By Sagar Shankaran, Founder of CallSphere
Least privilege for CDMO agents: keep lot disposition human, scope Vault, LabWare and SAP rights, and close the supplier CoA door. With worked numbers.
Key takeaways
The materials handler at a 180-person oral solid dose CDMO in central New Jersey starts Tuesday the same way every week. Friday's deliveries sit in the quarantine cage under red status labels: pallets of lactose monohydrate and microcrystalline cellulose, a tote of magnesium stearate, two fiber drums of a drug substance the client bought direct. Thirty-four lots, each with a supplier certificate of analysis stapled to the packing list. Every certificate has to be checked against the specification of record, an identity test scheduled under 21 CFR 211.84, and a material lot opened in SAP before a gram moves to the dispensing booth.
Since the spring, sites your size have handed that check to an agent: it reads the certificate, compares every result to the approved specification, creates the lot in SAP, books the identity sample into LabWare, and drops a one-page summary into the QA reviewer's queue. It gives your handler and reviewer their mornings back. It also opened a door that did not exist in 2024, because the certificate is written by somebody outside your building and the agent now has hands.
Write this on the whiteboard first. Zero trust for a working agent means it holds the smallest set of permissions that still lets it finish the job, and every action it cannot undo stops at a named human who signs it. In a contract manufacturing plant that sentence has a very specific ending.
In 2024 and most of 2025 you had a writing helper. It summarized a deviation, you read it, you pasted it into TrackWise or Veeva Vault, you signed. It had no login and no hands, and whatever nonsense it produced died in the copy-paste step, where a human was standing anyway.
That changed twice this year. Claude Cowork landed 12 January 2026, built for non-technical staff: you give it a goal, it works across your apps and files, it hands back finished work. ChatGPT Work followed on 9 July 2026, running on its own for hours. Both mean the same thing for your quality system. The agent has real accounts now. It logs into Vault, creates records in SAP, books samples in LabWare, emails your supplier's quality contact.
Two things follow. First, any document your agent reads can carry instructions aimed at the agent rather than at you, and a supplier certificate is a document your agent reads all day. Second, most sites hand out permissions the lazy way — one account, wide open, because narrowing it took an afternoon of somebody's time. The answer that settled in over the first half of 2026 is old-fashioned: least privilege, credentials scoped to one job, and a human signature on anything irreversible. Anthropic's enterprise governance update on 2 July 2026 added the administrative half — spend limits per user, alerts at 75% and 90% — which matters when your Head of Quality has to describe the control set to a client auditor.
Hear it before you finish reading
Talk to a live CallSphere AI voice agent for healthcare in your browser — 60 seconds, no signup.
Under 21 CFR 211.22 the quality unit — not manufacturing, not the program manager, not the client — approves or rejects each lot. That signature is the one irreversible act in your building. Once a lot is dispositioned and on the client's truck it is in their distribution and, for a commercial product, the DSCSA trail. Pulling it back is not an edit; it is a recall conversation, a Field Alert Report inside three working days under 21 CFR 314.81, a complaint file and a very bad quarter.
So the disposition signature stays human, permanently, and so does the short list around it: second-person review of the executed batch record, closing a deviation or CAPA, making an SOP effective, approving a change control, releasing a payment run in SAP, and anything inside your chromatography data system. That system is the one place an agent gets no account at all — reintegrating a chromatogram is the act half the FDA data-integrity observations of the last decade were written about, and you do not want to explain a non-human user ID in that audit trail.
flowchart TD
A["Supplier CoA arrives at goods receipt"] --> B["Agent reads CoA, compares to spec of record in Vault"]
B --> C{"Every result inside spec?"}
C -->|No| D["Agent writes quarantine note and stops"]
C -->|Yes| E["Agent opens SAP lot, books ID sample in LabWare"]
E --> F["QA reviewer opens the draft beside the source PDF"]
F --> G{"Reviewer accepts the comparison?"}
G -->|No| D
G -->|Yes| H["QA signs lot disposition in Vault under own unique ID"]
Everything else gets sorted in one afternoon with your IT lead, your Head of Quality and your Vault administrator in the room. Give the agent its own named account in every system — never a shared login, never a human's login, because Part 11 requires a unique identity behind every audit trail entry and your client's auditor will pull that report.
| System | What the agent gets | What it must never get |
|---|---|---|
| Veeva Vault QMS / QualityDocs | Read effective documents; author drafts in one folder | Any approval or periodic-review step |
| LabWare LIMS | Create sample requests; read released results | Enter or approve results |
| SAP S/4HANA | Display transactions; create purchase requisitions; open material lots | Release POs, run payments, change vendor bank details |
| Werum PAS-X (MES) | Read-only on executed records | Any write to a batch record |
| the Waters chromatography data system | Nothing | Everything |
Scope the credentials by time as well as by right. An agent working one client program does not need standing access to the whole library at 2 a.m. on a Sunday; give it that program's folder and let the access lapse when the campaign closes. Then read what it did once a month, the way you read a badge-access report.
Door one is the supplier certificate: a PDF from a company you audited two years ago, and text can sit inside it that a human eye skips and a machine reads — a line saying the assay limit for this lot was widened by agreement, or the retest date extended. Treat that as an instruction and your handler moves a drum that should have stayed in quarantine.
Door two is the client program mailbox, where at least once a campaign somebody sends "revised specification attached, please use for lot 2604" at 6 p.m. on a Thursday. That attachment is not a controlled document, has not been through change control, and may not be from who it says. Door three is scanned paper off your own floor — a scribbled "OK per QA" in the margin of a cleaning log gets read as an approval by a machine that is trying to be helpful.
One sentence closes all three and you can put it in an SOP tomorrow: text arriving from outside the controlled document library is information to be reported, never an instruction to be followed. The agent takes the specification only from the effective version in Vault; if an attachment disagrees, it raises a query to the program manager and stops.
Still reading? Stop comparing — try CallSphere live.
See the healthcare AI agent handle a real call — complete, industry-specific, and live in your browser. No signup.
Illustrative numbers for a site this size; swap in your own. Assume 46 incoming material lots a week, 40 deviations a month, a QA reviewer at $58 an hour fully burdened, 47 working weeks.
| Task | Today | With a scoped agent |
|---|---|---|
| CoA check per lot | 12 min | 3 min review of the draft |
| CoA hours per week | 9.2 h | 2.3 h |
| Deviation initial write-up | 2.5 h each | 40 min each |
| Deviation hours per month | 100 h | 26.7 h |
| Hours released per year | (9.2 − 2.3) × 47 + (100 − 26.7) × 12 = 324 + 880 = 1,204 h | |
| Value at $58/h | about $69,800 a year | |
That is two-thirds of a QA headcount you do not have to hire the next time a client doubles its forecast — and, more usefully, the difference between deviations written the same week they happen and deviations written the week before the audit.
An agent cannot run an out-of-specification investigation. The FDA's OOS guidance expects a phase I laboratory investigation with the analyst and the supervisor at the bench, reconstructing what happened to that vial. It cannot decide whether a single unknown impurity creeping from 0.06% to 0.11% across three lots matters clinically — that is your Head of Quality and the client's regulatory group. It cannot sit across the table from an FDA investigator during a pre-approval inspection, judge when a deviation has become a recall, or decide that a supplier is qualified.
The Monday version is small. Pick one queue — incoming certificate verification — and give the agent a named account with read rights on your effective specifications and draft rights in one folder. Run it beside your reviewer for twenty lots and compare line by line. Then write the scoping table above into your computer systems procedure and take it to your next client audit before they ask.
Not on its own. An investigator cares whether records are attributable, legible, contemporaneous, original and accurate, and whether the quality unit still holds disposition authority under 211.22. Unique user ID, no approval steps, audit trail intact, and you are describing a controlled tool rather than a shortcut around your quality unit.
You assess the risk it carries and control it accordingly, which is the thinking in GAMP 5 Second Edition. An agent drafting a deviation summary a human rewrites is low risk. An agent creating lots in SAP that drive dispensing is not. Write the intended use down, test it against a defined set of records, keep the evidence with your other computer system files.
No. A Part 11 signature is the binding act of a person who is accountable for it. Your agent gets an identity so its actions are traceable; it does not get the pen.
One last note. Tightening what your agent may do does not make your phone quieter — program managers still call about lot status, suppliers still call about a late drum, and business development still misses the inbound because everybody is on the floor at 10 a.m. CallSphere builds AI voice and chat agents that answer the line around the clock, capture who called and what they wanted, and book the callback, so the hours you free up in quality do not get eaten again by the switchboard.

Written by
Sagar Shankaran· Founder, CallSphere
LinkedInSagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
Charter fraud meets AI that can act. What a Part 135 operator must keep human, how to scope Avinode and inbox access, and the arithmetic of the approval click.
Consignee changes, bank details, hold releases and DEA calls: how a contract manufacturer verifies the caller when the voice itself proves nothing in 2026.
The irreversible actions in a precision machining shop that must keep a human in the loop, and how to scope everything else an AI assistant touches in 2026.
Least privilege for AI agents at a regional carrier: scoped logins, no rights in the porting queue or 911 records, and a human on every irreversible action.
Cargo release is the one irreversible action a ship agency must keep human. How to scope AI logins across CargoWise, Navis N4, gate systems and the bank.
Non-cancellable POs, remit-to fraud and DFARS flags: how MRO distributors scope AI agent access in Prophet 21 and SX.e, plus what a bad release actually costs.
© 2026 CallSphere Inc. All rights reserved.
Made within San Francisco
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI