Docs menu
How the platform's validation approach affects your compliance burden.
Compliance is built into the platform's architecture rather than added through configuration. This section covers what's validated at the platform level, and what your ops/compliance team still validates.
Compliance is enforced by the node architecture.
Traditional systems prove compliance by validating a configuration, then re-validating on every change. CMS Buildings builds compliance into the node architecture, so validation is continuous and built in rather than a manual re-do on every release.
- Every node maps to a governance principle — see the full mapping at /compliance
- A change to the system is itself readable and auditable
- Reason-for-change is captured structurally, not by policy alone
- The audit trail is immutable and append-only
- Data is available for audits via surface views and export — not a data-pull request to us
- Access is gated by role, so every screen a user sees is already within their authorized scope
Every mutation requires a categorized reason.
When a user corrects a record, the platform requires a structured reason before the change is accepted — the same categories your compliance process already recognizes.
| Category | When it applies |
|---|---|
| Correction of error | Fixes a data-entry or process mistake. |
| Additional information | Adds detail that wasn't available at the time of entry. |
| Code or spec update | Reflects a change to a building code, energy code, or project spec. |
| Owner/tenant request | Made at the property owner's or tenant's direction. |
| Regulatory requirement | Required to meet a regulatory obligation. |
| System-generated | Automated correction (e.g. reconciliation), still attributable. |
| Other | Requires a free-text note — the only category that does. |
Reports available to auditors today.
These reports exist in the running application, not as mockups, and compose into a single exportable audit trail.
Asset-history report
Composes audit events, transfers, and decommissioning into one timeline per asset, from commissioning through end of life.
Audit trail
Immutable, attributable event log — every event tagged with the specific governance principle it satisfies, filterable by user and action type, and exportable to CSV for your auditors.
Vendor & access approvals
Vendor-credential tracking with expiry alerts, satisfying access-gating requirements.
Effort & capacity reporting
Manager-level effort broken down by workflow stage (commissioning, transfer, reconciliation, decommissioning) — useful evidence for staffing and workload review during an inspection.
Regulatory standards covered by the platform.
NFPA life-safety codes
Inspection scheduling and immutable audit trails for fire and life-safety systems.
ASHRAE & energy codes
Structured reason-for-change captured on every setpoint and schedule mutation.
OSHA
Workplace-safety inspection tracking with expiry alerts.