Audit-ready by default.
The record is written as the work happens. Every add and every edit is logged with who, what, when, the browser and the address. Every form response is timestamped and attributed to an authenticated person. A correction is a cross-out, and the cross-out is signed too.
Training records that write themselves.
When an instruction reaches a new revision, the next operator to open it is asked to acknowledge it, and the acknowledgment is tied to the revision, the person, the kiosk and the job. When policy wants a second signature, the supervisor certifies at the kiosk. Assessments carry their own pass thresholds, and a failed one waits for a supervisor to resolve it, on the record, before the work continues.
One revision on the floor.
Instructions are revision-controlled and role-filtered. An approved instruction is locked; a change is a new revision, and the old one stays on file with the training that was done against it. The operator sees only what applies to this job and this role.
Nonconformance to corrective action, linked.
Nonconformances, customer complaints, returns and corrective actions live beside the jobs and items they concern, with the photos taken at the kiosk as evidence. The quality dashboard reads from the same records the operators wrote.
The standards, by name.
ISO 9001 and 13485, FDA 21 CFR Parts 11 and 820, AS9100, IATF 16949, ITAR: the same questions in different binders. Who was trained, on which revision, what was measured, who signed, when. MOLI answers them from the record, and the security overview explains how that record is protected.
| Standard | Domain |
|---|---|
| ISO 9001 | Quality management (baseline) |
| ISO 13485 | Medical devices |
| FDA 21 CFR Part 11 | Electronic records and electronic signatures |
| FDA 21 CFR Part 820 | Medical device quality system |
| AS9100 | Aerospace |
| IATF 16949 | Automotive |
| ISO/TS 22163 | Rail and transport |
| ISO 22000 / HACCP | Food safety |
| ITAR / EAR / C-TPAT | International trade: visitor citizenship capture, need-to-know access |
| NIST SP 800-171 / DoD CMMC | Cybersecurity and defense, through identity integrations and MFA |
What quality looks at first
- Training verifications: each acknowledgment tied to its revision and its person.
- Forms: attribution, timestamps and cross-outs built in.
- The audit log: every add and every edit, with who and when.
- Quality management: NCRs, complaints, RMAs and CAPA in one place.