Read-only access in laboratory software is a permission: a named person can see a record or a map and cannot change it. It is not an audit trail, and it is not a free Viewer license. What it protects is edit rights. A reviewer who must inspect yesterday's entry without rewriting it is the usual reason to grant it. This page keeps that permission in its own column and refuses to treat software as a compliance certificate.
What Read-Only Access Protects
The object is an access right on a person and a record or project: visibility without the right to alter the object. The protected thing is edit rights, not secrecy by itself. A collaborator can be allowed to open the experiment and still be forbidden to add, remove, or edit it. 21 CFR 11.10(d) states the control in official language: limiting system access to authorized individuals. The clause does not name a role called Read-Only. It requires that access match authorization. Read-only is one way to give visibility without handing over the edit key.

A finalized record may also sit in a read-only state after sign-off. That is a lock on the object — still a withheld write, still not a Viewer SKU. Seeing a record is not the same as being allowed to change it. A shared password with a "please don't edit" note is also not this permission. The software has to enforce the withhold, or you only have a request.
Read-Only Is Not an Audit Trail
Read-only limits who may change a record. An audit trail independently records who already created, modified, or deleted one. Those are adjacent letters in the same regulation, not the same object. 11.10(d) is the access limit. 11.10(e) is a secure, computer-generated, time-stamped audit trail that independently records the date and time of those operator actions.
A lab can grant read-only and still lack a trail, or write a detailed trail and still let too many people edit. The permission answers "who is allowed to change this." The trail answers "who already did." The existing audit-trail explainer owns the trail object. This page only needs the split.
Read-Only Is Not a Viewer License
A Viewer license is a product seat that opens files. Read-only is a permission bit inside a shared system. SnapGene Viewer is marketed as free visualization, annotation, and sharing with the same viewing capabilities as the fully enabled product. That is a SKU. Annotation on a desktop Viewer is already a write of a kind. It is not the same as a denied write on a shared ELN entry.
Buying Viewer seats does not set ELN permissions. A full editor seat can still be granted read-only on one project. The license and the permission are not the same purchase. If you asked IT for "read-only" and they bought a desktop viewer, you asked for the wrong object.
Read-Only Versus Audit Trail Versus Viewer
Keep the three objects on a ticket in separate columns. One product can ship all three. That does not merge them.
| Question |
Read-only access |
Audit trail |
Viewer license |
| What is it? |
A permission on a named person and a specified record or project |
A system-written, time-stamped log under 11.10(e) |
A product SKU or mode that opens files |
| What does it protect? |
Edit rights — the person can see the object and cannot change it |
Reconstructability of create, modify, or delete actions |
The vendor's commercial boundary for unpaid viewing |
| Can the person edit? |
No, if the permission is enforced |
The trail does not decide that |
Often yes for annotation; Viewer is not automatically non-editable |
| Is it 11.10(e)? |
No — access limits sit in 11.10(d) |
Yes |
No — a license is not a control letter |
Fill the ticket with one object name. "We need read-only for the reviewer" is a permission request. "We need to know who changed the entry" is a trail request. "We need people to open maps without paying for clone tools" is a SKU request.
What Lab Software Can and Cannot Finish
Software can limit who edits. It cannot finish laboratory compliance. 11.10 opens by asking the people who use closed systems to employ procedures and controls. Access limits sit beside validation, complete copies, retrieval, and trails. Setting a read-only role implements one of those letters. It does not finish the list.
After that boundary is clear: the ZettaNote product page lists read and write access levels for project management. That is a capability statement — the ELN can express those two levels — not a finding that a laboratory using the software meets 21 CFR Part 11. No feature checkbox on this site can make that finding.
If the next question is the log rather than the permission, return to the audit-trail page. The takeaway here is the withheld write: see the record, leave the record. Ask for a Viewer license only when the missing object is a desktop SKU.
Frequently Asked Questions
Is read-only access the same as an audit trail?
No. Read-only limits who may change a record. An audit trail records who already created, modified, or deleted one. A lab can have one without the other.
Is a free Viewer the same as read-only access?
No. A Viewer is a license to open files. Read-only is a permission inside a shared system. Some Viewers still allow annotation, which is already more than a withheld write.
Who should get read-only access to a lab record?
Anyone who must see the record and must not be able to change it — a reviewer, an external collaborator, or a PI who is inspecting, not editing. The test is the withheld write, not the person's title.
Does setting read-only access make a lab 21 CFR Part 11 compliant?
No. The permission can support an access-control objective under 11.10(d). Compliance is still laboratory work: validation, procedures, retention, and the rest of 11.10. Software cannot complete that list by existing.