Validation support
Regulated teams must validate the software they use for quality records. This page gives you what a supplier should: how each requirement is addressed, what stays your responsibility, and ready-to-run test scripts.
Clearlane apps are designed to help you meet the requirements below. They are not certified, and no software can be “compliant” on its own: compliance comes from the validated system together with your procedures.
Download the test scripts
- Controlled Documents: operational qualification (OQ) script, 12 tests
- CAPA: operational qualification (OQ) script, 12 tests
Each script lists the objective, the steps, the expected result and space for the result, the tester and the date. Run it on a test space or project, attach screenshots, and keep it with your validation file.
What the supplier provides
- The apps run on Atlassian Forge (Runs on Atlassian): no Clearlane servers, nothing leaves your Atlassian site.
- Every release is tested with automated tests of the full workflow before it is published.
- Release notes on the Atlassian Marketplace, and a security policy with a way to report vulnerabilities (security).
21 CFR Part 11 · Controlled Documents
| Requirement | How the app helps | Your responsibility |
|---|---|---|
| 11.10(a) Validation | Supplier testing of every release (automated tests of the full workflow). OQ test script below. | Validate for your intended use (IQ/OQ/PQ), keep the validation file. |
| 11.10(b) Accurate and complete copies | Evidence file as PDF; register export as CSV; Confluence page export includes the control block. | Define how copies are provided to inspectors. |
| 11.10(c) Protection of records | Records kept in Atlassian’s storage for your site; page history kept by Confluence. | Retention and backup of your Atlassian site. Export evidence files before uninstalling the app. |
| 11.10(d) Limiting access | Atlassian login and Confluence permissions; optional edit lock during approval. | Manage accounts and permissions. |
| 11.10(e) Audit trail | Time-stamped audit trail of lifecycle, signature and read events, visible to space administrators. | Review it as your procedures require. |
| 11.10(f) Operational checks | Enforced sequence: Draft, In review, Effective, Obsolete. | — |
| 11.10(g) Authority checks | Only the named approvers can sign; settings reserved to administrators. | Name the right people. |
| 11.10(i), (j) Training and accountability | Read-and-understood records per revision support training records. | Training, written signature policy. |
| 11.50 Signature manifestation | Name, date and time, and meaning shown with each signature and in the evidence file. | — |
| 11.70 Signature and record linking | SHA-256 fingerprint of the signed content; any change voids the approval. | — |
| 11.100 General requirements | Signatures tied to unique Atlassian accounts. | Verify identities; send the certification to FDA. |
| 11.200 Signature components | Two components: Atlassian login plus a personal signing password asked at each signature. | — |
| 11.300 Password controls | Signing passwords stored hashed (scrypt); blocking after repeated failures. | Password policy, periodic review, loss procedure. |
CAPA signs plan approvals and closures with the same signature engine (signing password, fingerprint, blocking).
ISO 13485 · 8.5.2 Corrective action · CAPA
| Requirement | How the app helps |
|---|---|
| 8.5.2 a) Review nonconformities, including complaints | Any Jira work item can become a CAPA: complaint, audit finding, defect, incident. Problem step with source and severity. |
| 8.5.2 b) Determine the causes | Guided root cause (5 whys, cause categories) with a guard against “human error” and “training” as causes; similar CAPAs shown. |
| 8.5.2 c) Evaluate the need for action | Severity, containment and a documented decision before the plan. |
| 8.5.2 d) Plan, document and implement the action | Signed action plan; actions as linked Jira work items with owners and due dates. |
| 8.5.2 e) Verify the action does not adversely affect requirements or safety and performance | Effectiveness criterion and verification recorded per action; your assessment is written in the plan. |
| 8.5.2 f) Review the effectiveness | Dated effectiveness check with reminder; “not effective” returns to root cause; signed closure. |
| Records (4.2.5, and ISO 9001 10.2.2) | Evidence file as PDF with every step, signature, attachment and audit event. Nothing is deleted. |
Since 2 February 2026, the FDA Quality Management System Regulation (QMSR) incorporates ISO 13485:2016 by reference.
What stays with you
- Validation for your intended use, and revalidation when you change your use or after a new app release that matters to you.
- Procedures (SOPs), training, and the written policy that makes electronic signatures binding.
- Account management, permissions, retention and backup of your Atlassian site.
Questions from your quality team or auditor: [email protected].