Individual user accounts
Users sign in with named accounts associated with their organisation and assigned role. Shared credentials should not be used for controlled approvals.
SOPManagerPRO combines organisation-scoped access, controlled workflows, auditability and security-focused account controls with quality-system governance. These controls support customer security and compliance programmes; they do not replace supplier qualification, intended-use validation or organisation-specific risk assessment.
Authentication and role governance are designed around individual accountability rather than shared access.
Users sign in with named accounts associated with their organisation and assigned role. Shared credentials should not be used for controlled approvals.
TOTP authenticator-based 2FA is supported, and organisations can require users to enable it according to their security policy.
Repeated failed sign-in attempts trigger temporary account lockout. Successful authentication regenerates the session identifier.
The platform keeps governance evidence close to the records, approvals and users it relates to.
Significant document, user, approval and administrative activity is recorded for traceability and can be subjected to formal audit-trail review.
Periodic access-review workflows help organisations review whether user roles and permissions remain appropriate under least-privilege principles.
Approval actions can require re-authentication and capture signer identity and signature meaning such as Reviewed, Approved or Authorized.
SOPManagerPRO is a multi-company platform. Customer records and user access are scoped to the relevant organisation workspace, while privileged platform administration remains separately controlled.
The platform includes governance areas for computerised systems, suppliers, backup verification, restore tests and business-continuity evidence so customers can connect technical operation to their quality system.
Maintain system ownership, validation status, supplier/service-provider information and review evidence in an Annex 11-oriented governance workflow.
Record backup-verification and restore-test evidence according to the organisation's approved continuity and recovery procedures.
Optional AI-assisted features are subject to intended-use governance and human review. AI output is not an approval, certification or regulatory decision.
Regulated organisations should define intended use, perform supplier qualification, configure roles and workflows, test critical functions, document deviations and approve the configured system under their own validation procedure. Contact SOPManagerPRO to discuss the validation-support evidence currently available for your implementation.
Talk to us about intended use, onboarding, access governance or available implementation evidence.