
Part 11 Signatures
Each signature binds identity, meaning, action, and timestamp, with re-authentication required at the point of signing. A human-readable signature manifestation records who signed, what they signed, the meaning, and when.
Review-Gated Workflows
Records move through review, approval, and signature before they enter the validated record. Multi-signer flows support an author, a reviewer, and an approver signing in sequence, with every signature event recorded in the audit trail.
Role-Based Access Control
Six fixed roles scope access to tenant and product, and a single user can hold different roles for different systems. Authentication is SSO-only with MFA enforced, and the Auditor role is hard read-only.

