CONTROLLED INFORMATION. GOVERNED OPERATION. 

Document Control Software for Review, Approval and Evidence

Govern the Information That Regulated Work Depends On

Zebsoft controls the lifecycle surrounding policies, procedures, specifications, drawings, work instructions, forms and external requirements. Each governed document can have defined ownership, review, approval, publication, visibility, change history and withdrawal arrangements.

This matters where using the wrong revision can affect product conformity, nuclear safety, medical-device quality, process integrity or the acceptance of work within an oil and gas supply chain. 

  • Establish one identifiable current approved version
  • Control who may create, review, approve, publish and view information
  • Communicate changes to the roles and sites affected
  • Retain evidence of decisions, revisions, review and withdrawal
Document control governance from creation and approval to use and assurance

MORE THAN FILE STORAGE 

A Repository Holds Files. Governance Controls Their Authority.

SharePoint, shared drives and cloud folders can be useful repositories. The control problem begins when users cannot readily determine which version is approved, who authorised it, where it applies, whether it has changed or what should happen to the previous revision. 

 

Storage

Provides a location for files, folders and collaboration. Storage alone does not establish operational authorit y.

 

Document control

Defines identity, ownership, status, review, approval, issue, distribution, revision and withdrawal. 

 

Document governance

Connects those controls to roles, sites, risks, competence, audits, suppliers and the work affected by the document. 

The purpose is not to move every file into another system. It is to identify which information carries controlled authority and govern that information proportionately. 

CONTROL WHAT DIRECTS WORK—PROTECT WHAT PROVES IT 

Documents and Records Serve Different Control Purposes

A procedure or drawing normally tells people what should happen. A completed inspection, approval, test result or acknowledgement records what did happen. Both are documented information, but their governance routes are not identical. 

Controlled documents

Policies, procedures, specifications, drawings, work instructions, templates and manuals may change. Their controls should address review, approval, issue, revision, availability, withdrawal and prevention of unintended use. 

  • Current approved content
  • Defined applicability and effective date
  • Revision and change history
  • Controlled access and distribution

Controlled records

Completed forms, inspection results, certificates, approvals, acknowledgements and other evidence normally require protection from inappropriate alteration, loss or premature disposal. 

  • Identifiable source and context
  • Integrity and authorised access
  • Retention and retrieval rules
  • Controlled disposal where applicable

THE CONTROLLED LIFECYCLE 

From Authoring to Withdrawal Without Losing Authority

Zebsoft can structure the stages around a document so its current status and history remain visible. 

01 

Create

Author content in the embedded editor or register an externally produced file with its metadata and owner. 

02 

Classify

Set document type, group, site allocation, sensitivity, visibility and applicable review route. 

03 

Review

Route the draft to suitable reviewers so technical, operational and compliance implications are examined. 

04 

Approve

Hold content in a pending state until the person with configured authority records the approval decision. 

05 

Publish

Make the approved version available to the authorised audience with a clear status and effective route. 

06 

Communicate

Notify or broadcast the change and, where configured, retain acknowledgement or training ac tivity.

07 

Review and revise

Prompt periodic review, record proposed change and repeat the required approval route. 

08 

Withdraw or archive

Remove superseded content from operational use while retaining the permitted history and evidence. 

GOVERNANCE CONTROLS BUILT AROUND THE DOCUMENT 

Apply the Right Controls to Each Information Type

Not every document needs the same route. Zebsoft document control software allows the organisation to configure controls according to risk, authority, audience and inten ded use.

 

Tiered registers

Separate policies, procedures, forms, guides, standards and other information types while maintaining a navigable structure. 

 

Embedded authoring

Create and edit governed content inside Zebsoft using the WYSIWYG editor, retaining metadata and saved-history context.

 

Approval states

Control movement from draft to pending review and approved publication according to configured authority. 

 

Review reminders

Set planned review points and notifications so overdue decisions remain visible to responsible roles. 

 

Site allocation

Apply documents to one site, selected sites or the wider organisation rather than publishing everything globally. 

 

Role and sensitivity

Combine job-role, location and sensitivity logic to control who may see governed information. 

 

Groups and subgroups

Build a logical virtual structure without relying on uncontrolled duplicate folder copies. 

 

Audit history

Retain user, time, status, version, review, approval and archive activity as part of the governance record. 

A CONTROLLED CHANGE IN PRACTICE 

When a Safety-Critical Instruction Changes

Consider a change to a welding procedure, inspection plan, design specification, nuclear work instruction or medical-device manufacturing SOP. Publishing a new PDF is not enough. The organisation must determine where it applies, who must review it, what evidence supports the change and how the previous revision will be removed from use. 

  • Open the proposed revision against the current approved document
  • Describe the reason for change and identify affected requirements or risks
  • Route technical, quality, safety and regulatory review as appropriate
  • Record approval by the configured authority before release
  • Set the applicable sites, roles, suppliers and effective arrangements
  • Communicate the new revision and create acknowledgement or training activity where required
  • Withdraw superseded content from normal use while retaining permitted history
  • Use audit or operational checking to verify that the revised instruction is being followed

The workflow makes each stage visible. The customer remains responsible for defining the required reviewers, validation, qualification, retention and regulatory controls. 

ZAP controlled document change showing review approval sites effective date and superseded revision

HIGH-ASSURANCE INDU STRIES

Document Governance for Work Where Revision Matters

Sector standards differ, but they share a need for documented information that is identifiable, authorised, current at the point of use and supported by retrievable records. Zebsoft supplies configurable governance capability; it does not make an organisation conform to a standard automatically. 

 

Oil, gas and energy

Support governance around procedures, specifications, drawings, inspection and test plans, supplier documents, certificates, deviations and management-of-change records used within ISO 29001 or API Spec Q1 environments. 

 

Nuclear supply chain 

Control the authorised information supporting products and services important to nuclear safety: technical requirements, graded controls, inspection evidence, configuration changes, supplier documentation and retained history within an ISO 19443 context. 

 

Medical devices 

Govern quality procedures, design and manufacturing information, forms, approvals, device-related records and change evidence supporting an ISO 13485 quality system and applicable FDA QMSR responsibilities. 

The appropriate configuration depends on the organisation’s products, contractual requirements, applicable regulations, classification, risk and valida tion strategy.

CONTROLLED TECHNICAL INFORMATION 

Govern More Than Policies and SOPs

In engineering and regulated operations, the information controlling work may sit across several document families. The governance model should recognise what each document does and how it relates to the product, process, asset, supplier or requirement. 

 

Requirements and specifications

Customer requirements, codes, standards, technical specifications, acceptance criteria and approved deviations. 

 

Production and service

Work instructions, route cards, inspection and test plans, maintenance instructions and controlled forms. 

 

Design and configuration

Drawings, design outputs, bills of material, configuration records, calculation references and approved changes. 

 

Evidence and release

Inspection results, certificates, test reports, approvals, concessions, release evidence and completed quality records. 

Zebsoft can hold governed documents and relate them to wider records. Where a specialist engineering, PLM, CAD or validated repository remains the master source, ZAP can govern the responsibility, reference and assurance route without creating an uncontrolled duplicate. 

ZAP external document register showing standards specifications owners revisions and review dates

EXTERNAL INFORMATION UNDER CONTROL 

Know Which Standard, Specification or Customer Requirement Applies

Organisations often control internal procedures carefully while relying on downloaded standards, customer specifications, supplier manuals or regulatory guidance with unclear ownership and revision status. External documented information needs its own governance route. 

  • Identify the external source, title, revision and accountable owner
  • Record where the authoritative copy is obtained and who may access it
  • Link the information to relevant processes, contracts, products, sites or suppliers
  • Review amendment, replacement or withdrawal information at defined points
  • Assess the impact of a changed external requirement before updating internal controls
  • Prevent uncontrolled downloaded copies from being mistaken for the governed reference

Zebsoft can provide the register, ownership and review workflow. Access to copyrighted standards and external sources remains subject to the organisation’s licences and permissions. 

THE RIGHT INFORMATION AT THE POINT OF USE 

Control Visibility Without Hiding Responsibility

Publishing every document to everyone creates noise and can expose sensitive information. Restricting too heavily can leave people without the instruction they need. Governance requires deliberate allocation. 

 

Site applicability

Publish the approved information to the location or locations where it governs work. 

 

Role applicability

Use job role and configured permissions to direct information to the people responsible for applying it. 

 

Sensitivity

Apply appropriate visibility to internal, management or more restricted content without creating duplicate masters. 

 

External access

Where portals and permissions are configured, share selected governed information with suppliers, contractors, employees or customers. 

PUBLICATION DOES NOT PROVE UNDERSTANDING 

Connect Document Change to Communication and Competence

A published revision only becomes operational when the affected people know it has changed and are capable of applying it. The response should reflect the significance of the change. 

 

Notify

Issue targeted notification or broadcast communication to the applicable roles and sites. 

 

Acknowledge or train

Use acknowledgement for awareness where appropriate, or create training and competency activity when the change affects capability. 

 

Assure

Use audit, inspection, supervision or process monitoring to determine whether the revised instruction is operating in practice. 

An acknowledgement proves receipt of a task or communication; it does not by itself prove understanding, competence or effective implementation. 

EVIDENCE OF GOVERNANCE 

See Which Documents Need Attention Before They Become a Control Failure

Document dashboards should show the current governance position rather than inventing a compliance score. Zebsoft can surface status and exceptions for authorised users. 

  • Drafts and pending approvals awaiting action
  • Documents approaching or exceeding their planned review date
  • Approved documents by type, site, group, owner or sensitivity
  • Recently revised, published, withdrawn or archived information
  • Acknowledgement or training activity linked to significant changes
  • History supporting audit examination of review, approval and issue

Management can then investigate why work is overdue, whether the document remains suitable and what action is proportionate. 

ZAP document control dashboard showing approvals reviews publication and withdrawal status

DOCUMENTS CONNECT TO THE SYSTEM THEY CONTROL 

Make Document Governance Part of Operational Assurance

A document should not sit apart from the risks, people, suppliers and processes that depend on it. 

 

Audit management

Reference controlled procedures and evidence in audits; use findings to trigger review or withdrawal.
Explore audit management → 

 

Risk management

Relate documents to controls and treatments so significant change prompts a proportionate risk review.
Explore risk management → 

 

Training and competency

Turn significant revisions into assigned awareness, training or competence activity.
Explore training and competency → 

 

Supplier assurance

Connect controlled specifications, requirements and responses to supplier approval and oversight.
Explore supplier management → 

Use document control as part of the wider QMS, enterprise eQMS or Integrated Management System. 

STANDARDS CONTEXT AND RESPONSIBILITY 

Configure the Governance Route Around Applicable Requirements

ISO 10013 provides general guidance for developing and maintaining documented information. Sector requirements add different expectations according to product, safety, regulatory and supply-chain risk. The organisation must interpret those requirements and determine the controls, records, retention and validation applicable to its operations. 

 

ISO 10013:2021

Guidance for documented information supporting quality and other management systems.
Official ISO overview → 

 

ISO 29001:2020 and API Q1

Sector quality-management context for petroleum and natural-gas product and service supply organisations.
ISO 29001 overview →
Official API Spec Q1 page → 

 

ISO 13485 and FDA QMSR

Medical-device quality-system context. FDA QMSR incorporated ISO 13485:2016 by reference and became effective on 2 February 2026.
Official FDA QMSR page → 

 

ISO 19443:2018

Quality-management requirements for organisations supplying products and services important to nuclear safety.
Official ISO overview → 

Important: software features, audit trails and approval history do not establish regulatory compliance by themselves. Where electronic records, electronic signatures, computer-system validation or product records are regulated, the customer must assess intended use, applicability and validation within its own quality and regulatory system. 

COMMON QUESTIONS 

Document Control Software FAQs

Can Zebsoft replace SharePoint?

It depends on the intended use. SharePoint may remain useful for collaboration and general file storage. Zebsoft is designed to govern controlled information through defined status, ownership, review, approval, visibility and history. The two may serve different purposes. 

Can we upload Word, Excel and PDF documents?

Externally authored files can be registered with clear metadata and status. The organisation should decide whether the uploaded file is the controlled master, a reference or an uncontrolled convenience copy. 

Can different sites use different documents?

Yes. Site allocation and visibility controls can make approved information available to the locations and roles for which it is intended, subject to the configured governance model. 

Does Zebsoft support regulated industries?

Zebsoft provides configurable document-control capability relevant to ISO, oil and gas, nuclear-supply-chain and medical-device environments. Suitability and conformity depend on the customer’s requirements, configuration, procedures, validation and use. 

Does an approval history count as an electronic signature?

Not automatically. Electronic-signature status depends on applicable requirements, identity controls, meaning, implementation and validation. Customers should assess their intended use before presenting an approval as a regulated electronic signature. 

Can a document change trigger training?

Yes. Where configured, a significant revision can be connected to communication, acknowledgement, training or competency activity and later checked through audit or operational assurance. 

BUILT ONCE. CONTINUOUSLY GOVERNED. 

Control the Information That Controls the Work

Bring one real document route to a demonstration—such as a safety-critical work instruction, external standard, engineering specification or regulated SOP. We can explore how ownership, approval, applicability, communication, revision and evidence could be governed in ZAP.