Skip to content

AI agents for pharmacovigilance and GxP

An agent called a serious case routine. The 15-day clock ran out before anyone looked.

A blown reporting clock is a dated, inspectable failure, and the QPPV answers for it personally. When the investigation asks who, or what, made the seriousness call, the CRO just promises its agent behaved. Our agent clears the routine cases and drafts the hard ones, then stops: the call that starts the 15-day clock stays with a named safety physician, never the agent. An inspector recomputes the file offline, with no access to your systems, and reads who owned the call and the timestamp it locked to.

Life sciences is one vertical of a domain-neutral engine. MakerChecker is the independent referee for any AI agent taking high-consequence actions. It enforces in code, outside the model, that the agent proposing an irreversible action cannot approve its own work, a hard 403, not a prompt-level promise, and commits every decision to a signed, hash-chained record an outside inspector recomputes offline. The pharmacovigilance, MDR, and cold-chain flows below are that same engine pointed at your safety and quality queue. See the general referee →

What keeps you up at night

The agent is the easy part. Being the one who answers for it is the hard part.

The agent is already in the safety and quality queue. The dread is what happens when it makes the wrong call: a blown clock with your name on it, an offshored agent you cannot watch, and an inspector who will not take your word for who decided.

A missed clock is a dated, inspectable failure

A 30-day MDR clock starts the instant anyone becomes aware. A serious, unexpected case is due in 15 days. Miss one and it is a dated failure an inspector can point to, and the agent triaging your queue is now exactly where that awareness moment happens. The record has to lock the decision to that timestamp, not reconstruct it after the subpoena.

You answer for work you did not run

PV is heavily offshored. The liability is not. A marketing authorisation holder and its QPPV answer for the safety system no matter who processes the cases. Yet all they get back from a CRO is the CRO promising its agent behaved. We make the agent produce evidence the MAH recomputes itself, so you stop having to take the operator at their word.

When the investigation asks who made the call, your word is weak

The QPPV carries personal accountability for the whole PV system, and the seriousness and reportability calls are medical judgments a qualified person owns. When an investigation asks who, or what, made the call, your own account of it carries little weight. The inspector needs an answer they can recheck on their own.

An LLM you cannot pin down, sitting at the awareness moment

Your Argus or Veeva log already clears inspection. We are not replacing it. The new problem is the agent in front of it. An LLM does not behave the same way twice, and you cannot validate behaviour you cannot reproduce. We give the agent a fixed, version-pinned set of things it is allowed to do, so your team has a stable boundary to validate against and a trail that proves the boundary held on every run.

How it works

We clear the queue. A named person owns the call. The proof writes itself.

Every flow has the same shape. Fast on the safe, reversible work. Stopped in code at the one call a qualified person has to own. And a record your inspector can check for themselves, without leaning on whoever ran the agent.

  1. We build the agent and run it on your stack

    Start from your safety or quality workflow. We build the agent and meet it where it already runs, on LangGraph, CrewAI, the Claude Agent SDK, or your own stack, inside your environment. We fix exactly what it is allowed to do and pin it to one version, so your validation team has a boundary that does not drift. The agent stays fast on the safe, reversible work: intake, coding, drafting, quarantining a temperature-excursion pallet on its own.

  2. The call that matters stays with a named person

    The seriousness call, the reportability decision, batch release: the run stops and waits for a named qualified person. The agent that processed the case cannot be the one to clear it. That is the separation 21 CFR 211.22 has demanded for fifty years, enforced in code instead of promised in an SOP. The person decides, and their reason is recorded word for word.

  3. The proof is something your inspector checks alone

    The record and the action are written together, so an agent that acted but did not log is impossible. Each case exports as one signed file, locked to the timestamp that started the clock. An FDA, EMA, or notified-body inspector rechecks that file themselves, against a published spec, with no access to your systems and none to ours. The record itself is the evidence. Your own word never has to be.

Gate

pv · case P-4003 · 15-day expedited clock

awaiting sign-off
  • Coded the case · narrative drafted with cited evidencesafe direction · agent acted alone

  • Flagged serious + unexpected · held for physician sign-off

One-way door

Set seriousness / expectednessReport to EudraVigilance (E2B)

The agent cannot set this. The safety physician signs, and the identity that processed P-4003 is barred from signing it.

“Serious, unexpected, expedited; causality assessed. Setting seriousness and routing P-4003 to EudraVigilance.”

Signed by Dr. M. Adeyemi, safety physician (human) · 14:08:11
Decision sealed in chainrequester ≠ approver

See it work

Three working scenarios. One command boots them.

Working software your validation team can read and run. Each demo plants the exact cases that force the qualified-person moment.

Demo · PV ICSR processing

Serious and unexpected? Onto the 15-day clock, after a qualified person owns the call.

A case-processor agent intakes ten adverse-event cases, codes them, and proposes seriousness and expectedness, then routes the two serious unexpected ones (acute liver failure; anaphylaxis from a foreign source) to the 15-day expedited track. The seriousness call is held for medical review, and the processor that triaged a case is barred from being its reviewer. Blocked at runtime, not flagged for follow-up, and every step is reproducible for your validation team.

Read the docs →

Demo · MDR reportability triage

Ten complaints in. The reportability determination stays with regulatory affairs.

A complaint-handling agent triages ten complaints and flags two against their statutory clocks: an insulin-pump injury (InsuFlow MX, on the 30-day MDR clock) and a ventilator malfunction (VentAssist 300, recurrence-reportable). The agent never decides reportability; a regulatory-affairs reviewer owns that determination, and only then are the MDR skeletons drafted. A clean fit where the agent runs outside the eQMS your inspector already accepts.

Read the docs →

Demo · cold-chain release / destroy

Release the pallet, or destroy six figures. A named QA person disposes.

A cold-chain agent catches a temperature excursion live, pulls the approved stability limits, and quarantines the affected lots itself. Then it stops. Publishing the flow without the gate is rejected, because a high-risk step forces an approval gate by construction. The release-or-destroy disposition belongs to a named qualified person.

See it block an agent, live →

Evidence for

In your world, this is already the law.

We make no claim about the standing of your system. We say only this: MakerChecker is built against the rules your inspectors already enforce, and it produces the per-case record each one asks for.

The agent cannot make the call that matters. A named person does, and the record proves it. Your inspector rechecks that record on their own, offline, without leaning on the framework vendor or the CRO.

  • 21 CFR 211.22An independent quality unit, fifty-year-old law. The reviewer cannot be the producer. That independence is enforced structurally: the same identity provably cannot triage a case and dispose of it in one run.
  • 21 CFR Part 1111.10(e) audit trails and 11.50 signature meaning, a 1997 rule written for exactly this. The signed export carries the approver, date and time, signature meaning, and the verbatim reason. The hash chain goes beyond what Part 11 requires; we never claim it demands one.
  • Data integrity / ALCOA+Attributable, legible, contemporaneous, original, accurate, and the rest. Every disposition is bound to a named identity and an awareness timestamp in an append-only record, so the audit trail an inspector reads is contemporaneous by construction.
  • QMSRIn force 2 February 2026, QMSR aligns the US device quality system with ISO 13485 and widens the records an inspection can reach. The signed, offline-verifiable evidence pack is the inspection-readiness artifact for that widened surface.
  • Draft EU GMP Annex 22GenAI in critical GMP applications only with a qualified human reviewing the output. AI drafts and a qualified person disposes. That is exactly what the product does.

How the primitives map to Part 11 →

See it for yourself

Start a paid pilot. We build and run the agent on your stack, and hand the inspector a file they recompute themselves.

One command starts the demo: an agent stopped from signing off its own work, and the signed evidence file an inspector can check for themselves.

Designed against the rules your auditors already enforce.