Home / Technology / acaDMY
Electronic Quality Management System
The eQMS an auditor actually wants to see.
A complete electronic Quality Management System — change control, CAPA, deviations, audits, risk, complaints, and supplier management on a 21 CFR Part 11 workflow engine — with controlled documents and workforce qualification built into the same system of record. Generate compliance evidence on demand.

acaDMY is K3's electronic Quality Management System — the system of record for how a GxP organization stays in control. Change control, CAPA, deviations and nonconformances, audits, risk, complaints, and supplier management all run on one configurable workflow engine, each step electronically signed, each record tamper-evident on a per-tenant hash chain. It is the software an auditor actually wants to see: not a binder describing intent, but the live system that enforces it.
Around that quality core sit controlled documents and workforce qualification — inseparable from quality in clinical research, so they live in the same platform rather than three disconnected tools. Documents move draft → review → approval with electronic signatures, immutable versions, and periodic review; approving a new version automatically resets acknowledgements, so retraining follows the document without anyone remembering to chase it.
Its most distinctive control is a site-ready gate: a worker moves from assigned, through training, to site-ready only when every required document and module is complete and in date — a guarded state machine whose invariant is 'all requirements current.' So when a sponsor or inspector asks whether the people on a study are qualified, the answer is a report produced on demand, and trusted when it is.
The invariant
Nobody reaches your site until every requirement is current
Site-readiness is a guarded state machine, not a checklist someone maintains. The gate only opens when every assigned document and training module is complete and in date — and it closes again on its own when something expires.
Conditional release is available as a time-boxed exception, and is itself tracked — it expires rather than quietly persisting.
What it does
Quality management
Change control, CAPA, deviation and nonconformance, audit management, risk, complaints, and supplier management — each electronically signed, with escalation into CAPA. The GxP quality processes, running as software.
Controlled documents
Draft to review to approval with electronic signature, immutable versions, effective dates, and periodic review scheduling. Approving a new version resets completed acknowledgements — retraining follows the document, automatically.
Workflow builder
A no-code builder for approval workflows: immutable versions, ordered steps, role-routed tasks, due dates, and signature requirements per step — so the QMS matches your SOPs, not the other way round.
Inspection readiness
Unified task queues, quality analytics on open and overdue items, and inspection-readiness reporting — the one-click evidence that turns an audit into a report.
Part 11 & tamper-evidence
Identity taken from the account, re-authentication at signing, recorded meaning, and a per-tenant hash chain with an independent verifier — append-only, tamper-evident records.
Training & qualification
Course authoring with SCORM and xAPI content, recurring cadences, and curricula resolved automatically from role, state, and client site — a requirements grid, not a spreadsheet someone maintains.
Site-ready workflow
A guarded state machine covering assignment, training, review, site-ready, time-boxed conditional exceptions, expiry, revocation, and offboarding.
Worker records
Completion records, competency, signatures, retention rules, and legal holds — with a one-click audit evidence packet per worker.
Where it's used
Vendor qualification
One-click compliance evidence for the staff proposed on your study. Clinical Resourcing & FSP →
Site-ready staffing
Training current across all 50 states before anyone is placed. Site Monitoring & Management →
eQMS
Change control, CAPA, and audits on one signed workflow engine.
Governance & compliance
- 21 CFR Part 11 signatures — signer identity taken from the account, re-authentication at signing, recorded meaning and reason, with multi-factor support
- Tamper-evident audit trail — a per-tenant hash chain over every event, with an independent verifier
- Append-only records — completion records, signatures, and audit events cannot be updated or deleted by the application
- Tenant isolation — enforced in the database itself through row-level security, not application convention
- Validation package — a GAMP 5 and FDA CSA risk-based package: validation plan, user requirements, risk assessment, IQ, OQ, PQ, traceability matrix, a Part 11 and data-integrity assessment, and a summary report, independently reviewed and approved
- Change control on itself — production changes are change-controlled, each record tied to a tagged release
- Role-based access — eight roles from learner through auditor to tenant administrator
Availability
In production at version 1.8, running K3's own compliance. Compliance evidence is available during vendor qualification; standalone licensing on request.
Built on
Next.js · PostgreSQL with row-level security · S3-compatible storage · xAPI learning record store · background job worker
See acaDMY on your own scenario.
An hour with the team that built and operates it — on a study shape you recognize. Never a requirement of working with K3, always an option.
Contact K3