Specifications with traceable elements
URS, FS, DS and your own document types, written in the editor. Each requirement or element carries a tag; a tag is traced to the level above with one click and coloured by whether it is traced.
Pharma validation software
MGTrace is validation software for pharmaceutical and GMP facilities. You write the user requirements, the functional and design specifications, the protocols that verify them — and the traceability matrix writes itself, level by level, from the first requirement to the last executed test. Electronic signatures and the audit trail are built in, not bolted on.
The first 5 users are free, with no time limit; every further user is €39 a month. Data hosted in the EU.
Computerised-system and equipment validation in pharma is a chain of documents that must agree with each other: a User Requirements Specification, the functional and design specifications that decompose it, and the IQ, OQ and PQ protocols that verify each level. An auditor does not read them one by one — they pick a requirement and follow it down to a test result, then pick a test and follow it back up. When the chain is kept in spreadsheets and Word files, that walk breaks at the first renumbered requirement.
Validation software exists to keep that chain unbreakable: every requirement, element and test is an identified object; every link between them is recorded, dated and attributable; every protocol is authored under version control, executed with results that cannot be edited after the fact, and signed by a person whose identity and intent are recorded. That is what EU GMP Annex 11, 21 CFR Part 11 and GAMP 5 describe — and what MGTrace does, from the V-model of a single system to the traceability matrix of a whole plant.
URS, FS, DS and your own document types, written in the editor. Each requirement or element carries a tag; a tag is traced to the level above with one click and coloured by whether it is traced.
Test cases authored as cards — steps, expected results, acceptance criteria — reviewed and approved as a document, then released for execution with results, evidence and signatures in place.
Read live for a project or across the plant: every requirement, the elements that decompose it, the I/O it reaches, the tests that verify it, gaps in amber. Exported to CSV with the application version and date stamped on it.
A signature records who, when (UTC, from the database clock), the meaning and the reason, and is hashed into the audit trail. Two-factor authentication and a 15-minute inactivity log-off are part of the account.
Every controlled change carries its actor, time, old and new value and reason, and can be filtered, paged and exported. Records are soft-deleted only; nothing regulated is physically removed.
A failed test opens a discrepancy with its own lifecycle; an approved protocol changes through an amendment, never in place; requirements freeze when the document that holds them is approved.
Each system shows its own V: specifications down the left leg, protocols up the right, the counts of traces between them, and any document or protocol movable to the rung you want it on.
A validation plan, risk assessment, summary report, supplier assessment and periodic review for MGTrace itself, kept current with each release and available for your own computerised-system validation.
I/O lists, loop checks generated per signal into their protocol, pre-commissioning, FAT, SAT and functional testing — traced to the same specifications as the qualification protocols.
A site, its areas and systems. Every document and protocol belongs to a system, so traceability stays within it.
Start the URS from a template or from scratch, tag each requirement, send it for review and approval with electronic signatures. Decompose it into the FS and the DS, tracing each element to the one above.
IQ against the DS, OQ against the FS, PQ against the URS — or wherever your V-model puts them. Each test names the element it verifies.
Release a protocol for testing; record results and evidence on the released version; raise discrepancies where a test fails; sign each execution.
Open the traceability matrix for the audit: every requirement covered or not, every test traced or not, with the chain behind each cell.
No vendor names: what matters is the way of working. Spreadsheets and Word are what most validation departments actually use; a generic document or QMS suite is what they are usually offered instead.
| Spreadsheets & Word | Generic document / QMS suite | MGTrace | |
|---|---|---|---|
| Traceability between levels | A matrix maintained by hand; breaks when anything is renumbered. | Document-level links, if any; element-level tracing is rare. | Element-level, level by level, recomputed from the links — never maintained by hand. |
| Protocol execution | Printed, executed on paper, scanned; results typed back in. | Forms attached to a document; execution often outside the tool. | Executed on the released version, results and evidence in place, signed per execution. |
| Electronic signatures and audit trail | Wet signatures; no audit trail of the file. | Present, configured per project; scope varies. | Built in for every controlled record, with meaning, reason and hash chain. |
| Loop checks and I/O | A separate spreadsheet per contractor. | Not covered — commissioning lives elsewhere. | I/O list as a controlled document; loop checks generated from templates into a protocol, executed and signed, traced to the signal. |
| Time to first protocol | Immediate, and every project starts from zero again. | Weeks to months of configuration and validation of the tool. | The same afternoon: create the organization, load the worked example, start from a template. |
| Cost | Free, plus the hours. | Enterprise licence, per site or per year, quoted. | Free for the first 5 users; €39 per further user and month. |
Controlled records are versioned, time-stamped by the database, soft-deleted only and reconstructable from the audit trail.
Identity, meaning, reason, UTC time and a hash of what was signed; a re-authentication at the moment of signing; two-factor authentication available for every account.
Roles defined by your organization, a 15-minute inactivity log-off, lock-out after repeated failures, and every sign-in on record.
Database and files in the EU (Ireland); daily backups with a rehearsed restore, kept in a register you can show.