Audit Export Package
CGM-v2 · SRS v1.2 · generated 2026-04-12 09:14 UTC
Controlled document · Audit export CGM-v2 · SRS v1.2
Lucora RM · Audit Export Package

Requirements Trace Matrix & Compliance Record

Continuous Glucose Monitor, Generation 2 · Software baseline SRS v1.2
Organization
Acme Biotech, Inc.
Project
CGM-v2
Baseline
SRS v1.2
Baseline approved
2026-03-27 14:02 UTC
Package generated
2026-04-12 09:14 UTC
Generated by
josh@acmebio.com
Tool & version
Lucora RM 0.4.2
Scope
Full trace · items & links
Part 11 Signature Manifest
This package has been cryptographically sealed. Any modification invalidates the hash below.
Sealed
Johanna Vega
Systems Engineering Lead
Authored
2026-03-20 16:41 UTC
re-auth · TOTP · 192.0.2.41
Rahim Chen
Design Assurance
Reviewed
2026-03-24 11:07 UTC
re-auth · TOTP · 192.0.2.58
Dr. Mei Lin
Regulatory Affairs Director
Approved
2026-03-27 14:02 UTC
re-auth · TOTP · 192.0.2.12
Package content hash (SHA-256)
e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 · chained to audit log tail f41a…9c7e
This export is generated from an immutable, append-only audit log. Every item and link in this package carries a chained content hash back to its creation. Signatures are bound to (a) the signer's authenticated identity at time of signing, (b) server-attested UTC timestamp, (c) the content hash of the signed artifact, and (d) a user-asserted meaning of signature. Regeneration of this package for the same baseline will always produce an identical content hash; any divergence indicates tampering or post-baseline change.
End of §1 · continues

§2Baseline Summary

Items in baseline
210
across 8 artifact types
Trace links
5 link types
Approved
Signatories
3
authored · reviewed · approved

Artifact mix

#TypeLabelCount% of totalApprovedIn reviewDraft

Baseline coverage

End of §2

§3Forward Trace Matrix

Forward traceability establishes, for each source artifact, the set of downstream artifacts that realize, test, and verify it. The matrix below is organized into two sub-sections: user needs to system requirements (§3.1), and system requirements to software requirements, design, verification and validation (§3.2).

3.1 User Needs → System Requirements → Validation

# User Need Title Derived System Reqs Validation Status

3.2 System Requirements → Software, Design, Verification

# System Req Title Parent UN Satisfying SS Design (DS) Tests (UT / IT) Verification Status
End of §3

§4Backward Trace Matrix

Backward traceability demonstrates that every test, verification, and validation activity is tied to at least one requirement. Any row lacking an upstream reference is a finding (see §5 Gap Analysis).

4.1 Verifications → System Requirements

# Verification Title Verifies (SR) Status

4.2 Unit & Integration Tests → Software Requirements / Design

# Test Title Tests (SS / DS) Status
End of §4

§5Coverage & Gap Analysis

Requirements with verification
Orphaned items
no links in either direction
Unverified requirements
missing downstream V&V
Conflict findings
explicit conflicts

5.1 Unverified requirements

#IDTitleOwnerStatusFinding

5.2 Orphaned artifacts

#IDTitleTypeFinding
End of §5

§6Per-Item Records

The following are the full controlled records for each item in the baseline: description, rationale, upstream & downstream trace, approval history, and change log. For brevity this mockup shows six representative records; the production export contains all items in the baseline.

End of §6 · per-item records continue for all baseline items

§7Audit Log Excerpt

Append-only audit log, scoped to changes affecting items in this baseline between baseline creation and lock. Each row's hash is chained to the previous; tampering is detectable.

# Timestamp (UTC) Actor Item Action Detail Hash
End of §7 excerpt · full log available on request

§8Approvals & Signatures

Part 11 electronic signatures bound to this baseline. Each signature is captured after successful re-authentication (password + TOTP) and is cryptographically linked to the signed artifact's content hash, the signer's identity, a server-attested timestamp, and a user-asserted meaning of signature.

# Signer Role Meaning Scope Timestamp (UTC) Signed content hash