# QMS Studio Public Demo Intended-Use Statement

> **SUPPLIER-AUTHORED DEMONSTRATION BOUNDARY / NOT HUMAN-APPROVED / NOT PRODUCTION VALIDATION EVIDENCE**

- Document ID: `QMS-PD-IUS-001`
- Revision: `2026-08-11.4`
- Product state: Public synthetic-data demonstration
- Baseline state: Final app source commit `02d2f87ecccfd7c7b0770b0b95df5ff69377242b`, expanded 68-file scoped SHA-256 `4d8ca26c48468c689edf3c225a48085e275a6905af5ecc55ba73361e1278a24d`, deployed as Sites version 21; not approved for regulated production use
- Approval state: No supplier, quality, regulatory, legal, security, privacy, accessibility, or customer approval recorded

## Intended use

QMS Studio's public demo is intended only to let prospective users, product teams, and qualified quality professionals:

- explore illustrative user-interface patterns for medical-device and IVD quality-system work;
- discuss candidate human-review, traceability, audit, evidence, change, training, complaint, CAPA, regulatory-change, and electronic-signature controls;
- exercise synthetic, browser-session interactions for evaluation and usability feedback; and
- download starter structures for planning a future, customer-specific software assurance and validation record.

The demo may be used for evaluation, training discussion, design review, and requirements discovery with synthetic, public, non-confidential data. Its outputs are illustrative and must not be relied upon for an operational or regulated decision.

## Included demonstration surfaces

The limited verification described in `public-demo-assurance-protocol-summary.md` covers:

- the `/validation` route, its scope language, customer-approval boundary, package anchor, and downloadable static artifacts;
- the `/demo` home, complaint register, complaint detail, CAPA, regulatory readiness, document change, training, approval, audit, and evidence-pack views;
- in-memory navigation, complaint search/filter behavior, and the simulated signature guard and reset behavior; and
- the source, build, lint, development-server render, and package-integrity checks listed in `validation-status.json`.

The bounded current-release evidence includes a 30/30 live HTTP/content check on the custom Sites-v21 domain and limited desktop 1280 x 720 / mobile 390 x 844 px browser checks. The browser check observed Inter and Source Serif loading, no horizontal overflow, a 56 x 56 px mobile launcher, and the mobile header parent cue hidden. These checks establish only the recorded synthetic informational demo behavior and targeted typography presentation, not production qualification, accessibility conformance, or customer validation.

## Explicit exclusions

The following are outside this intended use and outside the limited demo-verification conclusion:

- creation, approval, signature, retention, migration, export, submission, or management of real regulated records;
- production use, production deployment, installation or infrastructure qualification, tenant configuration qualification, or customer user-acceptance testing;
- authentication, identity proofing, role enforcement, segregation of duties, multi-tenant isolation, electronic-signature legal reliance, immutable audit trails, trusted time, accurate copies, retention, backup, restore, disaster recovery, monitoring, incident response, or change control;
- regulatory, legal, clinical, reportability, classification, release, CAPA, root-cause, or compliance determinations;
- accuracy, completeness, currency, or legal applicability of regulatory content for a particular product, market, organization, or date;
- accessibility conformance, cross-browser compatibility, mobile compatibility, performance, penetration testing, vulnerability testing, privacy assessment, or security certification;
- the globally mounted Bio-Consultant AI assistant, its external chat service, contact/lead submission, browser-storage behavior, model behavior, or third-party processing; and
- external links, external services, production APIs, database behavior, integrations, notifications, or customer environments.

## Data and privacy boundary

Use only synthetic, public, non-confidential data. Do not enter personal information, patient or health information, customer quality records, complaints, device identifiers, investigation material, credentials, trade secrets, or other protected information.

The simulated QMS workflow state is held in the browser session and resets. Separately, the Bio-Consultant assistant uses browser session/local storage and can call external chat and lead endpoints. That assistant is not part of the synthetic QMS workflow assurance scope and must not be used to enter regulated or confidential information.

## Meaning of simulated controls

Labels such as "approved," "signed," "committed," "verified," "audit trail," "SHA-256 verified," and "evidence pack" describe illustrative UI state. They do not establish that a server transaction occurred, an identity was authenticated, a record was retained, a hash was independently reconciled, an audit event is immutable, or a legally effective electronic signature was created.

The simulated signature check verifies only that the visible demo button remains disabled until the displayed name and intent control are supplied, changes to a committed demo state, and resets after reload. It is not evidence of compliant electronic records or signatures.

## Prohibited reliance

Do not use the public demo to:

- operate a quality system or production process;
- satisfy a regulatory, contractual, certification, inspection, audit, or submission obligation;
- approve, release, close, sign, classify, report, or disposition a real item;
- replace qualified human review or approved procedures; or
- claim that QMS Studio, a future release, a customer deployment, or a customer process is validated, compliant, certified, secure, accessible, or production-ready.

## Relationship to the engineering PRD

The Engineering Product Requirements Document is a future product baseline with more than one thousand individually testable requirements. This intended-use statement and the accompanying limited checks cover only the public synthetic demo surfaces identified above. They do not demonstrate implementation or verification of the full PRD, any jurisdiction pack, or any production requirement.

## Approvals and remaining decisions

Before this statement can become a controlled supplier intended-use baseline, designated product and quality owners must review and approve it and reconcile it with product claims, privacy notices, AI disclosures, security boundaries, accessibility evidence, and release documentation.

Before regulated customer use, the customer must define and approve its own intended use, applicable obligations, processes, records, roles, configuration, environment, integrations, procedures, risks, acceptance criteria, assurance activities, deviations, residual risks, training, release decision, and change-control plan.

## Change triggers

Reassess this boundary after any material change to claims, routes, workflow behavior, data handling, storage, APIs, AI providers/models/prompts, regulatory content, authentication, signatures, audit behavior, exports, deployment architecture, dependencies, or the downloadable package.
