Security at Obsidian Metra

Trust the record.
Trace the reason.

Calibration evidence deserves more than a final value. Obsidian Metra uses explicit access boundaries, controlled record lifecycles and connected provenance to keep the history behind each result intact.

Three operating principles

Security that can be explained

  1. 01

    Make boundaries explicit

    People work within a selected organisation, and access is limited by their active membership and assigned permissions.

  2. 02

    Preserve the evidence

    Approved work follows controlled voiding, revision and supersession paths so a correction does not silently replace the record it corrects.

  3. 03

    Keep claims testable

    We describe controls that exist in the product today and distinguish them from certifications, guarantees and future security work.

Organisation isolation

Your organisation. Explicit boundaries.

Organisation information is kept within the selected organisation and made available only to people with active membership and the appropriate permissions. Users who work with more than one organisation enter each in its own context.

A role belongs to a membership, not globally to a user. The same person can therefore have different permissions in different organisations.
  1. Identity

    A person signs in with their own account so activity can be associated with the individual responsible.

  2. Membership

    Access is available only where that person has an active membership in the selected organisation.

  3. Role

    The membership role determines which responsibilities and records are available to that person.

  4. Permitted action

    Viewing, changing, approving and exporting information remain within the organisation and the person's granted permissions.

Electronic record integrity

History is part of the evidence

A trustworthy record shows what changed, who acted and what came before. The platform separates draft editing from controlled outcomes and preserves correction paths after submission and approval.

CONTROL / 01

Retained history

Significant activity retains the organisation, responsible person, action and time so the history behind a record can be reviewed.

CONTROL / 02

Reviewable decisions

Controlled procedures preserve relevant decisions and reasons, helping reviewers understand how an operational outcome was reached.

CONTROL / 03

Controlled corrections

Completed calibration work can be voided or superseded through explicit workflows that retain links to the original record.

CONTROL / 04

Accountable activity

Actions are attributed to individual users and their organisation context, supporting accountability during routine review and audit.

Precise by design: completed and approved work follows controlled correction, revision or supersession procedures. Original evidence remains part of the reviewable history rather than being silently replaced.

Roles and permissions

The right access for the work at hand

Access follows a person\'s responsibilities within each organisation. Roles and permissions help separate everyday work from sensitive actions such as managing members, approving exceptions or exporting audit evidence.

  • Membership roles apply within a specific organisation, not across every organisation a person may use.
  • Sensitive activities are limited to people whose role includes the relevant permission.
  • Controlled procedures can distinguish recording work from reviewing or approving it.
  • User attribution helps organisations review who performed significant actions.

Certificates and files

The file and its provenance stay connected

Certificates remain connected to the equipment and calibration work they support. Access follows organisation membership and permissions, while source, upload and replacement context helps users assess where evidence came from and which version is current.

Certificate chain of custody
Evidence
Connected calibration certificate
Context
Equipment and completed work
Provenance
Source, uploader and time
History
Revision and supersession trail

Controlled procedures

Important decisions stay reviewable

Operational workflows help organisations control who can record work, review outcomes, approve exceptions and close investigations. Where a correction is needed, revision and supersession preserve the relationship to the earlier record.

The platform supports these controls, while each customer remains responsible for defining procedures, assigning appropriate roles and confirming that approvals meet its quality requirements.

AI usage

Import assistance, with human review

Obsidian Metra uses OpenAI to help interpret import files and propose mappings or accreditation setup. The information sent depends on the import operation.

Register mapping suggestions

Header analysis sends candidate column headings, region names and masked structural samples to OpenAI. Sample values are replaced with value types; complete register rows are not sent for this analysis. Headings and region names may still contain information from your file.

UKAS schedule interpretation

AI interpretation sends the complete schedule PDF to OpenAI, including any laboratory and contact details it contains. You must explicitly consent and choose to read the schedule with AI. Uploading a PDF alone does not authorise this transfer.

Review remains your responsibility

AI can misread or omit information. Check suggestions against the source before confirming an import. A UKAS import creates a draft and cannot approve or activate accreditation. Organisation permissions continue to apply, and the original source and AI model provenance remain connected to the import for review.

Provider data handling

OpenAI API data is not used to train models by default. Provider retention and account settings still apply; this is not a promise of zero retention. See OpenAI's API data policies.

For the consent and review steps, read Import a UKAS calibration schedule.

Shared responsibility

Good controls need good operation

Obsidian Metra provides safeguards for controlled system use. Customers remain responsible for how access, procedures and evidence are governed in their own quality environment.

Obsidian Metra

Platform responsibilities

  • Keep each organisation's access separate and apply the permissions assigned to its members
  • Keep calibration records, certificates, revisions and relevant activity history connected
  • Limit evidence access to authorised users and retain its operational provenance
  • Describe the current security posture honestly as safeguards continue to evolve

Your organisation

Customer responsibilities

  • Review membership regularly and grant only the access each person needs for their work
  • Protect account credentials, devices and access to registered email accounts; never share accounts
  • Remove or adjust access promptly when somebody leaves or changes responsibilities
  • Define operating procedures, approvals, retention decisions and required staff training
  • Validate that the configured system and exported evidence meet applicable quality or regulatory needs

Responsible reporting

Found something we should investigate?

Please use our existing contact channel and include enough detail for us to understand and reproduce the issue. Avoid accessing, changing or retaining data that is not yours.

Contact Obsidian Metra
Security posture evolves. This overview reflects implemented controls in the current product. It intentionally makes no claim of SOC 2, ISO 27001 or other independent certification, and it does not promise a particular uptime, incident-response time, backup regime or data-residency location.