Skip to main content

SQF Edition 10 audits start January 2027. Is your program ready? Learn more →

Back to Insights

Guides · Sep 29, 2026 · 10 min read

Someone Signed That the Drains Were Cleaned. Nobody Could Say Who.

A shared tablet login proves the work happened. It doesn't prove who did it. FDA's preventive controls rule requires the signature or initials of the person performing the activity, and SQF requires records confirmed by the people doing the monitoring. How shared logins happen on a floor, what an auditor does with a signature nobody can place, why paper initials fail the same way after turnover, and the identity pattern that holds up on a wet floor.

SM
Steven Moussawer Founder

A shared tablet login records that the work happened. It doesn't record who did it. FDA's preventive controls rule wants the signature or initials of the person performing the activity. SQF wants records confirmed by the people doing the monitoring. An entry made by an account instead of a person may satisfy neither, and it leaves an auditor no way to tell who did the work.

The rule names a person, not an account

The FDA rule requires the signature or initials of the person performing the activity. SQF requires records to be confirmed by those undertaking monitoring activities.

21 CFR 117.305(f) lists what a record has to include: enough information to identify the plant, the date and when appropriate the time, "the signature or initials of the person performing the activity," and where appropriate the product identity and lot code. Paragraph (d) of the same section says records are created concurrently with the activity they document. Together those provisions require the record to be created concurrently and tied to the person who performed the activity.

SQF gets at it from a different angle. Element 2.2.3.2 requires that all records "shall be legible and confirmed by those undertaking monitoring activities that demonstrate inspections, analyses, and other essential activities that have been completed." The confirmation belongs to the person doing the monitoring, and an entry made under a shared account may not demonstrate it. Edition 9 is still the audited edition for audits before January 2, 2027. Edition 10 audits begin as early as that date, subject to SQFI's transition guidance and its surveillance-audit exception.

One scope note on which sanitation records this reaches. Sanitation under the CGMP subpart doesn't carry a records requirement on its own. Sanitation controls you've identified as preventive controls do: the monitoring, corrective action, and verification records required by 117.190 are subject to every part of subpart F, including 117.305(f). Pre-op verification and sanitation monitoring records are in scope. A daily housekeeping walk is in scope too when your food safety plan treats it as monitoring, corrective action, or verification.

An unattributable signature can't show who did the work

The record needs to connect a qualified person to the task and the time. Strip the person out and you're left with a task and a time.

21 CFR Part 11 is worth reading here even though it doesn't bind you. Electronic records kept to satisfy Part 117 are exempt from Part 11 unless they're also required under some other statute or regulation. It's still a useful reference point for electronic signature controls.

Section 11.50 says a signed electronic record carries the printed name of the signer, the date and time the signature was executed, and the meaning of the signature. Section 11.100(a) says each electronic signature "shall be unique to one individual and shall not be reused by, or reassigned to, anyone else." If a shared shift login is doing the work of an electronic signature, it meets neither half of that sentence. The exemption doesn't change what the record has to show.

How one tablet ends up carrying a whole crew

Shared logins are what's left after four practical problems land on the same device. The details below are a composite, not any real site.

Gloves. Wet nitrile on a capacitive screen is unreliable, and an operator who has to strip a glove to log in will do it twice before deciding somebody else can enter it.

One device per line. If the tablet is mounted at the packaging end and six people work the line, the login belongs to whoever mounted it, usually the lead.

Password fatigue. A twelve-character password with a symbol, typed on a screen keyboard, dozens of times a shift, is an unworkable design. Crews solve it by typing it once at start of shift and leaving the session open.

The QA tech signing for the crew. This one looks like diligence. The tech walks the line, sees the work is done, and enters it because she's the one with the account and the training on the form. Her name goes on all of it.

Put those together and you get the failure. A sanitation crew cleans the floor drains overnight. The work is recorded against the supervisor's account, because his is the login open on the mounted tablet. Weeks later an FDA investigator pulls the drain cleaning records during an environmental swabbing follow-up, points at three nights, and asks who performed them. The supervisor's name is on all three. He worked one of them.

What an auditor does with a signature nobody can place

An auditor may treat the task as unverified and may go on to review related records. The code sets the confirmation and qualification requirements, not the sampling response.

The reason is a requirement most people read past. SQF element 11.2.5.7 says pre-operational inspections "shall be conducted by qualified personnel." Qualified is a claim you back with a training record. The signature on the inspection is the only thing connecting that task to that training file. Cut the link and it gets much harder to demonstrate that a qualified person completed the inspection for that date.

That's a harder problem than a dirty drain. A dirty drain is one corrective action. A records practice that can't attribute entries puts every record it touched in question, and moves the conversation from your sanitation to your record system.

It costs you the investigation too. A pathogen hit on a drain swab starts with what happened on that drain and who was standing there. If the answer is "the supervisor account," the investigation has nowhere to go, and neither does retraining.

Paper has the same hole. Turnover is what opens it.

21 CFR 117.305(f)(3) permits a signature or initials from the person performing the activity, which is why sanitation logs use a small initials box.

Initials only work if something maps them to a person. Plants that do this well keep a signature and initials register: printed name, initials, the specimen signature, employment dates, and the tasks that person is qualified for. Plants that don't end up with "JM" on a stack of logs and a QA manager who left in March, the only one who knew there were two JMs on second shift.

The clock runs longer than people expect. 117.315(a)(1) requires records be retained at the plant for at least two years after they were prepared, and SQF ties retention to customer, legal, and regulatory requirements, at minimum the product shelf life. For a shelf-stable product that can run well past two years. Two years is long enough that "we'll just ask him" stops being a plan.

Digital systems inherit the same obligation. A deactivated user still has to resolve to the person behind the signature or initials on every record they ever signed. Where Part 11 applies, 11.50 also wants the printed name, the execution date and time, and the meaning of the signature. Reassigning a departed employee's PIN or badge number to a new hire rewrites history with no trace of the swap. If that PIN is an electronic signature component, the reuse also runs into 11.100(a).

The fix that works on a wet floor

A defensible shared-device workflow needs three properties, and any one of them on its own leaves the hole open.

Per-person identity at the point of entry, in seconds. A four-digit PIN on a numeric keypad, or a badge tap, rather than a password typed on a screen keyboard. If identifying yourself costs more than a few seconds, the crew will route around it, and the record you get back is a lie told for convenience.

A session that expires on its own. The device stays signed in for the shift. The person doesn't. If an operator walks away and the next one picks up the tablet, the system should already have forgotten who the last one was. Part 11 describes this arrangement at 11.200(a)(1)(i): the full credential opens a single continuous period of controlled system access, and every signing inside that window still takes a component only that individual can use.

The record carries the operator, not the device owner. That's the genuinely architectural part. Most software has one concept of "the logged in user" and writes that name onto everything. A shared floor device needs two: the account the device is signed in under, and the person standing in front of it right now. The second one is what the signature has to say.

Part 11 comes at the same idea from the other direction at 11.200(a)(3): attempted use of someone else's electronic signature requires collaboration of two or more individuals. When a QA tech can sign for the whole crew with one tap, nothing in the design creates that friction.

Beacon's floor workspace separates the signed-in device from the active operator: the operator identifies with a PIN, the session expires fifteen minutes after their last activity, and the record carries the operator rather than the device account.

Run this on last week's sanitation records

Start with two checks: identify the signer, then verify the training record.

Pull last week's sanitation and pre-op verification records. Pick ten signatures or sets of initials at random. Write down the ten names.

If you can name all ten, do the second half, the one that matters on audit day. For each of those ten people, find the training record that qualifies them for the task they signed. Not a general orientation record. The one for that procedure.

If three of your ten come back as "that's the shift lead's account" or "that's whoever was on the tablet," you have your gap, and it's a records gap, not a sanitation gap. Fix the identity at the point of entry, then check that person's training record against the procedure. Identity doesn't prove qualification. It's what makes the training record findable.

This is a different failure from the one where your contracted sanitation crew hands you a service log instead of verification evidence, and different again from the Edition 10 records you can't backfill because they need elapsed time. Those are about what the record contains and how long it's been accumulating. This one is about whose name is on it. A record can have perfect content, perfect timing, and a year of history behind it and still be unusable because nobody can say who made the entry.

It's also the one of the three you can start fixing immediately, because it doesn't need elapsed time. If you're already working through a move off paper, sequence it by name: start with sanitation, pre-op, and CCP monitoring, where the daily execution records carry a person rather than a number.

Book a call to see how per-operator identity works on a shared device without slowing a crew down.

Run a food safety program? See how Beacon keeps it audit-ready.

See Beacon in 20 minutes