Compliance Dashboard
System overview — applications, audit activity, and workstation agents.
Alert & Violation Management
Critical and warning events requiring review — sourced from the tamper-evident audit chain.
| When (UTC) | Severity | Type | Application | Detail |
|---|
Compliance Monitoring Center
Live compliance status across wrapped applications and recent violations.
| Application | Vendor | Tier | ACL lock | Status |
|---|
Validation Hub
IQ / OQ / PQ validation lifecycle for wrapped applications.
System Settings
System health, services, and configuration.
Roles & Permissions
What each role can do across the console and agent.
Directory Integration
Sync users from Active Directory / LDAP.
Backup & Recovery
On-demand, consistent snapshots of the system-of-record database, each hashed for verification.
Applications
Registered Windows executables, their tier, and ACL launch-lock state.
| Name | Vendor | Version | Path | Tier | ACL Lock | Capability | Actions |
|---|
Agents
Every workstation running the Compliance ARMOR agent, with its last-seen heartbeat and active session.
| Status | Workstation | Agent version | OS user | Last seen | Active session |
|---|
Session Trail
A plain-English story of each supervised session — who used which application and, step by step, what they opened, clicked, typed, saved and signed.
Audit Trail
Hash-chained, HMAC-signed, append-only event ledger.
System Log shows all activity — including mouse clicks, keystrokes and window changes — captured from the supervised application. Use the chips above to narrow to a category (e.g. Clicks, Keyboard, Files).
What do the severity levels mean?
Info — Routine activity; no action needed.
Notice — A meaningful GMP event (file saved, signature, configuration or status change). Recorded for the trail; review as part of normal oversight.
Warning — Needs attention: a failed sign-in, an uncontrolled edit, or a removed/renamed original. Review and follow up.
Critical — A data-integrity or security failure: audit-chain tampering or a corrupted controlled copy. Investigate immediately.
| # | When (UTC) | Application | Action | Severity | What happened | Chain hash |
|---|
Electronic Signatures
21 CFR Part 11 §11.50 manifested signatures, bound to the audit chain.
| Document | Status | Uploaded (UTC) | Size | SHA-256 | Signatures |
|---|
| Signed at (UTC) | Signer | Meaning | Reason | Manifestation hash |
|---|
Controlled Records
Files captured into the controlled vault by the agent. Each row is one observed file in a watched folder, copied to a write-protected location, hash-verified, and linked to the audit event that announced it.
📄 Controlled files
| Captured (UTC) | Application | File | Operation | Size (Δ) | Version | Status |
|---|
📸 Screen image & video evidence
| Captured (UTC) | Application | Capture | Kind | Reason |
|---|
Retention & Legal Hold
Set how long controlled records are kept, pin records under legal hold, and dispose expired records. Disposal removes the vault file but keeps an audited tombstone — the chain stays intact.
Retention policy
Legal holds
| Status | Vault record | Reason | Placed (UTC) | Actions |
|---|
Capability Reports
Per-application probe results that drive tier assignment.
| App | Tier | Window titles | UIA surface | Hardware dep. | Files seen | Generated |
|---|
Users
Tenant members and their roles.
| Name | Role | Active | Created | Actions |
|---|