Record personnel technical authorisations
A personnel technical authorisation records what an organisation member is authorised to do, within which scope and limits, and for what period. It is separate from the member's application role and permissions. A calibration engineer role does not by itself prove competence or technical authorisation.
Prerequisites
- Select the organisation that employs or controls the person.
- Ensure the person has an active organisation membership.
- Define the authorised activity, technical scope, and any limits.
- Agree the effective date and optional expiry date.
- Upload and approve any controlled PDF evidence that should support the authorisation.
- Have technical authorisation management permission.
- Arrange for an authorised decision-maker who is independent of the person receiving the authorisation.
Create the draft authorisation
- Open ISO 17025 audit.
- Open Personnel authorisations.
- Start a new authorisation.
- Select the organisation member.
- Enter the Activity reference.
- Enter the Authorisation scope.
- Record any limits on methods, ranges, equipment, locations, supervision, or approval activity.
- Enter the effective date and expiry date where applicable.
- Select the approved supporting document revisions that evidence competence or the authorisation decision.
- Save the authorisation as a draft.
Use a scope that is specific enough to distinguish what the person may and may not do. Do not place an authorisation in a broad application role merely to avoid recording technical limits.
Activate the authorisation
- Open the draft authorisation.
- Review the member, activity reference, scope, limits, dates, and supporting evidence.
- Confirm that the proposed effective and expiry dates are correct.
- Select Activate when the authorisation decision has been made by an eligible authorised user.
Activation records who authorised the scope. The current status becomes active according to the controlled lifecycle and dates; it does not change the member's application permissions.
Maintain the lifecycle
The displayed lifecycle states are:
draft: prepared but not yet activeactive: current technical authorisationsuspended: temporarily unavailableexpired: no longer current after its validity ends or an expiry actionsuperseded: replaced by a later controlled authorisation
Use the available lifecycle action rather than editing the status in ordinary fields. Record the required reason for suspension, expiry, supersession, or another controlled transition.
When an active authorisation's scope, limits, dates, or supporting evidence need revision:
- Select Edit.
- Update the controlled fields.
- Enter the Revision reason.
- Select Save revision.
- Review the updated record and activate it again when appropriate.
Saving a controlled revision returns the authorisation to draft for activation review. Previous revisions remain retained; the edit does not silently change an active technical decision.
Review expiry
- Regularly filter or review authorisations approaching their expiry date.
- Verify competence and supporting evidence before extending or replacing an authorisation.
- Create a controlled revision with the new dates and evidence.
- Complete activation review before relying on the revised authorisation.
- Leave expired or superseded records in history.
An expired authorisation remains evidence of the earlier authorised period. It must not be presented as current authority.
Expected result
The member has a traceable technical authorisation showing the activity, scope, limits, supporting evidence, authoriser, effective date, expiry date, lifecycle status, and revision history. Application access remains governed separately by organisation membership permissions.
Warnings
- Never infer technical competence from an application role, job title, or ability to use a screen.
- Supporting evidence must be a current approved controlled revision when it is selected.
- An expiry date in the future does not prove continuing competence; follow the organisation's review process.
- Do not overwrite an expired, suspended, or superseded record to make it appear continuously active.
Permissions and separation of duties
Technical authorisation read and management permissions are separate from evidence approval, calibration-event approval, and dossier review. The subject of an authorisation must not authorise themselves. An application owner remains subject to the technical-authorisation decision and separation-of-duties rules.
If an action is unavailable, check the membership status, authorisation lifecycle, supporting evidence status, effective permission, and whether the intended decision-maker is independent.