits, structurally

Sector is a rough guide. The better question is what position an organisation occupies, because the problem is structural rather than industrial. These are positions, not a list of who we would like to sell to.

Organisation type The trigger event Who owns it What changes
Validation and quality consultancies
Firms delivering computerised system validation, qualification and quality assurance into regulated manufacturing and laboratory environments.
A client's supplier document, reference standard or source dataset is revised, and the scope of revalidation has to be argued rather than derived. Validation lead or practice principal Change impact becomes a derived, signed artefact instead of a judgement defended in a report.
Contract research and development organisations
Organisations running studies, analysis or manufacturing on behalf of sponsors, under the sponsor's obligations as well as their own.
A protocol amendment or a corrected source record propagates across studies, and someone has to establish what it touched. Quality assurance or data management lead The propagation is traced rather than reconstructed, and the sponsor receives evidence rather than assurance.
Regulated manufacturers with computational workflows
Pharmaceutical, biotechnology and medical technology organisations where computational analysis feeds a regulated decision.
A model, dataset or reference source is updated between the analysis and the submission. Head of quality, regulatory affairs or computational science Affected work is separated from preserved work by rule, and the separation is defensible to an inspector.
Software-as-a-medical-device manufacturers
Organisations whose software is itself the regulated product, with change notification obligations attached to it.
A change to the software, its training data or its dependencies raises the question of what must be revalidated and notified. Regulatory affairs or quality management representative Change impact and the record of it are produced by the system rather than assembled afterwards.
Research institutes and core informatics platforms
Groups running shared computational infrastructure where many downstream analyses depend on the same versioned source records.
A public reference database issues a revision, and nobody knows which prior analyses are now stale. Platform or core facility lead Dependency impact is computed instead of estimated, and valid work is preserved rather than rerun defensively.
Financial institutions with model governance obligations
Lenders, insurers and market participants where models inform decisions inside obligations that move.
A policy, threshold or regulatory expectation changes, and prior decisions sit on the superseded version. Model risk, operational risk or internal audit Per-decision records exist, so operating effectiveness can be demonstrated rather than attested.
Operators of safety-critical physical systems
Organisations where a decision can drive hardware, machinery or infrastructure.
Autonomy or machine-supported decisions move closer to the control path than the assurance method was designed for. Safety, assurance or operations lead A fail-closed permission boundary sits before execution, and the basis of every permit or block is recorded.
Boards, general counsel and assurance advisers
Those who have to demonstrate that a framework operated, not merely that it existed.
A question is asked about a specific decision made some time ago, and the answer has to be reconstructed. General counsel, chief risk officer or audit committee Reconstruction becomes a retrieval rather than an investigation.
Self-test

Does any of this describe you?

If none of these is true, we are not useful to you yet, and we would rather say that than take the meeting and find out together.

  • A change to a rule, a policy or a reference source has already forced you to work out what it invalidated.
  • That work was done by people, from memory and documents, rather than derived from a dependency model.
  • You could not quickly reconstruct one specific decision made two years ago from its sources, its output, its review and its final approval.
  • You revalidate more broadly than necessary because narrowing the scope is hard to defend.
  • An auditor, regulator or customer has asked you to show that a control was operating, not just that it was designed.
  • A machine-supported decision in your organisation can cause a physical action, and the permission for it is implicit.

One of them is enough

A single true statement above is a reason for a thirty-minute conversation about that one workflow. Several true statements usually means the cost is already being absorbed somewhere and nobody has named it.

Not sure which one you are?

If a change in rules or evidence has ever forced you to work out what it invalidated, you are in scope regardless of sector.

Next · Start a pilot Adoption