Supporting Sanofi to ace agile on Atlassian Cloud, GxP included
Written by Rina Nir
Overcoming this twofold challenge of driving agility while ensuring compliance is why Sanofi came to Radbee for help – it’s something we have a lot of experience in. Now, while pharma companies are unsure about the best approach to digital transformation, Sanofi aims to lead the industry when it comes to moving to the cloud and introducing improved ways of working.
We spoke to Kevin Paugam, Product Owner Jira and Confluence, and Christophe Galibert, Scrum Master, at Sanofi to find out about their specific pain points and how Radbee’s expertise helped streamline their system, solve these complex challenges, and ensure they keep leading the pack.
“We know that Radbee is focused on providing solutions to manage compliance in Jira and Confluence, and this was the knowledge and experience we needed. The relationship was very professional and very fruitful.”
Kevin Paugam
Product Owner Jira and Confluence, Sanofi
Success story in brief
Challenges
- Optimizing an Atlassian Cloud instance to streamline GxP systems development and validation efforts.
- Problems creating specifications tables in Confluence, including traceability reports, for example:
- The table layout was broken when specifications included image files.
- Hierarchical relations were not captured.
- Restrictions on deletion of unwanted or unnecessary attachments on Confluence pages. As a result, pages were becoming cluttered and messy.
Solutions
- Technical adjustments to how compliance documents are authored and exported from Confluence to improve data fidelity and their overall appearance.
- The introduction of our Snapshots App to streamline traceability report management, including improving layout, accuracy, and speed.
- Developed a custom Forge application to secure the retention of compliance record PDFs.
Results
- A fully integrated cloud experience across Jira and Confluence with no need for extra tools or Excel files.
- Thanks to Snapshots, significant time and effort saved creating release documents and GxP records.
- Data quality was also improved thanks to Snapshots – it helps Sanofi identify missing and incorrect connections early on.
- A secure archive for long-term retention of all compliance records ensures no important information is lost.
- With compliance records independent of Confluence pages, the team has more flexibility and autonomy.
Looking to the future with Atlassian Cloud
Sanofi had been using Atlassian tools, Jira and Confluence, for nearly a decade, particularly for project management and development. In 2020, the organization decided to validate Jira and Confluence so they could be used for the delivery and testing of GxP systems.
“We were looking for a solution to manage the life cycle of our computer systems from an end-to-end perspective – from defining requirements to solution testing,” said Kevin. In the past, Sanofi had used legacy ALM (Application Lifecycle Management) tools together with an EDMS (Electronic Document Management System) for documentation and approvals management. This hybrid approach meant not everything was integrated.
The team wanted a single source of truth for all these activities. So rather than update GxP systems once or twice a year, they could ship changes much more regularly, helping them respond to feedback and deliver enhancements to their users more quickly. Jira and Confluence were the standout candidates for the job, but the decision of whether to use Atlassian Cloud or Data Center was a more complex one.
“We carried out some research to evaluate the pros and cons of each version of Jira and Confluence,” said Kevin. “One of the main reasons we went with Cloud was that Atlassian’s long-term strategy is the development of its Cloud products, and we wanted to benefit from all the new functionalities.”
What is GxP?
GxP stands for ‘good X practices’ where X can refer to manufacturing, distribution, supply chain, and so on – it applies to everything, not just your IT system. GxP regulations impact the management of digital products in a pharmaceutical context. They entail controls, careful risk management, and documentation in the development, configuration, and usage of systems within pharmaceuticals.
Optimizing Jira and Confluence to streamline GxP system development
The Sanofi team wanted to make the most of its Jira and Confluence instances to support GxP system development. While they could at times rely on existing functionality, built-in automations, or a plugin already available in their existing environment, some functionality required an alternative solution, such as new marketplace apps or customisations using Atlassian’s Forge application.
Radbee CEO Rina Nir had worked with different teams at Sanofi for several years, with a great reputation for her GxP and Atlassian expertise.
On choosing to work with her, Kevin said: “We know that Radbee is focused on providing solutions to manage compliance in Jira and Confluence, and this was the knowledge and experience we needed. The relationship was very professional and very fruitful.
“Obviously, some of the recommendations were relying on Radbee products, because those products were answering some of our concerns, but Rina also suggested other products.” The team was pleased with the non-Radbee Atlassian Marketplace plugins she proposed and the variety of solutions. “At the end of the discovery phase, we had a clear picture of our concerns and how we could potentially fix them with different alternatives. These included some quick wins as well as some longer-term alternatives that we could decide to implement later on.”
Setting up Confluence for release documentation success
Despite a successful migration to Atlassian Cloud, Sanofi faced a number of issues generating the release documentation it needed out of the platform.
First, there were problems managing pictures or attachments coming from Jira when inserting tables from Jira into a Confluence page using Confluence’s built-in Jira macros.
“It’s a very specific point,” explained Kevin, “but because we consider some of these Confluence pages as official records, in our validation activities, we have to retrieve data from Jira into the Confluence page itself.” With Atlassian’s Jira Legacy Macro, they were able to retrieve content from Jira issues into Confluence pages as tables. But there was an issue with the pictures included in the Jira issues. “They weren’t showing correctly, or they were not showing at all, or they were breaking the size of the pages,” said Kevin.
Second, Atlassian’s Jira Macro cannot bring a list with hierarchy into Jira, so it could not help Sanofi create traceability reports in Confluence. Snapshots of Jira Data into Confluence, a RadBee app, solved these issues out of the box. It is now one of the cornerstones of the Sanofi Atlassian universe.
Storage of official records inside Confluence
The third big issue involved the need to retain PDF versions of official pages – the evidence required for compliance. Each time that a page version was approved, an automatic process would generate a PDF of the page and attach it to the page. To avoid these specific attachments being lost, users were not granted the permission to delete any attachment.
“But because the PDF of the approved Confluence page was also an attachment of the page,” said Kevin, “when users added attachments that they wanted to remove afterwards or copied pages that already contained attachments, they couldn’t clear them up.” This created a lot of clutter that users couldn’t do anything about.
To solve this, Sanofi tasked RadBee to develop a custom Forge app, which was named Official PDF Export Repository. This has been in place since August 2024.
“It’s a dedicated tool we can consider as a vault for validated records,” said Christophe Galibert. “It means we’ve been able to remove some constraints we had around deleting attachments. Now teams are able to use the core Confluence system as they should, and they don’t have to deal with all these restrictions. Now we have a really clear organization of regulated spaces.”
Weighing up custom development using Atlassian Forge
Christophe explained Sanofi’s thinking around custom development on Atlassian: “If a requirement is not covered either by native Jira/Confluence functionalities or by existing plugins, we will assess if a marketplace plugin can cover the need or if a custom development is required (e.g. a forge app).
“For any of these options, we need to estimate the cost to implement it versus the expected benefits,” said Christophe. “But the difficulty resides in the evaluation of the expected benefits. In our context, benefits are not only measured in terms of money or time saved but also in terms of product quality, security, and compliance.”
However, the development team had no experience using Atlassian Connect – a development framework for extending Atlassian Cloud products – and just a few months’ experience using Forge. They recognized that Forge could meet the needs of implementing very specific features not covered by standard or marketplace apps, but, as Christophe explained, “this requires a good level of expertise in the framework from developers for design choices ensuring performance, stability, and security.
“Outsourcing custom development to Radbee was a success. And even before the project, there was an important contribution of Radbee in the definition of the requirements.”
Christophe mentioned specifically the continuous support we provided during and after the project. He added: “Custom developments were delivered on time, including additional functionalities not in the initial scope, with appropriate documentation and quality level. And last but not least, there was a very good transition of code base and deployment pipelines so that we have the means to maintain the developments ourselves after the initial delivery.”
“It’s a dedicated tool we can consider as a vault for validated records,” said Christophe Galibert. “It means we’ve been able to remove some constraints we had around deleting attachments. Now teams are able to use the core Confluence system as they should, and they don’t have to deal with all these restrictions. Now we have a really clear organization of regulated spaces.”
Weighing up custom development using Atlassian Forge
Christophe explained Sanofi’s thinking around custom development on Atlassian: “If a requirement is not covered either by native Jira/Confluence functionalities or by existing plugins, we will assess if a marketplace plugin can cover the need or if a custom development is required (e.g. a forge app).
“For any of these options, we need to estimate the cost to implement it versus the expected benefits,” said Christophe. “But the difficulty resides in the evaluation of the expected benefits. In our context, benefits are not only measured in terms of money or time saved but also in terms of product quality, security, and compliance.”
However, the development team had no experience using Atlassian Connect – a development framework for extending Atlassian Cloud products – and just a few months’ experience using Forge. They recognized that Forge could meet the needs of implementing very specific features not covered by standard or marketplace apps, but, as Christophe explained, “this requires a good level of expertise in the framework from developers for design choices ensuring performance, stability, and security.
“Outsourcing custom development to Radbee was a success. And even before the project, there was an important contribution of Radbee in the definition of the requirements.”
Christophe mentioned specifically the continuous support we provided during and after the project. He added: “Custom developments were delivered on time, including additional functionalities not in the initial scope, with appropriate documentation and quality level. And last but not least, there was a very good transition of code base and deployment pipelines so that we have the means to maintain the developments ourselves after the initial delivery.”
Christophe Galibert
Scrum Master, Sanofi
Results
A fully integrated cloud experience
Even with a few expected challenges, the move to Atlassian Cloud has been overwhelmingly positive, with Sanofi reaping the rewards of Atlassian’s efforts, including AI capabilities. “I’ve had a number of discussions with people at other pharmaceutical companies, and most of them are willing to move to Atlassian Cloud now,” said Kevin. “But they want reassurance that they will be able to manage their systems with the same level of compliance and security. “I tell them that Atlassian is putting a lot of effort into that.”
With everything integrated, Sanofi’s digital organization teams are now working almost exclusively with Jira and Confluence with no need for them to use extra tools or Excel files. Time saving is a key benefit, especially when it comes to generating validation evidence and GxP records.
“We hope that teams can stay agile while managing the validation of GxP products,” said Kevin. “Because really, since the beginning, our motto was ‘to manage activities in an agile way and stay compliant at the same time’.”
Snapshots saves time and improves data quality
One part of the process relied on using Radbee’s Snapshots app, which Kevin described as an important saving for all Sanofi teams that have to manage reports in Confluence pages. Using Snapshots was an important step forward in Sanofi’s efforts to integrate all activities in Jira and Confluence.
“Before Snapshots was in place, I used to generate a traceability matrix manually with exports from different places but mainly from Jira. So I exported my issues into an Excel file. It took me three to four hours to compute this table because there were a lot of issues to manage. Today, it takes 30 minutes to generate the same table – all I have to do is change the filters in the macro. Plus, I have all the missing links in the traceability report, so I can repair these links directly in Jira too. It’s not only saving time but it’s also improving the quality of the information in Jira.”
A secure archive for compliance records
Another major step was the implementation of the Official PDF Export Repository. And the feedback from teams has already been positive. “We know that it’s very helpful,” said Kevin. “First, because it gathers all records in the same place, so it’s easier for users to find their official PDF exports. And second, it has allowed users to delete attachments, which was one of the pain points we had identified during the discovery phase.”
Agility and compliance – get the best of both worlds
Meeting GxP regulations is essential for pharmaceutical organizations like Sanofi, but it isn’t always easy. And those challenges can multiply when you factor in digital transformation and the need to become more agile. Helping businesses tackle both with the right practices and tools is exactly what we specialize in.
Find out more about how the Radbee team can take the pain out of GxP while ensuring agile practices stay front and center, setting your system up for success.
Let’s make things easier
Ready to streamline and stay compliant?
Wherever you are on your digital transformation journey, we can help. We know the regulations you need to meet and how to comply without compromising on agility. Get in touch today to find out more.
Success stories
Lifting a Quality System on Jira and Confluence to a New Galaxy – Ada Case Study
Find out how we helped medical tech company Ada transform its quality processes using Jira and Confluence. The project team tells about the power of tailoring their Quality System on Atlassian.
Stepping in to support Saluda Medical’s Jira validation project
Sanofi is one of the world’s top 10 pharmaceutical companies and part of the organization’s strategy is prioritizing agile working practices and embracing an agile…
Paige Case Study: How a Customized QMS Helps a Medical Device Company Keep Their Agile Flow
Paige.ai, a global leader in AI-based pathology diagnostic software, uses Jira and Confluence for their Quality Management System (QMS). RadBee Ltd. has helped this...
Have more questions?
Or reach out to us and we’ll show you how we can make your work easier, faster and help you get more done.