The SME Sign-Off Log
Eighteen months after a pharmaceutical company shipped an AI-assisted good-manufacturing-practice refresh to four thousand operators, an inspector arrives and points at one screen. "This handling threshold," she says. "Who verified it?" In the room with no sign-off log, that question is a slow disaster: the designer who built it has left, the SME who knew the answer is in another meeting, and the team spends two weeks reconstructing a trail that may not exist. In the room with a sign-off log, it is a thirty-second lookup: the SME's name, the source the claim traces to, the date she approved it, and a record that has not been altered since. That difference, between a frantic reconstruction and a calm lookup, is the whole point of Stage 4, and it is what turns a fast AI build into a defensible one.
The Artifact That Answers Who Verified This
This is Stage 4 of the source-to-certified-course pipeline, and it is the stage that makes the other three count. Stage 1 grounded the content. Stage 2 validated the assessment. Stage 3 made the media conformant. Each produced verified work, but verification that leaves no record is, to an auditor, indistinguishable from verification that never happened. Stage 4 is the artifact that captures the verification as it occurs, so the question that ends careers, "who verified this," always has an answer ready before anyone asks it.
That artifact is the SME sign-off log. A subject-matter expert, or SME, is the human authority on the content: the compliance officer who owns the policy, the safety engineer who owns the procedure, the clinician who owns the protocol. Why you care: the SME is the person whose judgment certifies that a regulated claim is correct, and their approval is the difference between "the AI wrote it" and "a named expert verified it against the source." The sign-off log is the record of those approvals, and two more terms make it audit-grade. Provenance is the chain from a claim back to the source it came from, carried forward from Stage 1. Tamper-evidence means the record cannot be silently altered after the fact; any change is detectable, so the log proves not only what was approved but that the approval has not been quietly edited since. Why you care: a record that could have been changed later proves nothing to a regulator, because the whole value of the log is that it is trustworthy precisely when someone has a motive to revise history.
The sign-off log is the accountability artifact the entire program builds toward. It is where the iron rule becomes a document. "AI assists, the human verifies, the human owns the decision" is a principle until the log makes it a record: this human, this claim, this source, this date, unaltered. Without the log, the iron rule is a good intention. With it, the iron rule is evidence.
Verification without a record is a rumor. The sign-off log is what turns "we checked it" into "here is who checked it, against what, and when, and the record has not changed since."
What a Sign-Off Log Actually Records
A sign-off log is not a vague approval stamp on a whole course. It is a claim-by-claim record for every regulated, safety, or policy statement in the build, because those are the claims an auditor will pull and the ones a hallucination is most dangerous in. For each such claim, the log records a specific set of fields, and each field answers a question someone will eventually ask.
| Field | The question it answers |
|---|---|
| The claim | What exactly was approved, in the words that shipped |
| The source it traces to | Where the claim came from: the policy section, the SOP step, the protocol line, from Stage 1 |
| The SME who approved it | Which named human authority verified it |
| The date of approval | When it was approved, and against which version of the source |
| The AI involvement | That the claim was AI-drafted and human-verified, not silently machine-authored |
| The tamper-evidence marker | That this record has not been altered since the approval |
Notice that most of these fields already exist if Stages 1 through 3 were done well. The claim and its source come straight from the structured provenance fields of Stage 1. The validity chain from Stage 2 and the conformance record from Stage 3 are the same kind of evidence for assessment and accessibility. The sign-off log is largely an assembly of records you already generated, plus the SME's approval and the tamper-evidence, which is exactly why building provenance in from the first draft pays off here: the log is compiled, not reconstructed. A team that skipped provenance upstream faces the eighteen-months-later reconstruction; a team that built it in faces a lookup.
What Tamper-Evidence Means in Practice
Tamper-evidence does not require a blockchain or any exotic technology. It requires that the log be kept in a way where alterations are detectable and attributable: append-only entries, timestamps, version history that cannot be silently overwritten, and access controls that record who changed what. The standard a regulator applies is not "is this fancy" but "could someone have quietly changed an approval after the fact without it showing." If the answer is no, the log is tamper-evident enough. The point is not the mechanism; it is that the record's trustworthiness does not depend on trusting that nobody edited it, because edits would be visible.
This matters because of when the log is read. A sign-off log is never read on a quiet day; it is read when something has gone wrong, when an incident has occurred, when a regulator has questions, when a claim is being challenged. Those are precisely the moments when someone might have a motive to revise history, to make a missing approval appear to have happened, to change a date, to attach a name to a check that was never done. An editable document that anyone could have quietly altered carries no weight at exactly the moment it needs to, because the reader cannot rule out that it was edited to look better. A tamper-evident log keeps its value under suspicion. That is the whole reason the property is non-negotiable: the log is an evidentiary artifact, and evidence that could have been forged after the fact is not evidence.
Who Keeps the Log and When
The log is kept by the build team as the build happens, not handed to a compliance department to assemble at the end. The reason is the same one that governed Stage 1: a record created as the work occurs captures what actually happened, while a record assembled afterward captures what someone remembers or assumes happened. When a SME approves a claim, the approval is logged then, in that moment, with the source version in front of them. When a claim changes, a new approval is logged. The designer who runs the build owns the log the way a lab technician owns a lab notebook: it is a contemporaneous record of decisions, not a report written after the experiment. This is a small discipline that feels like overhead in the moment and is worth everything the day an inspector arrives, because the alternative, reconstructing months later who approved what, is the two-week archaeology the worked example describes.
A Worked Example: The GMP Refresh
Return to the good-manufacturing-practice refresh and watch the inspection land on two versions of the same build.
Before, the build with no log. The team rebuilt the GMP refresh fast with AI, grounded reasonably well, and shipped it to four thousand operators. The build was genuinely faster than the old way, and everyone moved on. Verification happened informally, a SME looked things over in a meeting, comments were left in a document that has since been overwritten, and no claim-by-claim record was kept. Eighteen months later the inspector points at the handling threshold and asks who verified it. The answer requires archaeology: find the version that shipped, find who was on the project, find whether the SME actually reviewed that specific claim or just glanced at the course, find what source it was supposed to trace to. Two weeks of work later, the best the team can offer is "we believe the compliance officer reviewed it," which is not evidence, it is a hope. The fast build became a slow, anxious, expensive audit, and the speed that looked like a win is now a liability with no paper trail.
After, the build with a sign-off log. The same team built the same refresh and kept a sign-off log as they went. Every regulated claim, including the handling threshold, carries its source from Stage 1, the name of the SME who approved it, the date, the source version, a note that it was AI-drafted and human-verified, and a tamper-evident marker. When the inspector points at the threshold, the answer is immediate: here is the claim, it traces to SOP section 7.3, the safety engineer approved it on this date against this version of the SOP, it was AI-drafted and verified by her against the source, and the record has not been altered since. The inspector checks the log, sees a clean chain, and moves on. The build was just as fast as the version with no log, because the log was assembled from records the team was already creating in Stages 1 through 3. The only added cost was capturing the SME approval and keeping the log tamper-evident, and that small cost bought a calm thirty-second answer to the question that cost the other team two weeks.
The two builds shipped the same content at the same speed. The difference was entirely the record. One team treated verification as a thing that happened and was forgotten; the other treated it as a thing that happened and was captured. When the inspector arrived, the captured verification was worth everything and the forgotten verification was worth nothing, because to an auditor an unrecorded check and an uncompleted check look identical.
To an auditor, verification you cannot prove and verification you never did are the same thing. The log is the difference, and you cannot create it after the question is asked.
It is worth dwelling on why the no-log team's situation is so much worse than it first appears, because the lesson is easy to underestimate when the build is going well and no inspector is in the building. The team did real work. A SME genuinely did look at the content. The threshold may even have been correct. None of that helps them, because the value an auditor places on verification is not "did diligence occur" but "can diligence be demonstrated," and those are different questions with different answers. The team that cannot demonstrate it is in the same position, legally and practically, as a team that was reckless, even though they were not. They are punished not for failing to verify but for failing to record that they verified, and the punishment is identical to the one a negligent team would receive. That asymmetry, real work made worthless by a missing record, is the specific trap the sign-off log exists to close, and it is why the discipline of logging is not bureaucratic box-ticking but the act that protects the team's own careful work from being indistinguishable from carelessness.
Notice also a subtler cost in the before-version: the reconstruction itself introduces new risk. When a team spends two weeks trying to establish who approved a claim eighteen months ago, the answer they assemble is itself unreliable, built from memories, partial documents, and inference. If they tell the inspector "the compliance officer reviewed it" and that turns out to be wrong, they have now made a false statement to a regulator on top of the original gap. The absence of a contemporaneous record does not just leave a hole; it pressures the team to fill the hole with a reconstruction that may be incorrect, compounding the exposure. The tamper-evident log, captured at the time, is the only version of events that does not require anyone to remember or guess, which is why it is safer for the team and more credible to the regulator at the same time.
The Log as the Pipeline's Keystone
Stage 4 is where the whole pipeline becomes defensible rather than merely fast, and it is worth seeing why the log is the keystone that holds the other three stages in place. A grounded draft with no sign-off is a claim someone says is sourced. A validated item bank with no record of who validated it is a test someone says is valid. A conformance check nobody signed is accessibility someone says they verified. The sign-off log is what converts every "someone says" across the pipeline into "here is the named human who says it, and here is the unalterable record." It is the artifact that lets the graduate make the sentence the whole program is built to earn: here is the build time cut from six weeks to four days, here is the verification log proving every regulated claim traces to an approved source and a named approver, here is the accessibility conformance report, and here is the behavior-change data, all defensible to compliance, accessibility, and finance.
And the log is where the iron rule stops being a slogan and becomes an operating discipline. AI assists, the human verifies, the human owns the decision, and the log proves it. When a regulator, an auditor, or a plaintiff's lawyer asks "who is accountable for this regulated claim," the answer is not "the AI" and not "the vendor" and not "we think someone checked it." The answer is a name, a source, a date, and a record that has not changed. That is what accountability looks like when it is real, and it is the difference between a learning function that can use AI at speed and one that cannot afford to. The sign-off log does not slow the build. It is what makes the fast build survivable.
There is a strategic point hidden in that last sentence that is easy to miss when the log feels like paperwork. The organizations that will win with AI in learning are not the ones that build fastest; they are the ones that build fast and can prove it was done right, because only those organizations can keep using AI at speed after the first audit, the first incident, or the first legal challenge. A team that builds fast and cannot defend it gets one disaster, and then leadership clamps down, AI use is restricted, and the speed advantage evaporates under a cloud of risk. A team that builds fast and hands the auditor a clean sign-off log gets to keep going, because they have demonstrated that speed and accountability are not in tension in their hands. The log is therefore not a tax on the fast build; it is the permission slip that lets the fast build continue. The function that treats verification as a record-keeping discipline rather than an afterthought is the function that gets to keep its AI advantage instead of losing it the first time someone asks a hard question.
Step back and see the whole pipeline from the vantage of Stage 4, because this is where its shape becomes clear. The four stages are not four separate good practices bolted together; they are one continuous chain of accountability with a single property running through it: every claim that reaches a learner can be traced back to a source, a verification, and a named human, and that trace cannot be quietly altered. Stage 1 establishes where the claim came from. Stage 2 establishes that any test of it measures the right thing. Stage 3 establishes that everyone can access it. Stage 4 establishes who stands behind all of it, in a record that holds up under suspicion. Remove any one stage and the chain breaks: ungrounded content has nothing to sign off on, an invalid item certifies the wrong people no matter who approved it, inaccessible media excludes learners regardless of how well it is logged, and an unrecorded approval is no approval at all. The sign-off log is the last link, and the last link is the one that bears the weight when someone pulls on the chain.
Key Takeaways
- Stage 4 of the pipeline is the SME sign-off log, the tamper-evident record of who approved every regulated claim, which makes the verification of the other three stages count by capturing it as a record.
- To an auditor, verification that leaves no record is indistinguishable from verification that never happened; the log exists so 'who verified this' always has an answer ready before it is asked.
- A SME is the named human authority on the content whose approval is the difference between 'the AI wrote it' and 'a named expert verified it against the source.'
- The log records, claim by claim for every regulated statement: the claim, its source, the approving SME, the date and source version, the AI-drafted-and-human-verified status, and a tamper-evidence marker.
- Tamper-evidence means alterations are detectable and attributable (append-only entries, timestamps, version history, access controls); the test is whether someone could have quietly changed an approval without it showing.
- The log is largely assembled from the structured provenance of Stage 1, the validity chain of Stage 2, and the conformance record of Stage 3, which is why building provenance in upstream turns the log into a compilation, not a reconstruction.
- The GMP example shows the stakes: the same fast build with no log meant two weeks of archaeology ending in 'we believe someone checked it,' while the build with a log meant a calm thirty-second answer.
- The log is the keystone that converts every 'someone says it is sourced, valid, accessible' into a named human and an unalterable record; it is where the iron rule becomes evidence, because AI assists, the human verifies, the human owns the decision, and the log proves it.
Skill.re