GxP requires controlled documentation with audit trails, version history, and approval workflows. Your glossary defines the terms those documents use. If the glossary isn’t governed, the documents aren’t fully compliant.
GxP (Good x Practice) is the umbrella term for quality regulations in life sciences — GMP, GLP, GCP, GDP, and GVP. Every GxP framework demands controlled documentation: versioned, audit-trailed, approved, and trained on. Confluence gives you the document platform and page-level history; it does not give you a controlled vocabulary with per-term approval, mandatory change reasons, or four-eyes enforcement. Compliance Glossary adds that governance layer on top of Confluence, mapping each term's lifecycle to ALCOA+ expectations and 21 CFR Part 11 audit-trail integrity — without moving data off Atlassian Forge infrastructure.
GxP (“Good x Practice”) is a collection of quality guidelines and regulations that govern the life sciences industry. The “x” represents the specific area of practice:
Governs the manufacture of drugs, medical devices, food, and cosmetics. Enforced by the FDA under 21 CFR Part 210, Part 211, and Part 820, and by the EMA (EudraLex Volume 4). Requires documented procedures, controlled processes, and full traceability.
Governs non-clinical laboratory studies. Enforced by the FDA under 21 CFR Part 58 and by the OECD GLP Principles. Ensures the quality and integrity of safety data submitted for regulatory approval.
Governs the conduct of clinical trials. Defined by ICH E6(R3) (Step 4 reached 6 January 2025; previously E6(R2)). Protects patient rights and ensures clinical data integrity. Requires documented SOPs and terminology consistency across study sites.
Governs the distribution of pharmaceutical products. Ensures drugs remain safe and effective from manufacturer to patient. EU Guidelines 2013/C 343/01.
Governs the monitoring and reporting of drug safety. EMA GVP modules require standardized terminology for adverse event classification and reporting (MedDRA coding).
Every GxP framework shares common documentation requirements that apply to terminology management:
| Requirement | GxP Standard | How It Applies to Terminology |
|---|---|---|
| Document control | ISO 9001 §7.5, 21 CFR 211.100 | Glossary terms must be controlled documents with defined review/approval cycles |
| Version history | 21 CFR Part 11, ALCOA+ (Enduring) | Every change to a definition must be tracked with who, when, what, and why |
| Audit trail | 21 CFR 11.10(e), ALCOA+ (Attributable) | Append-only history that cannot be modified after the fact |
| Approval workflows | 21 CFR 211.100(a), ICH Q10 | Terms must be reviewed and approved before use in controlled documents |
| Change justification | 21 CFR 211.100(b), SOC 2 CC8 | Best practice under ICH Q10 change management; required for 21 CFR Part 11 audit-trail integrity. |
| Periodic review | ISO 9001 §7.5.3, ISO 13485 §4.2.4 | Approved terms must be reviewed for continued accuracy |
| Training records | 21 CFR 211.25, ICH E6 | Staff must be trained on controlled terminology before using it |
For a deeper dive into each of these controls, see our compliance guide with auditor-facing evidence for each requirement.
Many pharma and medtech teams already use Confluence for SOPs, protocols, and quality documentation. Atlassian provides a GxP trust page covering their security and compliance posture.
What Confluence provides natively:
What Confluence lacks for GxP terminology management:
This is exactly the gap that Compliance Glossary fills. It adds ALCOA+-compliant terminology governance on top of Confluence’s existing platform capabilities.
Terminology inconsistency in GxP environments creates real regulatory risk:
21 CFR Part 11 distinguishes between closed systems (access controlled by the entity responsible for the records) and open systems (access controlled by parties outside that entity). The distinction matters because the evidentiary bar differs:
For GxP terminology specifically, the Part 11 expectations are concrete: every term creation, modification, approval, and retirement must be attributable to an identified user, captured with a trustworthy timestamp, protected from deletion, and exportable for inspection. Compliance Glossary stores all term events on Forge, inherits the Confluence identity layer, and exposes an append-only history plus a CSV export that lines up with the records you would hand to an inspector.
ALCOA+ is the data-integrity framework the FDA, MHRA, and EMA reference when judging GxP records. Each principle has a direct expression in how terminology is managed:
| ALCOA+ Principle | What it means for a glossary term |
|---|---|
| Attributable | Every create/edit/approve action is tied to a named Confluence user; no shared accounts. |
| Legible | Definitions are plain text, readable without proprietary viewers, exportable to CSV (PDF on the 2026 roadmap). |
| Contemporaneous | Timestamps are captured at save time by the Forge runtime, not entered by the user. |
| Original | Terms live on Forge storage inside the customer's Atlassian tenancy; no external copy. |
| Accurate | Four-eyes approval prevents a single author from self-approving a definition change. |
| Complete | All versions are retained; superseded definitions are not deleted, only marked retired. |
| Consistent | Enforced workflow states (draft → review → approved → retired) prevent ad-hoc changes. |
| Enduring | Forge storage persists for the life of the installation and is included in Atlassian backups. |
| Available | Inspectors and QA get read-only access; CSV export runs in seconds, not days. |
A glossary fails the moment no one owns it. GxP organisations typically split ownership by functional area, with a single governance forum reviewing cross-cutting terms:
For pharma and life sciences teams using Confluence:
Start with regulation-specific term sets, ready to import:
| Template | Terms | Covers |
|---|---|---|
| FDA 21 CFR Part 11 | 43 | Safety reporting, quality system, risk management, regulatory, Part 11 |
| SOC 2 | 40 | Trust Services Criteria, controls, risk governance, security operations |
| EU AI Act | 68 | Article 3 verbatim definitions: AI system, GPAI, deployer, conformity assessment |
| ISO 13485 | 35 | Medical device QMS, design controls, production, monitoring |
GxP (“Good x Practice”) is a family of quality guidelines and regulations governing the life sciences industry, where the “x” is the specific area of practice — GMP (Manufacturing), GLP (Laboratory), GCP (Clinical), GDP (Distribution), and GVP (Pharmacovigilance). Every GxP framework requires controlled documentation, version history, audit trails, approval workflows, and training records.
Confluence Cloud provides the platform-level controls — access control, page version history, author attribution, and SOC 2 Type II / ISO 27001 certifications — that can support a 21 CFR Part 11 closed-system deployment. Part 11 compliance is a system-level responsibility: the customer must validate the system for intended use, configure electronic signatures, enforce change justification, and maintain independent audit trails. Confluence alone does not provide per-term audit trails or mandatory change reasons — those gaps are addressed by governance apps like Compliance Glossary.
Confluence’s native page history is per-page, not per-term. GxP expects a controlled vocabulary with its own lifecycle — draft, review, approved, retired — with four-eyes approval and mandatory change reasons. A dedicated glossary layer on top of Confluence gives each term its own approval chain, version history, and audit export, which page history cannot.
Each term change is Attributable (signed-in user), Legible (plain-text definition), Contemporaneous (timestamped at save), Original (stored on Atlassian Forge infrastructure, no external copy), and Accurate (enforced by four-eyes approval). The ALCOA+ additions — Complete, Consistent, Enduring, Available — are covered by append-only history, enforced workflow states, Forge-native storage, and one-click CSV export for audits.
Add controlled vocabulary governance to your existing Confluence documentation. Built on Forge — all data stays on Atlassian infrastructure.
Evaluate in Confluence Read DocumentationCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
ALCOA+ Documentation Principles — the data integrity framework behind GxP audit requirements
Four-Eyes Principle — why second-person verification matters for GxP documentation
FDA Terminology Management — 43 terms for pharma & medtech, 21 CFR Part 11 aligned
ISO 13485 Terminology — medical device quality management terms
EU GMP Annex 11 Terminology — computerised systems terminology for EU pharma
FDA Form 483 CFO Readiness — financial exposure from documentation findings
Security Whitepaper — Forge architecture, data residency, SOC 2 alignment
Compliance Guide — what auditors check and how we help