No template library, no consulting sprint, no schema written by hand. An agent connected to the Koddex MCP read the brief, drew the conclusions from the diagrams, and created the models, the relationships and the computed severity roll-up directly in the workspace.
Full ISO 14971 traceability, built while you watch: one prompt, 13 models, 17 declared links. Placeholder workspace name.
A regulatory consultant in medical devices wanted to know whether Koddex could hold the risk structure he rebuilds, spreadsheet by spreadsheet, on every programme. He sent an email and two diagrams drawn by hand. That was the entire input — handed to Claude with one instruction: set this up in the workspace.

Consultant, manufacturer and device unnamed at their request. The workspace in the film uses a placeholder name.
Hazard, harm, severity, control, requirement — all connected, and kept connected while the design changes. A spreadsheet holds the rows. It cannot hold the links.
Change one harm and every severity that depended on it is silently wrong.
Residual risk can only be scored if you can see how a control was implemented. In a grid, that link lives in someone's head.
An auditor asks how much testing a software item needs. A reviewer asks which items one control touches. A flat file answers neither.

Severity and probability are entered by a person. The risk index is not — it is computed, and there is no cell to overwrite.
The workspace's own Where-used view. Walkable from either end.
Access tags decide who sees which row.
| Name | Hazard | Severity | Probability | Risk index | Access tag |
|---|---|---|---|---|---|
| Incorrect dose displayed | Software fault | 5 | 3 | 15 | clinical |
| Unintended actuation at setup | Stored energy | 4 | 3 | 12 | quality-core |
| Air embolism from line purge | Air in line | 5 | 2 | 10 | clinical |
| Overheating of drive unit | Excess heat | 3 | 3 | 9 | quality-core |
| Sharp edge on housing | Mechanical | 2 | 2 | 4 | quality-core |
ƒ Risk index = severity × probability — computed by Koddex, not typed by anyone.
Change either input and it moves on its own.
Drop a harm from 3 to 1 and the requirement and the software item both read 1. That number justifies test effort to an auditor.
It depends on the control type declared above it, and computed attributes only aggregate upwards. A feature, not a gap.
Nobody builds an ISO 14971 file in one place. Each tool is fine alone — the cost is the seams between them, paid again on every design change.
Every double arrow is a synchronisation somebody maintains by hand.
| Five tools, stitched | Koddex, on film | |
|---|---|---|
| Building the 13 object types | Days of workshops, then schema work in each tool | One prompt, two minutes |
| Declaring the 17 links | IDs copied from one tool into another | Declared with the models |
| Keeping the risk index right | A formula column — until someone pastes over it | Computed. No cell to overwrite |
| Staying aligned after a change | Re-export, re-import, reconcile. Every tool, every time | One graph. Nothing to synchronise |
| Standing it up | Days to weeks, then a sync cost forever | Two minutes, then minutes per iteration |
The Koddex column is measured, on film. The left column is an order-of-magnitude estimate for a conventional tool chain — not measured here.
Two minutes is the headline. The durable value is what it costs to be wrong — and the model always has to change.
Split a model, add the field you forgot: ask, review the diff, keep it. Restructuring is not a project.
No export to reconcile, because there is no second copy.
The consultant stops rebuilding scaffolding and spends the hours deciding whether a residual risk is acceptable.
The agent proposes structure at machine speed. A person keeps the risk judgement, and every write is attributed, scoped and revisable.
The agent proposes. The expert disposes.
The controls that make an agent safe make a team auditable.
Provenance on the item itself.
Who can read this risk.
Attributed, timestamped changes.
Frozen baselines, compared.
Every reference, before you touch it.
| Spreadsheet risk file | Koddex model | |
|---|---|---|
| Standing up the structure | Rebuilt by hand on each programme | Two minutes from the brief, then refined |
| Severity of a software item | Traced by hand through the hazard analysis | Computed, always current |
| Changing one harm | Silent inconsistency across tabs | Propagates to every dependent score |
| Impact of one risk control | Manual search across files | Reverse link lists the items it touches |
| Severity scale | Free text, per author | Controlled list, set at model level |
| Producing the risk file | Copy-paste into a Word template | Export an item with its children, attachments included |
“I'm thinking I might just do diagrams and let the agent do the modelling. That is much easier to do.”
A case study that only lists wins is no use to a quality manager.
Computed attributes only aggregate upwards. A field reads its children, never its parents — so residual probability stays a human decision. You can see the parent value; you cannot compute from it.
You get a first draft, not a release. The model still needed adjustment by someone who knows the device, and these diagrams were unusually clear. Quality of the brief decides quality of the output.
Export is structural, not editorial. An item and its children export as PDF with attachments. Pouring that into a client's Word template, section by section, is not a feature today.
No — the agent builds the structure, not the risk judgements. Severities, probabilities and acceptability are still entered and approved by qualified people, with the usual review trail.
It is computed, never typed: severity is entered once on the harm, and each level above takes the maximum of everything below it.
Not by design: it depends on the control type declared above it, and computed attributes only aggregate upwards — so a reviewer sets it deliberately.
Any MCP-capable client — this session used Claude. Your team connects its own client and tokens, so the agent works with your access rights.