GLI GLI Quality Tool
GLI Quality Tool — Version 2.0

Document distribution and access control for TB laboratories

Every tuberculosis laboratory generates a steady flow of standard operating procedures, result reports, safety data sheets, training records and audit logs. Without a deliberate policy for moving these documents around and deciding who may see them, even a small pathology service in Adelaide or a regional sputum processing hub near Cairns will struggle to demonstrate integrity. A well-designed policy provides the framework that ties controlled paperwork to clinical safety, accreditation readiness and patient confidentiality.

In Australia, TB laboratories operate within a layered regulatory environment. National accreditation through NATA requires conformance with AS ISO 15189, state public health legislation lists tuberculosis as a notifiable disease, and the Privacy Act 1988 places strict obligations on how identifiable patient information is handled. Designing the policy with these requirements in mind from the outset prevents costly rework when assessors arrive, and it also reassures the laboratory workforce that every paper or electronic file they touch has a clear owner and a defined audience.

Defining scope and document classification

The first practical step is to decide which documents fall inside the policy and how they should be classified. A useful starting point is the GLI roadmap, which outlines the foundational activities for new laboratories. Reviewing phase one guidance helps teams identify the categories of records that must be controlled before the first specimen is processed.

A tiered classification keeps things manageable. Public documents such as patient information leaflets and specimen collection instructions can be shared widely. Internal documents cover most SOPs, training plans and equipment manuals, and they are restricted to staff with a relevant role. Confidential documents include identifiable patient results, biosafety risk assessments and quality review minutes, while highly restricted records cover things like biosecurity keys, validation credentials and any data subject to legal privilege. Each tier needs its own storage rules, distribution list and disposal pathway.

For a TB laboratory this matters in a tangible way. A microscopy standard operating procedure may be shared with every bench scientist in the Brisbane laboratory, while the corresponding risk assessment for a containment level 3 procedure is limited to trained operators and the laboratory director. Mapping these tiers in a single table at the front of the policy saves time later and gives auditors a quick orientation tool.

Building a document register and master list

Once documents are classified, they need to be listed. A document register, sometimes called a master list or document inventory, records every controlled file by title, unique identifier, current version, owner, issue date, review date and location. The register is itself a controlled document, which means it must be governed by the same rules it describes. Many Australian laboratories align the register's fields with the record requirements of their NATA accreditation folder so that evidence can be cross-referenced during surveillance visits.

The register is the natural place to record who receives each document. A column for distribution recipients allows the laboratory manager to see at a glance whether a new version of the TB culture inoculation SOP has reached every bench in Perth, every regional collection centre and the offsite archive. Linking the register to an electronic folder structure means a change of version can be tracked, and superseded copies can be flagged for withdrawal. When the document register is kept current, the policy becomes self-auditing, because every receipt and signature falls back to a defined entry.

A common mistake is to treat the register as an administrative chore rather than a live tool. In a busy TB laboratory serving both metropolitan catchments and remote communities through outreach services such as the Royal Flying Doctor Service, the register is the only reliable way to confirm that a critical change has reached every site. Embedding quarterly register reviews into management meetings keeps the list honest.

Choosing distribution channels

Distribution methods vary depending on the resource setting, the classification of the document and the geography of the laboratory. Some sites in the Northern Territory still rely on paper because of intermittent connectivity, while a metropolitan service in Sydney or Melbourne may operate almost entirely through an electronic quality management system. The policy should describe how each channel is used, the controls applied and the records kept.

Distribution channel Strengths Weaknesses Typical controls
Paper in a controlled binder Works offline, easy to read, low technology barrier Prone to photocopying, slow to update, hard to track each copy Numbered copies, signed receipt log, periodic reconciliation
Shared electronic folder Searchable, version history, audit trail Depends on network, may be accessed from unmanaged devices Role-based permissions, automatic version numbering, watermarking
Quality management software Integrated approvals, electronic signatures, retention automation Licensing cost, training required, vendor dependency Unique user accounts, access reviews, automated retention rules
Email distribution Fast, familiar, reaches remote sites Easy to forward, hard to recall, weak audit trail Encrypted attachments, distribution lists, receipt confirmation

A useful rule of thumb is to match the channel to the classification tier. Public documents may be posted on an open noticeboard or website, internal documents should sit behind a staff login, and confidential records need both encryption and a logged distribution list. Many Australian laboratories combine paper for the bench reference folder with an electronic system for governance, a hybrid model that suits both urban and regional workflows.

A worked example helps clarify the approach. Suppose a laboratory is rolling out a revised protocol for transporting sputum specimens from remote clinics. The accompanying cold chain protocol guide is internal, so it goes into the electronic quality system with role-based access. A short summary card with key temperature checkpoints is printed for couriers, and the courier vehicle log is classified as confidential because it links patient identifiers to transport conditions. Each artefact has a defined audience, and the policy records how changes will be communicated in future.

Access control by role and need-to-know

Classification sets the ceiling, but access control decides who actually reaches the document. Role-based access is the most practical model in a TB laboratory, because it groups staff by function rather than by name. A bench scientist, a quality manager, a section head and a courier each see a different slice of the document set, and the policy spells out those slices in a simple matrix.

Need-to-know adds a second filter for confidential material. A microbiologist investigating a potential laboratory-acquired exposure may legitimately view the relevant biosafety risk assessment, while the same assessment is withheld from a clerical officer whose role does not involve contact with specimens. Documenting these exceptions is important, since regulators will ask how temporary access was granted, reviewed and revoked.

Strong access control also depends on everyday habits. Shared passwords, sticky notes with server logins and unlocked offices are common findings in audit reports from regional sites. The policy should require individual user accounts, password rotation, screen locking and clear-desk practices. Where electronic records contain identifiable patient information, the laboratory must also satisfy the Australian Privacy Principles under the Privacy Act 1988, including the reasonable steps principle for protecting personal information from misuse or unauthorised disclosure.

Version control, retention and disposal

Documents change, and the policy must describe how changes are approved, communicated and recorded. Each controlled document should carry a version number, an issue date, an author, a reviewer and an approver, with the signatures held either on the document itself or in the electronic quality system. When a new version is issued, superseded copies must be withdrawn promptly, either destroyed or marked as obsolete, and the master list updated on the same day.

Retention periods reflect clinical, accreditation and legal requirements. TB laboratory records in Australia are typically retained for several years after the last patient encounter, in line with state health records acts and NATA expectations. Pathology materials, consent forms and quality records each have their own minimum retention window, and the policy should list these rather than relying on staff memory. Once the retention period expires, documents are disposed of through a documented process, whether that means secure shredding for paper or cryptographic erasure for electronic media.

Version control extends to the policy itself. A document distribution and access control policy that was written five years ago is unlikely to reflect current threats such as remote working, cloud storage and ransomware. Scheduling a formal review at least every two years, or sooner after any significant incident, keeps the policy aligned with operational reality.

Training, auditing and continual improvement

A policy that staff have never read provides little protection. The induction programme for new scientists, couriers and clerical staff should include a session on document control, with a short assessment to confirm understanding. Refresher training, at least annually, reminds experienced staff of expectations and introduces changes to the policy. Records of attendance, assessment outcomes and follow-up actions belong in the training file and should themselves be controlled documents.

Internal audits are the next safeguard. Once or twice a year, an auditor independent of the document owner should sample controlled documents, check that the current version is in use, verify that superseded copies have been withdrawn and confirm that access permissions match the role matrix. Findings are fed into the laboratory's corrective action system, and trends are reviewed by management to identify recurring weaknesses.

Continual improvement closes the loop. When the policy is revised after an audit, after a near-miss or after a regulatory change, the new version is communicated, training is updated and the cycle begins again. This is the practical expression of the quality management system at work, and it is what allows a TB laboratory in Hobart, Perth or any other setting to demonstrate that information is protected, current and accessible to the right people at the right time.

If your laboratory is starting from scratch or refining an existing policy, the GLI Quality Tool offers phase-specific checklists, downloadable templates and worked examples that translate these principles into concrete steps. Begin with the foundational activities in phase one, then build outwards as your quality management system matures, and remember that a living policy, revisited and revised with input from the bench scientists who use it every day, will serve your laboratory far better than any document left to gather dust on a shelf.