Applications · IT and access
User Access Management
Employee details come from your HRMS if you connect it, or the requestor enters them in Quickflow UAM. Once the manager reviews and the system owner approves, Quickflow Vision creates the user on each selected system and proves every step with a screenshot. A Digital Scientist reviews who holds what and makes the case for every right that should go.
Where do the employee details come from?
HRMS · People · New joiner
Your HRMSPriya Shah
QC analyst · Quality control
- Employee ID
- E-10482
- Department
- Quality control
- Designation
- QC analyst
- Reporting manager
- A. Rao
- Date of joining
- 1 Oct
Step 1 of 8HR · in your HRMSHRMS integration only
HR adds the new joiner in the HRMS
Nothing changes for HR. They create the employee record in the HRMS as they do today. Because the HRMS is connected, the new-joiner event is sent to Quickflow UAM on its own: no form to fill, no email to forward.
Quickflow UAM at a glance
User access management for GxP systems: request, approve, then grant or remove access on every system automatically.
- Who uses it
- Requestors
- Managers
- System owners
- IT
- What is included
- Electronic access requests
- Joiner, mover, leaver
- Automatic account creation
- Who has access to what
- Instrument single sign-on
- Password vault
- Works with
- HRMS (optional)
- Active Directory
- Empower
- LIMS
- SAP
- Any Windows PC
- Built for
- 21 CFR Part 11
- EU Annex 11
- GAMP 5
- Role-based access
How it works
5 steps. Every one recorded.
- Step 1Details from HRMSSystem
- Step 2Requestor selects the systemsHuman decision
- Step 3Manager reviewsHuman decision
- Step 4System owner approvesHuman decision
- Step 5Vision runs on the selected systemsSystem
HRMS integration, if you want it
From HRMS, or straight into UAM. Systems chosen by the requestor.
If your HRMS is connected, Quickflow reads the new joiner's record, so nobody types it again. If not, the requestor raises the request in Quickflow UAM and types the details once. Either way, the requestor ticks the systems needed, the manager reviews, the system owner approves, and the request goes to the endpoints of each selected system. Role changes and exits follow the same path.
HRMS · employee record
- Employee
- Priya Shah
- Employee ID
- E-10482
- Department
- Quality control
- Designation
- QC analyst
- Reporting manager
- A. Rao
- Date of joining
- 1 Oct
Quickflow UAM · AR-7790 · New user request
- Details from HRMSAutomatic
- Requestor selects systemsRequestor
- Manager reviewsManager
- System owner approvesSystem owner
- Sent to the endpointsAutomatic
Employee details
- Employee
- Employee ID
- Department
- Designation
Systems required · chosen by the requestor
- Active Directory
- Empower
- LIMS
- SAP
- QMS
- Chromeleon
Submitted by the requestor
Sent to the endpoints of each selected system
- DC-01
- QC-HPLC-WS-03
- LIMS-APP-01
- SAP-GUI-02
Typed once at most
From the HRMS record when it is connected, otherwise entered once in UAM. Never re-typed into each system.
Only the systems chosen
The requestor ticks what the person needs, and only those systems receive the request.
Two sign-offs
The manager reviews, then the system owner approves, both with e-signatures.
Quickflow Vision · set up once
Do it once. Vision writes the script.
Quickflow Vision is the agent that sits on each endpoint. An administrator does the task once while Vision watches, and every click and keystroke becomes a step.
QC-HPLC-WS-03 · Lab application · User administration
Quickflow Vision · script
create-lab-user- 1Click "New user"
Vision writes a step for every click and keystroke. Where a value will change, it asks.
Record, do not code
The person who knows the system shows Vision how it is done. No scripting skills needed.
Values come from the form
Names, IDs and roles that change per request are linked to Quickflow Forms fields.
Scripts are controlled
Each script is versioned and approved before it can run on any endpoint.
Rules and conditions
The rules pick where it runs
Scripts are assigned to endpoints by rules, not by hand. Conditions decide when it is safe to run, so an analysis in progress is never interrupted.
Quickflow UAM · assignment rule
Approved- Whenthe system owner has approved a New user request
- andEmpower is one of the selected systems
- andthe site is Ahmedabad QC
- Runcreate-lab-user v1 on endpoints tagged Empower · QC
- Only ifthe endpoint is online and no analysis is running
QC-HPLC-WS-01
Empower · QC
QC-HPLC-WS-02
Empower · QC
QC-HPLC-WS-03
Empower · QC
QC-GC-WS-01
Chromeleon · QC
RD-HPLC-WS-07
Empower · R&D
MB-LAB-PC-04
Micro lab
LIMS-APP-01
LIMS server
SAP-GUI-02
SAP terminal
DC-01
Active Directory
Endpoints are tagged
By system, site, department or lab. A new workstation joins the right rules the day it is tagged.
Rules read the request
The request type and the systems the requestor selected choose the script and the endpoints.
Conditions protect the lab
Held until the endpoint is online and free, then released and run without anyone chasing it.
A Digital Scientist for access
It reads who holds what, finds what should not be there, and you approve
Agentic AI would run the access request. A Digital Scientist understands whether the access should exist: it reads every account in every system, sets it against the job, the HRMS record and data integrity rules, and makes the case for each change. The system owner approves, and Vision carries it out.
1. Read every account
Digital ScientistUser lists pulled from each system by Vision, set against HRMS and the role matrix.
2. Spot what does not fit
Digital ScientistLeavers still active, unused accounts, rights beyond the job and duties that must stay apart.
3. Check each request
Digital ScientistA requested role is compared with the role matrix and with peers in the same job before the manager sees it.
4. Make the case
Digital ScientistEach finding comes with its evidence and a change request ready to route.
5. You decide
Your teamThe manager and system owner approve; Vision makes the change and proves it.
Periodic review, prepared
Accounts from every system reconciled with HRMS and the role matrix before the reviewer opens the review.
Segregation of duties
Conflicting rights, such as acquiring and approving the same result, are flagged in each system.
Leavers and movers
People who left or changed jobs are matched to the accounts they still hold, so nothing stays open after a transfer.
Dormant accounts
Unused accounts are found and their licences freed, with the last sign-in behind each one.
The right role on request
Unusual rights on a new request are flagged for the manager, with the role the matrix expects.
It never grants access
It prepares requests; it never grants or removes a right. Approvers sign, and Vision runs and records the change.
Every finding, recommendation and signature is in the audit trail. See the Digital Scientist Trust Charter.
One connected loop
HRMS fills it. UAM approves it. Vision does it.
Quickflow Vision is connected to the Quickflow UAM application. Only a request the system owner has approved becomes a job, and every result comes back with its evidence.
HRMS
Employee details
Quickflow Forms
Where requests start
- Employee details from HRMS
- Requestor selects the systems needed
- Every changing value captured once
Quickflow UAM
Where it is decided and recorded
- Manager review, system owner approval
- Sends each selected system to its endpoints
- Job queue, retries and holds
- Access register and audit trail
Quickflow Vision
Where the work is done
- Agent on each endpoint
- Runs the approved script version
- Captures a screenshot per step
- Reports success or the exact failure
Value add · single sign-on for instruments
One Windows login. Every instrument signs them in.
The analyst signs in to the instrument PC with their Active Directory account. Straight away, Quickflow Vision opens the instrument software and signs them in as themselves. Nobody types, shares or writes down an instrument password.
- 1Windows sign-in with ADThe analyst signs in to the instrument PC with their own Active Directory account.
- 2Vision opens the instrument softwareStraight after Windows sign-in, Quickflow Vision launches the instrument software for that analyst. Nobody waits at a login screen.
- 3Vision signs them inVision completes the instrument login as that analyst. The credentials are never shown, typed or shared.
- 4Ready as themselvesThe analyst lands in the software under their own name, and the sign-in is logged.
QC-HPLC-WS-03 · instrument PC
P. Shah
CORP\psha · Active Directory
Verified by Active Directory
- 09:14:02Windows sign-in · CORP\psha · verified by Active Directory
- 09:14:03Empower opened on QC-HPLC-WS-03 for psha by Quickflow Vision
- 09:14:05Empower login completed by Vision · credentials never displayed
- 09:14:06Signed in to Empower as psha
No shared passwords
Analysts never see or type instrument passwords, so they cannot pass them on or write them down.
Every entry is attributable
Each analyst is signed in as themselves, so the instrument audit trail names the right person.
Leave AD, lose access
Disable the Active Directory account and instrument sign-in stops with it, on every workstation.
How instrument credentials are stored and protected is covered in an architecture note we share with your IT and security teams during evaluation.
Beyond user accounts
If a person can do it on the endpoint, Vision can run it
Creating, changing and deactivating users is where most teams start. The same record, approve and run loop works for any approved task on any endpoint.
Create a user
A new starter in every system from one request
Change a role
Transfers and promotions, rights follow the role
Deactivate on exit
Every system on the same day, with proof
Reset or unlock
Back into the system without a ticket queue
Archive instrument data
Scientific Rawdata copied from the instrument PC to the archive and checked
Create a folder
Project or study folders with the standard structure
Set folder permissions
Project shares opened and closed by role
Apply instrument settings
An approved configuration set on the workstation
Pull users for review
User lists exported from each system for periodic review
Your own task
Tell us what your team repeats on endpoints today.
Talk to us
Every task follows the same rule: nothing runs until the request is approved, and every run leaves an audit trail with screenshots.
Before and after
Paper forms, then Quickflow UAM
The same new starter, twice. One request is a paper form walking between desks. The other starts from HRMS, or from one form in UAM, and is finished while the first is still waiting for a signature.
Today
- Day 1
- Day 2–3
- Day 5
- Day 8–12
- Day 14
Paper form filled in: Waiting in an in-tray
With Quickflow UAM
- 09:00
- 09:02
- 10:30
- 13:15
- 13:25
Details from HRMS or UAM form: Read from HRMS, or typed once in UAM
Time to access, same new starter
Typical timeline, illustrative. Not a measured result.
Employee details are copied by hand onto every form
Details come from HRMS, or are typed once in UAM; the requestor ticks the systems
Paper forms walk from desk to desk for signatures
The manager reviews and the system owner approves online, e-signed
An administrator re-types the same details into every system
Vision types them from the approved form, the same way each time
IT hears about a leaver late, and accounts stay open
The exit starts from the HRMS record, or a removal request in UAM, and every selected system is deactivated, with proof
Nobody can say where a request is
Live status for every request and every endpoint
The audit trail is a filing cabinet
Every action is time-stamped, attributed and screenshotted
Features
What is in the box
Seven capabilities, each shown working. Pick one, or let them play.
Quickflow UAM · Electronic access request
Electronic access request
Employee details from HRMS; the requestor only ticks the systems.
Employee · from HRMS
Systems · chosen by the requestor
Reviewer and approver
Compliance built in
Inspection-ready by default
Access is one of the first things an inspector asks about. Every answer is already a record, not a search through paper.
- 21 CFR Part 11 audit trail
- Electronic signatures
- Role-based access
- EU Annex 11 · GAMP 5
- Web-based, any location
Mock inspection
Inspector
Illustrative records with placeholder names.
Industries
Wherever access to a GxP system has to be proven
Across life sciences plants, laboratories and offices, for every system that holds GxP data.
Pharmaceuticals
Access to LIMS, CDS, ERP and instrument PCs across plants and labs.
Biotechnology
Many systems per suite, with access that changes as people move between projects.
API manufacturers
Plant, lab and utility systems, with leavers removed from all of them the same day.
CDMOs
Client-dedicated systems, where only named people may have access.
CROs
Sponsor-specific systems, with access granted per study and removed when it ends.
Medical devices
Design, production and quality systems under ISO 13485 and Part 11.
Full overview: User Access Management
When we speak of the pharmaceutical industry, effective User Access Management (UAM) plays a pivotal role in ensuring compliance, security, and operational efficiency. This sector, governed by strict Good Manufacturing Practices Ensuring compliance with industry standards and regulatory requirements is paramount in the pharmaceutical sector.
The User Access Management (UAM) Procedure delineates a comprehensive approach to issuing, modifying, revoking, and reviewing user access rights, ensuring the safeguarding of business information assets and systems' confidentiality, security, and privacy. This streamlined process not only enhances security measures but also contributes to the optimization of the IT team's efforts, ultimately boosting productivity.
Leveraging Robotics Process Automation (RPA), UAM facilitates the creation and modification of user access rights based on roles or functions in various instruments or systems.
Additionally, it seamlessly deactivates users during employee offboarding, minimizing operational hassles. The IT team benefits from centralized management of user access rights, application and software licenses, and their utilization, providing an efficient solution for overseeing software and application licenses. UAM further establishes connectivity with internal and external systems (Li'ke SAP ) , through RPA, ensuring a cohesive and integrated user access management experience.
QuickFlow's UAM software, by linking with Active Directory and adhering to security regulations, provides assurance of compliance, reducing the risk of regulatory observations, including FDA 483.
IT and access
Related applications
See Quickflow UAM on your own process.
Tell us how this runs in your organisation today and we will walk through the application against it, with your QA and IT teams in the room.