Skip to content

Applications · IT and access

Quickflow UAM

User Access Management

Employee details come from your HRMS if you connect it, or the requestor enters them in Quickflow UAM. Once the manager reviews and the system owner approves, Quickflow Vision creates the user on each selected system and proves every step with a screenshot. A Digital Scientist reviews who holds what and makes the case for every right that should go.

Where do the employee details come from?

HRMS · People · New joiner

Your HRMS

Priya Shah

QC analyst · Quality control

Joining 1 Oct
Employee ID
E-10482
Department
Quality control
Designation
QC analyst
Reporting manager
A. Rao
Date of joining
1 Oct
Received by Quickflow UAM · request AR-7790 opened

Step 1 of 8HR · in your HRMSHRMS integration only

HR adds the new joiner in the HRMS

Nothing changes for HR. They create the employee record in the HRMS as they do today. Because the HRMS is connected, the new-joiner event is sent to Quickflow UAM on its own: no form to fill, no email to forward.

Quickflow UAM at a glance

User access management for GxP systems: request, approve, then grant or remove access on every system automatically.

Who uses it
  • Requestors
  • Managers
  • System owners
  • IT
What is included
  • Electronic access requests
  • Joiner, mover, leaver
  • Automatic account creation
  • Who has access to what
  • Instrument single sign-on
  • Password vault
Works with
  • HRMS (optional)
  • Active Directory
  • Empower
  • LIMS
  • SAP
  • Any Windows PC
Built for
  • 21 CFR Part 11
  • EU Annex 11
  • GAMP 5
  • Role-based access

How it works

5 steps. Every one recorded.

  1. Step 1Details from HRMSSystem
  2. Step 2Requestor selects the systemsHuman decision
  3. Step 3Manager reviewsHuman decision
  4. Step 4System owner approvesHuman decision
  5. Step 5Vision runs on the selected systemsSystem

HRMS integration, if you want it

From HRMS, or straight into UAM. Systems chosen by the requestor.

If your HRMS is connected, Quickflow reads the new joiner's record, so nobody types it again. If not, the requestor raises the request in Quickflow UAM and types the details once. Either way, the requestor ticks the systems needed, the manager reviews, the system owner approves, and the request goes to the endpoints of each selected system. Role changes and exits follow the same path.

HRMS · employee record

New joiner
Employee
Priya Shah
Employee ID
E-10482
Department
Quality control
Designation
QC analyst
Reporting manager
A. Rao
Date of joining
1 Oct
Maintained in HRMS as usual

Quickflow UAM · AR-7790 · New user request

  1. Details from HRMS
  2. Requestor selects systems
  3. Manager reviews
  4. System owner approves
  5. Sent to the endpoints

Employee details

Employee
Employee ID
Department
Designation

Systems required · chosen by the requestor

  • Active Directory
  • Empower
  • LIMS
  • SAP
  • QMS
  • Chromeleon

Submitted by the requestor

Manager · A. RaoWaiting
System owner · K. IyerWaiting

Sent to the endpoints of each selected system

  • DC-01
  • QC-HPLC-WS-03
  • LIMS-APP-01
  • SAP-GUI-02
  • Typed once at most

    From the HRMS record when it is connected, otherwise entered once in UAM. Never re-typed into each system.

  • Only the systems chosen

    The requestor ticks what the person needs, and only those systems receive the request.

  • Two sign-offs

    The manager reviews, then the system owner approves, both with e-signatures.

Quickflow Vision · set up once

Do it once. Vision writes the script.

Quickflow Vision is the agent that sits on each endpoint. An administrator does the task once while Vision watches, and every click and keystroke becomes a step.

QC-HPLC-WS-03 · Lab application · User administration

Recording
New userEditDisable
ProjectsQC_AssayQC_Stability
CancelSave

Quickflow Vision · script

create-lab-user
  1. 1Click "New user"

Vision writes a step for every click and keystroke. Where a value will change, it asks.

  • Record, do not code

    The person who knows the system shows Vision how it is done. No scripting skills needed.

  • Values come from the form

    Names, IDs and roles that change per request are linked to Quickflow Forms fields.

  • Scripts are controlled

    Each script is versioned and approved before it can run on any endpoint.

Rules and conditions

The rules pick where it runs

Scripts are assigned to endpoints by rules, not by hand. Conditions decide when it is safe to run, so an analysis in progress is never interrupted.

Quickflow UAM · assignment rule

Approved
  1. Whenthe system owner has approved a New user request
  2. andEmpower is one of the selected systems
  3. andthe site is Ahmedabad QC
  4. Runcreate-lab-user v1 on endpoints tagged Empower · QC
  5. Only ifthe endpoint is online and no analysis is running
0 of 9 endpoints match
  • QC-HPLC-WS-01

    Empower · QC

  • QC-HPLC-WS-02

    Empower · QC

  • QC-HPLC-WS-03

    Empower · QC

  • QC-GC-WS-01

    Chromeleon · QC

  • RD-HPLC-WS-07

    Empower · R&D

  • MB-LAB-PC-04

    Micro lab

  • LIMS-APP-01

    LIMS server

  • SAP-GUI-02

    SAP terminal

  • DC-01

    Active Directory

  • Endpoints are tagged

    By system, site, department or lab. A new workstation joins the right rules the day it is tagged.

  • Rules read the request

    The request type and the systems the requestor selected choose the script and the endpoints.

  • Conditions protect the lab

    Held until the endpoint is online and free, then released and run without anyone chasing it.

A Digital Scientist for access

It reads who holds what, finds what should not be there, and you approve

Agentic AI would run the access request. A Digital Scientist understands whether the access should exist: it reads every account in every system, sets it against the job, the HRMS record and data integrity rules, and makes the case for each change. The system owner approves, and Vision carries it out.

  1. 1. Read every account

    Digital Scientist

    User lists pulled from each system by Vision, set against HRMS and the role matrix.

  2. 2. Spot what does not fit

    Digital Scientist

    Leavers still active, unused accounts, rights beyond the job and duties that must stay apart.

  3. 3. Check each request

    Digital Scientist

    A requested role is compared with the role matrix and with peers in the same job before the manager sees it.

  4. 4. Make the case

    Digital Scientist

    Each finding comes with its evidence and a change request ready to route.

  5. 5. You decide

    Your team

    The manager and system owner approve; Vision makes the change and proves it.

Digital Scientist · access review· Quality control · Q3
Accounts reviewed808 across 5 systems
  • Periodic review, prepared

    Accounts from every system reconciled with HRMS and the role matrix before the reviewer opens the review.

  • Segregation of duties

    Conflicting rights, such as acquiring and approving the same result, are flagged in each system.

  • Leavers and movers

    People who left or changed jobs are matched to the accounts they still hold, so nothing stays open after a transfer.

  • Dormant accounts

    Unused accounts are found and their licences freed, with the last sign-in behind each one.

  • The right role on request

    Unusual rights on a new request are flagged for the manager, with the role the matrix expects.

  • It never grants access

    It prepares requests; it never grants or removes a right. Approvers sign, and Vision runs and records the change.

Every finding, recommendation and signature is in the audit trail. See the Digital Scientist Trust Charter.

One connected loop

HRMS fills it. UAM approves it. Vision does it.

Quickflow Vision is connected to the Quickflow UAM application. Only a request the system owner has approved becomes a job, and every result comes back with its evidence.

HRMS

Employee details

Quickflow Forms

Where requests start

  • Employee details from HRMS
  • Requestor selects the systems needed
  • Every changing value captured once

Quickflow UAM

Where it is decided and recorded

  • Manager review, system owner approval
  • Sends each selected system to its endpoints
  • Job queue, retries and holds
  • Access register and audit trail

Quickflow Vision

Where the work is done

  • Agent on each endpoint
  • Runs the approved script version
  • Captures a screenshot per step
  • Reports success or the exact failure

Value add · single sign-on for instruments

One Windows login. Every instrument signs them in.

The analyst signs in to the instrument PC with their Active Directory account. Straight away, Quickflow Vision opens the instrument software and signs them in as themselves. Nobody types, shares or writes down an instrument password.

  1. 1Windows sign-in with ADThe analyst signs in to the instrument PC with their own Active Directory account.
  2. 2Vision opens the instrument softwareStraight after Windows sign-in, Quickflow Vision launches the instrument software for that analyst. Nobody waits at a login screen.
  3. 3Vision signs them inVision completes the instrument login as that analyst. The credentials are never shown, typed or shared.
  4. 4Ready as themselvesThe analyst lands in the software under their own name, and the sign-in is logged.

QC-HPLC-WS-03 · instrument PC

Vision agent
PS

P. Shah

CORP\psha · Active Directory

Verified by Active Directory

  • 09:14:02Windows sign-in · CORP\psha · verified by Active Directory
  • 09:14:03Empower opened on QC-HPLC-WS-03 for psha by Quickflow Vision
  • 09:14:05Empower login completed by Vision · credentials never displayed
  • 09:14:06Signed in to Empower as psha
  • No shared passwords

    Analysts never see or type instrument passwords, so they cannot pass them on or write them down.

  • Every entry is attributable

    Each analyst is signed in as themselves, so the instrument audit trail names the right person.

  • Leave AD, lose access

    Disable the Active Directory account and instrument sign-in stops with it, on every workstation.

How instrument credentials are stored and protected is covered in an architecture note we share with your IT and security teams during evaluation.

Beyond user accounts

If a person can do it on the endpoint, Vision can run it

Creating, changing and deactivating users is where most teams start. The same record, approve and run loop works for any approved task on any endpoint.

  • Create a user

    A new starter in every system from one request

  • Change a role

    Transfers and promotions, rights follow the role

  • Deactivate on exit

    Every system on the same day, with proof

  • Reset or unlock

    Back into the system without a ticket queue

  • Archive instrument data

    Scientific Rawdata copied from the instrument PC to the archive and checked

  • Create a folder

    Project or study folders with the standard structure

  • Set folder permissions

    Project shares opened and closed by role

  • Apply instrument settings

    An approved configuration set on the workstation

  • Pull users for review

    User lists exported from each system for periodic review

  • Your own task

    Tell us what your team repeats on endpoints today.

    Talk to us

Every task follows the same rule: nothing runs until the request is approved, and every run leaves an audit trail with screenshots.

Before and after

Paper forms, then Quickflow UAM

The same new starter, twice. One request is a paper form walking between desks. The other starts from HRMS, or from one form in UAM, and is finished while the first is still waiting for a signature.

Today

ElapsedDay 1Hand-offs: 0Values re-typed: 0
  1. Day 1
  2. Day 2–3
  3. Day 5
  4. Day 8–12
  5. Day 14

Paper form filled in: Waiting in an in-tray

With Quickflow UAM

Day 109:00Paper forms: 0Values re-typed: 0
  1. 09:00
  2. 09:02
  3. 10:30
  4. 13:15
  5. 13:25

Details from HRMS or UAM form: Read from HRMS, or typed once in UAM

Time to access, same new starter

Paper forms
Day 1…
Quickflow UAM
Day 1, in progress
Day 1Day 7Day 14

Typical timeline, illustrative. Not a measured result.

  • Employee details are copied by hand onto every form

    Details come from HRMS, or are typed once in UAM; the requestor ticks the systems

  • Paper forms walk from desk to desk for signatures

    The manager reviews and the system owner approves online, e-signed

  • An administrator re-types the same details into every system

    Vision types them from the approved form, the same way each time

  • IT hears about a leaver late, and accounts stay open

    The exit starts from the HRMS record, or a removal request in UAM, and every selected system is deactivated, with proof

  • Nobody can say where a request is

    Live status for every request and every endpoint

  • The audit trail is a filing cabinet

    Every action is time-stamped, attributed and screenshotted

Features

What is in the box

Seven capabilities, each shown working. Pick one, or let them play.

Quickflow UAM · Electronic access request

Electronic access request

Employee details from HRMS; the requestor only ticks the systems.

Employee · from HRMS

Systems · chosen by the requestor

Reviewer and approver

No paper, no printer, any locationSubmit request
Illustrative screens with placeholder names.

Compliance built in

Inspection-ready by default

Access is one of the first things an inspector asks about. Every answer is already a record, not a search through paper.

  • 21 CFR Part 11 audit trail
  • Electronic signatures
  • Role-based access
  • EU Annex 11 · GAMP 5
  • Web-based, any location
How we prove it

Mock inspection

Inspector

Illustrative records with placeholder names.

Industries

Wherever access to a GxP system has to be proven

Across life sciences plants, laboratories and offices, for every system that holds GxP data.

  • Pharmaceuticals

    Access to LIMS, CDS, ERP and instrument PCs across plants and labs.

  • Biotechnology

    Many systems per suite, with access that changes as people move between projects.

  • API manufacturers

    Plant, lab and utility systems, with leavers removed from all of them the same day.

  • CDMOs

    Client-dedicated systems, where only named people may have access.

  • CROs

    Sponsor-specific systems, with access granted per study and removed when it ends.

  • Medical devices

    Design, production and quality systems under ISO 13485 and Part 11.

Full overview: User Access Management

When we speak of the pharmaceutical industry, effective User Access Management (UAM) plays a pivotal role in ensuring compliance, security, and operational efficiency. This sector, governed by strict Good Manufacturing Practices Ensuring compliance with industry standards and regulatory requirements is paramount in the pharmaceutical sector.

The User Access Management (UAM) Procedure delineates a comprehensive approach to issuing, modifying, revoking, and reviewing user access rights, ensuring the safeguarding of business information assets and systems' confidentiality, security, and privacy. This streamlined process not only enhances security measures but also contributes to the optimization of the IT team's efforts, ultimately boosting productivity.

Leveraging Robotics Process Automation (RPA), UAM facilitates the creation and modification of user access rights based on roles or functions in various instruments or systems.

Additionally, it seamlessly deactivates users during employee offboarding, minimizing operational hassles. The IT team benefits from centralized management of user access rights, application and software licenses, and their utilization, providing an efficient solution for overseeing software and application licenses. UAM further establishes connectivity with internal and external systems (Li'ke SAP ) , through RPA, ensuring a cohesive and integrated user access management experience.

QuickFlow's UAM software, by linking with Active Directory and adhering to security regulations, provides assurance of compliance, reducing the risk of regulatory observations, including FDA 483.

IT and access

Related applications

See Quickflow UAM on your own process.

Tell us how this runs in your organisation today and we will walk through the application against it, with your QA and IT teams in the room.