Compliance & Governance

Governance that lives in the architecture, not a binder.

CMS Industrial is governed by construction: every action is attributable and timestamped, every change captures a reason, and the audit trail is immutable. Your operations and quality teams read the configuration directly — they don't have to trust us.

The difference

Governance by construction vs. by configuration.

Traditional historians and enterprise systems prove compliance by validating a configuration, then re-validating on every change. CMS Industrial builds governance into the node architecture itself, so validation still happens: it's continuous and built in, not a manual re-do.

Governance by configuration

  • Compliance lives in a validated configuration document
  • Someone validates that configuration produces compliance
  • Every change triggers expensive re-validation
  • You hold a vendor license — stop paying, stop running

Governance by construction

  • Compliance lives in the node architecture
  • Your team reads the EaC configuration directly
  • A node change is itself readable and auditable
  • You own portable artifacts your internal team can keep evolving
Governance principles

Every principle, mapped to the architecture.

Each node in a CMS Industrial workspace satisfies at least one governance principle. This is how compliance becomes something you can read, not something you take on faith.

See how this is architected
PrincipleHow CMS Industrial implements it
AttributableEvery action traced to a person or system + timestamp
LegibleReadable, permanent records (non-editable storage)
ContemporaneousRecorded at the moment of action
OriginalFirst-recorded source preserved; copies flagged
AccurateCorrections documented; the original is never deleted
CompleteAll events captured — not just successes
ConsistentLogical chronology via platform time sync
EnduringDurable across the full retention period
AvailableAccessible for audits via surface views + export
Standards

The frameworks your plant already answers to, built in.

ISA-95 operations model

Equipment, material, and personnel models aligned to the ISA-95 hierarchy, with expiry alerts on certifications.

IEC 62443 (ISA-99)

Zone-and-conduit access boundaries with structured reason-for-change captured on every setpoint and recipe mutation.

OSHA

Workplace-safety and lockout/tagout inspection tracking with sign-off gating.

ISO 55000

Asset-management governance aligned to the ISO 55000 framework.

Access control

Feature-locked dashboards, controlled by access rights.

Every screen is gated by access rights, so each role sees exactly the dashboards and actions it's authorized for — completely governed and tested. An OEM doesn't want to see another line's process data, and that's a configuration, not a code branch.

  • assets:view · assets:commission · assets:reconcile
  • network:query · network:manage · devices:onboard · tags:manage
  • compliance:view · compliance:export · review:approve
  • history:approve · admin:access
Role → access rights
Compliance Auditor
audit trail · export
Plant Operations Manager
commission · reconcile
Controls Engineer
network:query
Reliability Engineer
history:approve
Read-only
view
“Start with us. Keep developing with your own team.”

Your workspace configuration, governance mapping, and runbooks are version-controlled, portable, and readable by your operations and quality teams without software expertise. Begin the build with us, then hand it to your internal team to keep evolving — you own the compliance artifacts either way.

Show your auditors compliance they can read.

We'll walk your operations and quality teams through the governance mapping node by node.