Product
The validation pack
On this page ยท 4 sections
A regulated site (21 CFR Part 11, EU Annex 11, GAMP 5) validates the system it puts a record on: that it is installed as specified, that it operates as specified, that it performs in the process. The vendor's part of that is a documented system with the evidence that it was tested; Scada Studio generates it from what the repository already knows, for every release.
What is in it
| File | What it is |
|---|---|
| 00-README.md | The system, the versions, how the evidence was made, how to use the pack |
| 01-IQ.md | Installation Qualification: a checklist for the station. The rows the script can verify on the machine it runs on are filled in - Node.js, the platform, the download's SHA-256 and signature, the installed files against the SBOM's hashes, the agent's configuration (authentication, TLS, the code policy, the policy on pages, the origins, the licence); the rest are manual rows with initials and date |
| 02-OQ.md | Operational Qualification: every automated check of the release as a test case with its result, grouped by the requirement it evidences, and the full list; the raw outputs are in evidence/ |
| 03-PQ-template.md | Performance Qualification: the procedures a site runs on its own apps and stations - publishing, access, live data, writes, signed writes, alarms, logs, rollback, time, backup - as blank tables |
| 04-traceability.md | The requirements traced to the design (the documentation page) and to the tests, with the coverage; a requirement no passing check covers is said to be not covered |
| 05-records.md | Time, records and signatures: what a timestamp is, what the trail keeps, what a signature carries and how it is verified, retention |
| pack.json, index.html, .pdf | The same, machine-readable, as one page, and printed |
How it is made
npm run studio:validation -- --zip dist/scada-studio-1.18.0.zip --config /path/to/agent.config.json --pdf
scripts/build-validation-pack.js runs the three check suites (or reads their saved outputs with --from), matches every check against the requirements in studio/validation/requirements.json - each requirement names the documentation page that describes its design and the checks that are its evidence - gathers the installation facts it can, and writes the pack to dist/validation-pack-<version>/. The pack never claims what the checks did not show: a requirement without a passing check is reported as not covered, and the script exits non-zero when any check failed.
The requirements
Thirty-five, in the areas access control, network, code, audit trail, 21 CFR Part 11, licensing, data acquisition, applications, operations and the designer. They are the vendor's requirements of the product, written so that a site's user requirement specification can point at them; a site adds its own and traces them in the PQ.
What the pack is not
It is not the site's validation. The IQ is signed on the station, the PQ is written for the app and the process and run there, the deviations are the site's to assess, and the retention of the pack, the trail and the logs is the site's policy. The security page has the threat model and the development practices the pack rests on; the support page has the long-term support line a validated station stays on.