返回技能列表

decommission-validated-system

pjt222
更新于 2 days ago
3 次查看
17
2
17
在 GitHub 上查看
测试worddata

关于

This skill provides a structured process for decommissioning a validated computerized system in a regulated environment. It handles critical compliance tasks like data retention assessment, migration validation, archival, and stakeholder notification. Use it when replacing or retiring a system due to end-of-life, discontinued support, consolidation, or regulatory changes.

快速安装

Claude Code

推荐
主要方式
npx skills add pjt222/agent-almanac -a claude-code
插件命令备选方式
/plugin add https://github.com/pjt222/agent-almanac
Git 克隆备选方式
git clone https://github.com/pjt222/agent-almanac.git ~/.claude/skills/decommission-validated-system

在 Claude Code 中复制并粘贴此命令以安装该技能

技能文档

Decommission Validated System

Plan and execute controlled retirement of validated computerized system. Preserve data integrity and meet regulatory retention requirements.

When Use

  • Validated system being replaced by new system
  • System reaching end-of-life with no replacement (business process eliminated)
  • Vendor discontinues support for validated product
  • Consolidation of many systems into single platform
  • Regulatory or business changes make system obsolete

Inputs

  • Required: System to be decommissioned (name, version, validation status)
  • Required: Data retention requirements by regulation (21 CFR Part 11, GLP, GCP)
  • Required: Replacement system (if applicable) and migration scope
  • Optional: Current validation documentation package
  • Optional: Data volume and format inventory
  • Optional: Business owner and stakeholder list

Steps

Step 1: Assess Data Retention Requirements

Determine how long data must be retained and in what form:

# Data Retention Assessment
## Document ID: DRA-[SYS]-[YYYY]-[NNN]

### Regulatory Retention Requirements
| Regulation | Data Type | Retention Period | Format Requirements |
|-----------|-----------|-----------------|-------------------|
| 21 CFR 211 (GMP) | Batch records, test results | 1 year past product expiry or 3 years after distribution | Readable, retrievable |
| 21 CFR 58 (GLP) | Study data and records | Duration of study + retention agreement | Original or certified copy |
| ICH E6 (GCP) | Clinical trial records | 2 years after last marketing approval or formal discontinuation | Accessible for inspection |
| 21 CFR Part 11 | Electronic records | Per predicate rule | Original format or validated migration |
| EU Annex 11 | Computerized system records | Per applicable GxP | Readable and available |
| Tax/financial | Financial records | 7-10 years (jurisdiction-dependent) | Readable |

### System Data Inventory
| Data Category | Volume | Format | Retention Required Until | Disposition |
|---------------|--------|--------|------------------------|-------------|
| [e.g., Batch records] | [e.g., 50,000 records] | [e.g., Database + PDF reports] | [Date] | Migrate / Archive / Destroy |
| [e.g., Audit trail] | [e.g., 2M entries] | [e.g., Database] | [Same as parent records] | Archive |
| [e.g., User data] | [e.g., 200 profiles] | [e.g., LDAP/Database] | [Employment + 2 years] | Anonymise and archive |

Got: Every data category has defined retention period, format requirement, planned disposition. If fail: Retention requirements unclear? Consult regulatory affairs and legal. Default to longest applicable retention period.

Step 2: Plan Data Migration (If Applicable)

If data migrating to replacement system:

# Data Migration Plan
## Document ID: DMP-[SYS]-[YYYY]-[NNN]

### Migration Scope
| Source | Target | Data Category | Records | Migration Method |
|--------|--------|---------------|---------|-----------------|
| [Old system] | [New system] | [Category] | [Count] | ETL / Manual / API |

### Data Mapping
| Source Field | Source Format | Target Field | Target Format | Transformation |
|-------------|-------------|-------------|---------------|---------------|
| [e.g., test_result] | FLOAT(8,2) | [e.g., result_value] | DECIMAL(10,3) | Precision conversion |
| [e.g., operator_id] | VARCHAR(20) | [e.g., user_id] | UUID | Lookup table mapping |

### Validation Approach
| Check | Method | Acceptance Criteria |
|-------|--------|-------------------|
| Record count reconciliation | Source count vs target count | 100% match |
| Field-level comparison | Sample 5% of records, all fields | 100% match after transformation |
| Checksum verification | Hash source vs target for key fields | Checksums match |
| Business rule validation | Verify key calculations in target | Results match source |
| Audit trail continuity | Verify historical audit trail migrated | All entries present with original timestamps |

Got: Migration plan has mapping, transformation rules, validation checks proving data integrity maintained. If fail: Migration validation fails? Do not proceed to decommission. Fix migration issues and re-validate.

Step 3: Define Archival Strategy

For data that will be archived rather than migrated:

# Archival Strategy

### Archive Format
| Consideration | Decision | Rationale |
|--------------|----------|-----------|
| Format | [PDF/A, CSV, XML, database backup] | [Why this format survives the retention period] |
| Medium | [Network storage, cloud archive, tape, optical] | [Durability and accessibility] |
| Encryption | [Yes/No — method if yes] | [Security vs long-term accessibility trade-off] |
| Integrity verification | [SHA-256 checksums, periodic verification schedule] | [Prove archive is uncorrupted] |

### Archive Verification
- [ ] Archived data is readable without the source system
- [ ] All required data categories are included in the archive
- [ ] Checksums recorded at time of archival
- [ ] Archive can be searched and retrieved within [defined SLA, e.g., 5 business days]
- [ ] Periodic integrity checks scheduled (annually)

### Archive Access
| Role | Access Level | Authorisation |
|------|-------------|--------------|
| QA Director | Read access to all archived data | Standing authorisation |
| Regulatory Affairs | Read access for inspection support | Standing authorisation |
| System Owner (former) | Read access for business queries | Request-based |
| External auditors | Read access, supervised | Per audit plan |

Got: Archived data readable, searchable, verifiable without original system. If fail: Data cannot be read independently of source system? Archive not compliant. Consider exporting to open, standard format (PDF/A, CSV) before decommission.

Step 4: Execute Decommissioning

# Decommission Checklist
## Document ID: DC-[SYS]-[YYYY]-[NNN]

### Pre-Decommission
- [ ] All stakeholders notified of decommission date and data disposition
- [ ] Data migration completed and validated (if applicable)
- [ ] Data archive created and verified (if applicable)
- [ ] Final backup of complete system taken and stored separately
- [ ] All open change requests resolved or transferred
- [ ] All open CAPAs resolved or transferred to successor system
- [ ] All active users informed and redirected to replacement system (if applicable)

### Decommission Execution
- [ ] User access revoked for all accounts
- [ ] System removed from production environment
- [ ] Network connections disconnected
- [ ] Licenses returned or terminated
- [ ] System entry removed from active system inventory
- [ ] System moved to "Decommissioned" status in compliance architecture

### Post-Decommission
- [ ] Validation documentation archived (URS, VP, IQ/OQ/PQ, TM, VSR)
- [ ] SOPs retired or updated to remove references to decommissioned system
- [ ] Training records archived
- [ ] Change control records archived
- [ ] Audit trail archived
- [ ] Decommission report completed and approved

### Decommission Report
| Section | Content |
|---------|---------|
| System description | Name, version, purpose, GxP classification |
| Decommission rationale | Why the system is being retired |
| Data disposition summary | What data went where (migrated, archived, destroyed) |
| Validation evidence | Migration validation results, archive verification |
| Residual risk | Any ongoing data retention obligations |
| Approval | System owner, QA, IT signatures |

Got: Decommissioning controlled, documented, approved — not just "turn it off." If fail: Any checklist item cannot be completed? Document exception and get QA approval before proceeding.

Checks

  • Data retention requirements assessed for all data categories
  • Data migration validated with record counts, sampling, checksums (if applicable)
  • Archive created in format readable without source system
  • Archive integrity verified with checksums
  • All user access revoked
  • Validation documentation archived with defined retention period
  • SOPs updated to remove references to decommissioned system
  • Decommission report approved by system owner, QA, IT

Pitfalls

  • Premature decommission: Turning off system before data migration validated → permanent data loss risk. Complete all validation before pulling plug.
  • Unreadable archives: Storing data in proprietary format needing original system to read defeats purpose of archival. Use open formats.
  • Forgotten audit trails: Archiving data but not audit trail → data provenance cannot be shown. Always archive audit trails with their parent records.
  • Orphaned SOPs: SOPs still referencing decommissioned system confuse users and make compliance gaps. Update or retire all affected SOPs.
  • No periodic archive verification: Archives degrade. Without periodic integrity checks, data loss may go undetected until data is needed for inspection.

See Also

  • design-compliance-architecture — update system inventory and compliance architecture after decommission
  • manage-change-control — decommissioning is major change requiring change control
  • write-validation-documentation — migration validation follows same IQ/OQ methodology
  • write-standard-operating-procedure — retire or update SOPs referencing decommissioned system
  • prepare-inspection-readiness — archived data must stay accessible for regulatory inspections

GitHub 仓库

pjt222/agent-almanac
路径: i18n/caveman/skills/decommission-validated-system
0
agentsagentskillsai-assisted-developmentclaude-codeskillsteams

相关推荐技能

evaluating-llms-harness

测试

该Skill通过60+个学术基准测试(如MMLU、GSM8K等)评估大语言模型质量,适用于模型对比、学术研究及训练进度追踪。它支持HuggingFace、vLLM和API接口,被EleutherAI等行业领先机构广泛采用。开发者可通过简单命令行快速对模型进行多任务批量评估。

查看技能

cloudflare-cron-triggers

测试

这个Claude Skill提供了关于Cloudflare Cron Triggers的完整知识库,用于通过cron表达式定时执行Workers。它支持配置周期性任务、维护作业和自动化工作流,并能处理常见的cron触发错误。开发者可以用它来设置定时任务、测试cron处理器,并集成Workflows和Green Compute功能。

查看技能

webapp-testing

测试

该Skill为开发者提供了基于Playwright的本地Web应用测试工具集,支持自动化测试前端功能、调试UI行为、捕获屏幕截图和查看浏览器日志。它包含管理服务器生命周期的辅助脚本,可直接作为黑盒工具运行而无需阅读源码。适用于需要快速验证本地Web应用界面和交互功能的开发场景。

查看技能

finishing-a-development-branch

测试

这个Skill用于开发分支完成后的集成决策,当代码实现完成且测试通过时,它会引导开发者选择合适的工作流。它首先验证测试状态,然后提供合并、创建PR或清理等结构化选项。核心价值在于确保代码质量的同时,标准化分支收尾流程。

查看技能