Skip to main content

Build custom Part 11 clinical agents. In a runtime regulators can audit.

A 21 CFR Part 11 environment for custom clinical AI agents — protocol amendments, site risk, SAE narratives, sponsor-specific SDTM. Every inference is logged at the token level. Every output hits the same Decision Queue as Core and Signal.

See the runtime
Token-level audit log21 CFR Part 11 runtimeWorks with Core + Signal
How it works

Four layers of control. Built into the runtime.

Most AI platforms bolt compliance on after the fact. Agent Studio starts from the regulatory requirement and builds up. These are not features you configure. They are guarantees the runtime enforces.

01

Token-level audit log

Every token sent to and received from the LLM is logged with timestamp, agent ID, model version, and tenant identity. Not a summary. Not a hash. The full trace: immutable, append-only, and available for inspection at any time.

02

CDISC-scoped context windows

Agents only see the data their task requires. Context windows are bounded by domain, study, and role, enforced before the first token is sent. There is no path from one study's data to another's. No cross-tenant leakage by design.

03

Decision Queue integration

Every custom agent output routes through the same human-approval gate as Core and Signal. You cannot deploy an autonomous output without an explicit approval step in the chain. The Decision Queue is not optional. It is the architecture.

04

Validation packages included

Every agent deployment ships with a Part 11 validation package your QA team can sign off. IQ/OQ/PQ documentation, risk assessment, and traceability matrix, generated from the agent's own audit trail. Not written separately after the fact.

What you can build

Six agents sponsors have already asked us to build.

These are the custom agents that come up on every Enterprise call. With Agent Studio, your team builds them in the same compliant environment as Core and Signal, not as one-off scripts but as auditable, versioned, production agents.

01

Protocol amendment agent

Detects changes in an amended protocol PDF and propagates them downstream, flagging affected CRF fields, SDTM mappings, and edit checks for human review. What used to take a DM team a week to audit manually becomes a Decision Queue of targeted items.

02

Site risk-scoring agent

Synthesizes enrollment pace, protocol deviation rate, query aging, and monitoring-visit history into a per-site risk score. Clinical Ops sees ranked sites before the next monitoring window. Not after the damage is done.

03

Regulatory intelligence agent

Monitors FDA and EMA guidance document feeds. When a new guidance matches a term in your submission portfolio, it surfaces the relevant sections and maps them to your open studies. Your Regulatory Affairs team gets signal, not noise.

04

SAE narrative drafting agent

Pre-fills expedited report narratives from AE data, medical history, and concomitant medications, in MedWatch and CIOMS format. Your Medical Monitor edits a draft instead of writing from scratch. The source citations are embedded in every sentence.

05

Custom SDTM mapping agent

For sponsor-specific domains or controlled terminology extensions not covered by CDISC Library, build a mapping agent trained on your standards. Confidence-scored output routes to your DM lead for review. Same Decision Queue, same audit trail.

06

Data reconciliation agent

Compares EDC data against lab vendor transfers, ePRO feeds, and central reader outputs. Surfaces discrepancies with source context attached. Query proposals are generated with the data side-by-side. Reviewers confirm, not investigate.

The runtime

The same infrastructure that runs Core.

Agent Studio is not a sandbox. It is the same Temporal-based workflow runtime that powers the Core pipeline, with the same per-tenant isolation, the same append-only audit store, and the same confidence-gating architecture. Custom agents are first-class citizens.

Workflow orchestration

Temporal-based. Every agent runs as an isolated activity with its own retry policy, concurrency limit, and timeout. Failures are captured with full context. No silent errors.

Per-call token logging

Every token in, every token out, logged to an append-only Postgres table with agent ID, model version, tenant identity, and a wall-clock timestamp. Queryable by your compliance team at any time.

Context-window contracts

Agents declare their input schema in JSON Schema. The runtime validates inputs before the LLM call. Agents cannot receive data outside their declared contract. Enforced, not documented.

Confidence gating

Your agent declares its confidence model. The runtime enforces threshold gates: outputs below your configured threshold route to the Decision Queue automatically. No manual monitoring required.

Version control + rollback

Every agent version is immutable. Any version can be rolled back with full replay of the audit log against the restored version. Your QA team can re-validate in minutes, not weeks.

Part 11 validation package

Generated from the agent's own audit trail. IQ/OQ/PQ documentation, risk assessment, and traceability matrix are produced at deployment time and updated on every version change.

Integration

Custom agents that work inside the OS.

Agent Studio agents are not isolated scripts. They share the Core data layer, write to the Signal read layer, and live in the same audit trail as every other agent in the pipeline.

Read from Core

Access USDM output, SDTM mappings, and Define-XML artifacts from the Core pipeline. Your agents pick up where Core leaves off.

Write to Decision Queue

Custom agent outputs appear in the same Decision Queue as Core. Your DM team reviews everything in one place. One workflow, one audit trail.

Publish to Signal

Surface custom narratives and metrics to role-aware Signal views. Your Protocol Amendment agent's output can appear in the Regulatory Signal tab automatically.

Common questions

What QA asks before a custom agent ships.

Agent Studio is the same Temporal-based runtime that runs Core: token-level logging of every inference, CDISC-scoped context windows, a mandatory Decision Queue, and an IQ/OQ/PQ validation package generated from the agent's own audit trail. Compliance is enforced by the runtime, not documented after the fact.
Sponsors typically ask for protocol-amendment propagation, site risk-scoring, regulatory-intelligence monitoring, SAE narrative drafting, sponsor-specific SDTM mapping, and data reconciliation across EDC, labs, and ePRO. Each agent is versioned, auditable, and reviewed in the same Decision Queue as Core.
A base model has no CDISC contract, no per-study isolation, and no Part 11 signature. Agent Studio bounds the context window by domain, study, and role before the first token is sent, logs every token, and will not deploy an output without an explicit human approval step.
Yes. Custom agents read USDM, SDTM, and Define-XML from Core, write reviews to the shared Decision Queue, and can publish narratives into role-aware Signal views. They are first-class citizens of the same OS, not shadow scripts.

What would you build?

Tell us the agent you've been wishing existed. If it can be built in a compliant, auditable way on top of clinical data, we want to show you how.

Send us your use case