veeva-vault-qms

Classifies Veeva Vault QMS operations by read, write, and destructive risk for safe GxP execution.

Updated Aug 17, 2026
One-click install
npx skills add https://github.com/MetaFloor-AI/metafloor-scm-plugin-openai --skill veeva-vault-qms-metafloor-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: veeva-vault-qms
Source: https://github.com/MetaFloor-AI/metafloor-scm-plugin-openai/tree/main/skills/platforms/quality/veeva-vault-qms
Command: npx skills add https://github.com/MetaFloor-AI/metafloor-scm-plugin-openai --skill veeva-vault-qms-metafloor-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? Operating a validated GxP quality system like Veeva Vault QMS is dangerous because nearly every meaningful write is a regulated act with a permanent audit trail: lifecycle state changes fire automation, e-signatures are irrevocable 21 CFR Part 11 acts, and wrong dispositions can miss statutory reporting deadlines. This Skill classifies every Vault QMS action so consequential ones pause for human approval. ## Core Features & Use Cases - Action Classification: Sorts Vault QMS operations into read, reversible write, committing write, and destructive tiers with gating rules for each. - Quality Event Expertise: Covers deviations, CAPAs with effectiveness checks, complaints and reportability, change control, audits, and OOS/OOT investigations across object types and lifecycles. - Recovery Playbooks: Provides correct-forward recovery patterns for premature closures, wrong dispositions, erroneous signatures, and cross-vault pushes. - Use Case: When asked to close a CAPA, the Skill recognizes closure before the effectiveness check as a destructive premature closure and routes it for named human approval instead of executing it. ## Quick Start Ask the agent to classify a deviation as major and advance it to investigation in Veeva Vault QMS, and it will gate the committing state change for approval first.

Frequently Asked Questions about veeva-vault-qms

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I safely advance a deviation lifecycle state in Veeva Vault QMS?

Advancing a lifecycle state is a committing write because entry actions fire automatically, locking fields, creating child records, and starting clocks. Read the object type, current state, open tasks, and roles first, then route the state change through human approval before executing.

What makes an e-signature in Veeva Vault different from a normal approval?

A Vault e-signature is a 21 CFR Part 11 act that permanently captures the signer, signature meaning, and timestamp linked to the record. It cannot be removed or edited, and signing on another user's behalf is a data-integrity violation.

When should I use this Skill instead of SAP QM or LabWare LIMS guidance?

Use it when the connected system is Veeva Vault Quality/QMS handling quality events, CAPAs, complaints, or change control. SAP QM covers inspection lots and usage decisions in ERP, while LabWare covers lab sample login, instrument results, and LIMS OOS workflows.

Why is closing a CAPA before its effectiveness check a problem?

Closing a CAPA before the effectiveness check completes is a premature closure that skips proof the corrective action worked, leaving an audit gap. Reopening is restricted to QA/admin and logged, so the Skill treats closure as destructive requiring named approval.

Can a wrong complaint reportability decision be undone in Vault QMS?

No. A reportability decision can commit or waive a statutory MDR or vigilance deadline that starts at awareness, and a wrong non-reportable call cannot be retracted. The only recovery is a corrective follow-up report filed with the regulator.

Can configuration changes be made directly in a production Vault?

No. Changing lifecycles, workflows, picklists, fields, or security rules in production is a validated computer-system change requiring change control, sandbox testing, and migration via a configuration package. Operators should never perform production config edits.