TTMS MY

Home Blog

TTMS Blog

TTMS experts about the IT world, the latest technologies and the solutions we implement.

Sort by topics

Agentic CMS in 2026: How AI Agents Are Changing the Content Supply Chain

Agentic CMS in 2026: How AI Agents Are Changing the Content Supply Chain

Enterprise content teams are under pressure to create, adapt, approve, and deliver more content across more digital touchpoints. Traditional CMS workflows can still support structured publishing, but they often struggle with the speed, coordination, and governance demands of modern content operations. This is where the idea of an agentic CMS enters the conversation. In the AEM ecosystem, it points to a shift toward AI-assisted content workflows, where agents can help teams discover, optimize, adapt, and orchestrate content more efficiently while keeping human oversight in place. 1. What Is an Agentic CMS, and Why It Matters Now An agentic CMS is best understood as a content management concept rather than a fixed product category. It describes a CMS environment where AI agents help teams complete content-related tasks such as discovery, optimization, adaptation, tagging, workflow support, and delivery preparation. In the AEM ecosystem, this idea is most closely connected to Agents in AEM, which Adobe describes as capabilities that can automate tasks, streamline workflows, and help orchestrate changes in AEM as a Cloud Service and Edge Delivery Services. The key shift is not that humans disappear from the process. Instead, agentic workflows are designed to reduce repetitive manual work while keeping people in control of strategy, creative judgment, governance, and final approval. This makes the concept especially relevant for enterprise content teams that need to manage more digital content without weakening brand, compliance, or workflow standards. 1.1 The Evolution: From Headless CMS to Agent-Assisted Content Workflows Headless CMS platforms helped separate content structure from presentation, making it easier to reuse content across websites, applications, and other digital experiences. However, headless architecture still relies on people to decide what content to create, how to adapt it, when to publish it, and how to coordinate work across teams. Agent-assisted content workflows build on that foundation. Instead of only storing and delivering structured content, AI agents can help with tasks such as finding relevant assets, preparing channel-ready content variations, supporting content updates, and assisting with workflow execution. Structured content, metadata, permissions, and governance rules remain essential because they provide the framework within which agents can operate safely and usefully. 1.2 Integrated Agent Workflows vs. Isolated AI Features There is an important difference between isolated AI features and integrated agent workflows. A standalone writing assistant or translation tool can help with a single task, but it may not understand the broader content model, workflow, permissions, brand rules, or delivery context. 2. The Risks of Fragmented AI Tools in Content Operations Adding a standalone AI writing assistant, translation plugin, or LLM wrapper to an existing CMS can help with individual tasks, but it does not automatically create an agentic content workflow. The challenge appears when each tool works in isolation, with separate permissions, context, prompts, review processes, and monitoring. In that setup, teams may still need to manually move content between systems, check whether generated outputs follow brand rules, and make sure the right people review the right materials before publication. Instead of reducing operational complexity, disconnected AI tools can add another layer of coordination for content, marketing, legal, and technical teams. 2.1 Security and Governance Risks of Fragmented AI Tools When AI tools operate without a shared governance framework, organizations can lose visibility into how content is generated, adapted, reviewed, and approved. This can make it harder to maintain consistent permissions, content standards, audit trails, and human review across the content supply chain. This is why governance matters in agentic content operations: AI-assisted work needs shared permissions, review steps, content standards, and auditability across the content supply chain. 2.2 The Integration Trap: Why Disconnected Agents Break Workflows Disconnected agents can create workflow friction when they do not share the same content context. For example, a writing assistant may generate copy, a localization tool may adapt it, and an approval workflow may review it, but if these systems do not exchange context, people still need to coordinate the handoffs manually. 3. How Agents in AEM Support the Content Supply Chain AI agents can support content operations by helping teams reduce repetitive manual work across discovery, optimization, adaptation, and workflow execution. In the AEM ecosystem, this direction is reflected in Agents in AEM, which Adobe describes as capabilities designed to automate tasks, streamline workflows, and help orchestrate changes in AEM as a Cloud Service and Edge Delivery Services. The value is not full autonomy. The value is better coordination between people, content, assets, workflows, and delivery systems. Agents can help with specific tasks, while humans remain responsible for strategy, creative judgment, governance, and final approval. 3.1 Supporting the Content Supply Chain with Agent-Assisted Workflows An agentic content supply chain is not only about generating text. It is about using AI agents to support different stages of content operations, such as finding relevant assets, refining content, creating channel-ready variations, preparing assets for specific digital channels, and helping teams execute repeatable workflow steps. In AEM, the Content Advisor Agent is especially relevant here. Adobe describes it as helping users discover, refine, and adapt assets through natural language instructions. It can support discovery across Assets, Content Fragments, and Adaptive Forms, and it can help prepare channel-ready variations by generating renditions, adjusting visual properties, changing backgrounds, or preparing assets for specific digital channels. 3.2 Content Adaptation and Channel-Ready Variations Instead of describing agentic CMS as fully automated personalization, it is safer to think about content adaptation. AI agents can help teams prepare content or assets for different channels, formats, and use cases, especially when the content foundation is already structured, governed, and supported by clear metadata. This is where agentic workflows can reduce repetitive content work without removing human control. Teams can use AI-assisted capabilities to accelerate preparation and adaptation, while reviewers still validate quality, brand alignment, and business context before content is published or activated. 3.3 Human-in-the-Loop Workflows and Oversight Agent-assisted workflows still need human oversight. Adobe’s agentic content supply chain framing emphasizes human-led, agent-accelerated systems, where agents support execution but people remain responsible for review, approvals, and governance. In practice, this means AI agents can help with repetitive drafting, formatting, asset preparation, or routing tasks, while designated reviewers confirm whether the output is accurate, on brand, and ready for use. This balance helps teams reduce manual coordination while keeping decision-making and accountability clear. 4. Key Capabilities Behind Agentic CMS Workflows in AEM Evaluating agentic CMS concepts requires looking beyond isolated AI features. The most important question is how well AI agents can work with content, assets, governance rules, permissions, and delivery workflows inside the broader content platform. 4.1 AI-Assisted Content Creation and Adaptation Agentic CMS workflows should support more than one-off text generation. They should help users discover, refine, and adapt content or assets for specific needs while keeping people responsible for quality, context, and final decisions. 4.2 Governance, Guardrails, and Human Review Agentic workflows need clear governance. AI agents should operate within defined permissions, metadata standards, brand guidelines, and review processes. This helps teams keep AI-assisted content work connected to the same governance model used for human-created content. Strong guardrails can support consistency in tone, visual identity, asset usage, and workflow routing, but they should not remove human accountability. In enterprise environments, reviewers still need to validate accuracy, brand fit, legal context, and publishing readiness before content is activated. 4.3 Connected Architecture and Fast Delivery Agentic CMS workflows work best when agents can operate within a connected content environment instead of sitting beside the CMS as isolated tools. This means they should be able to work with structured content, digital assets, workflows, permissions, and delivery systems in a coordinated way. In AEM, this direction is reflected in Agents in AEM, AEM as a Cloud Service, and Edge Delivery Services. Together, these capabilities support a model where agents can assist with content operations while the platform continues to provide the structure, governance, and delivery foundation enterprise teams need. 5. How Adobe Experience Manager Supports Agentic Content Workflows In the Adobe ecosystem, Agentic CMS is best understood through the capabilities Adobe is building into AEM, including Agents in AEM, AEM as a Cloud Service, Edge Delivery Services, and AI-assisted workflows for content discovery, optimization, modernization, and delivery. 5.1 Agents in AEM and AI-Assisted Content Operations The most relevant AEM capabilities for agentic content workflows are Agents in AEM. Adobe describes these agents as capabilities available in AEM as a Cloud Service and Edge Delivery Services that can accelerate content creation and help orchestrate changes. Alongside the Content Advisor Agent discussed earlier, Adobe also describes the Brand Experience Agent, which includes specialized agents for modernization, production, and development tasks. Together, these capabilities point toward agent-assisted content operations where AI supports execution while people guide strategy, quality, and approval. 5.2 Edge Delivery Services and Faster Content Delivery Edge Delivery Services play a delivery role in the broader AEM environment where agentic workflows are becoming available. They support modern, high-performance content delivery patterns, while workflow orchestration depends on the specific agents, governance model, content structure, and review processes used in AEM. 6. How TTMS Can Help You Move Toward Agentic CMS Workflows Moving toward agentic CMS workflows does not have to mean replacing your current content setup all at once. In the AEM ecosystem, a safer approach is to start with clear, well-governed use cases where AI agents can support repetitive content tasks while people remain responsible for strategy, quality, and approval. This is where we can help. We support organizations in assessing where Agents in AEM, AEM as a Cloud Service, Edge Delivery Services, structured content, metadata, and governance can work together to improve content operations. Adobe describes Agents in AEM as capabilities that can automate tasks, streamline workflows, and help orchestrate changes in AEM environments. If your team is exploring Agentic CMS in the context of AEM, we can help you define the right starting point, prepare the governance model, and build a practical roadmap for human-led, agent-assisted content workflows. Contact us now. 7. Frequently Asked Questions About Agentic CMS What’s the difference between an agentic CMS and a traditional headless CMS? A headless CMS separates content from presentation, while an agentic CMS concept adds AI agents that can support content tasks such as discovery, optimization, adaptation, and workflow execution. In the AEM ecosystem, this idea is reflected in Agents in AEM, which Adobe describes as capabilities that help automate tasks and streamline workflows in AEM as a Cloud Service and Edge Delivery Services. Is agentic CMS the same as agentic AI? No. Agentic AI is a broader concept referring to AI agents that can help plan and execute tasks. Agentic CMS applies that idea specifically to content operations, where agents support content workflows, assets, governance, and delivery processes. How does an agentic CMS improve content governance? Agentic CMS workflows can support governance by keeping AI-assisted tasks connected to permissions, metadata, review steps, and approval processes. Adobe’s agentic content supply chain framing emphasizes human-led, agent-accelerated workflows, so people remain responsible for oversight and final decisions. Can smaller organizations benefit from agentic CMS, or is it only for large enterprises? Yes, but the value depends on content complexity, governance needs, and workflow maturity. Smaller teams can start with focused use cases, such as asset discovery, content updates, or channel-ready variations, before expanding agent-assisted workflows more broadly. How does AEM support agentic content workflows? AEM supports this direction through Agents in AEM, AEM as a Cloud Service, Edge Delivery Services, and AI-assisted workflows for content discovery, optimization, modernization, and delivery. Adobe describes agents such as the Content Advisor Agent and Brand Experience Agent as capabilities that help users discover, refine, adapt, and update content while keeping human oversight in place.

Read
15 ChatGPT Integrations with Business Apps in 2026

15 ChatGPT Integrations with Business Apps in 2026

How can ChatGPT integrations with business applications simplify everyday work in 2026? Here is a simple example: a client emails us asking for a project status update. At this point, we face half an hour of clicking between Google Drive, Slack, Asana and the CRM system. What if ChatGPT could collect information from all these sources in a single conversation and immediately prepare a summary, response or plan for the next steps? In this article: we examine 15 ChatGPT integrations with popular business applications that can make the scenario described above part of a company’s everyday workflow, we explain the differences between apps, integrations, plugins, GPTs and MCP servers, we present specific business use cases and highlight what should be checked before implementation, including permission scopes, data security, availability and costs. How do business application integrations extend ChatGPT’s capabilities? In the client enquiry scenario described above, the right set of integrations could work as follows: ChatGPT would find documents in Google Drive, summarise conversations in Slack, check task statuses in Asana and analyse the client’s data in the CRM system. Individual integrations may be available in ChatGPT as apps, connectors or MCP-based solutions. They make it possible to use data and selected functions from external services without leaving the conversation, and then prepare an up-to-date summary, a response for the client or a plan for the next steps. The available capabilities depend on the specific solution. Some integrations are more “passive” and are used mainly for searching and reading data. More “active” integrations support creating, updating and sending data. GPTs, apps, connectors, plugins and MCP – how do these concepts differ? The terminology surrounding ChatGPT extensions includes several related concepts. In our previous article, we described the ecosystem of the most useful ChatGPT plugins. In this comparison, we use the term “ChatGPT integrations” as an umbrella term for the different ways of connecting ChatGPT to business applications, their data and their functions. Concept Proposed definition ChatGPT integration An umbrella term for connecting ChatGPT to an external application, its data or its functions. An integration may be implemented as an app, connector, plugin, MCP server or GPT Action. App A function of an external service available directly in ChatGPT, sometimes with an interactive interface. Connector A ready-made connection that gives ChatGPT access to the data or functions of a specific service. Depending on the solution, it may support search, synchronisation or actions. MCP server A layer that gives ChatGPT access to selected tools, data and operations from an external system in accordance with the Model Context Protocol standard. Plugin An installable package that extends ChatGPT or Codex and may include instructions, skills, an MCP connection and an optional interface. These concepts describe different elements of the same ecosystem and are not always completely separate. Integration is the umbrella term for connecting ChatGPT to an external service. It may be available as an app, use a connector or MCP server, while a plugin may combine several of these elements into a ready-made workflow. How do you connect an app to ChatGPT step by step? Define the task the integration should perform. Open the app or plugin directory in ChatGPT. Select the appropriate service and start the connection process. Sign in to the external application and approve the required permissions. Open a new conversation and select the connected app. Test the integration using a limited dataset before deploying it across the entire team. How did we select 15 ChatGPT integrations with business applications? This comparison covers integrations that support recurring business processes and are available directly in ChatGPT or through documented MCP-based solutions. We considered five criteria: Frequency of use: the tool stores data or supports tasks performed by teams every day. Value of context: the connection gives ChatGPT access to information that significantly improves the quality of its output. Scope of actions: the integration supports searching, analysing, creating or updating data. Access control: the provider describes authentication, user permissions or administrative controls. Usefulness across multiple roles: the solution can support sales, marketing, operations, IT, product development or knowledge management. The availability of individual features depends on the ChatGPT plan, the external service plan, the country, workspace settings and administrator decisions. The catalogue and permission scopes should be checked immediately before implementation. 15 ChatGPT integrations with business applications in 2026 1. Google Drive integration with ChatGPT – searching and analysing company documents The Google Drive integration with ChatGPT enables users to work with materials stored in Drive, Docs, Sheets and Slides. Users can search for files, combine information from several documents, analyse spreadsheets and use existing materials as sources for a new report, brief or presentation. It provides the greatest value to teams with well-organised folders and consistent document naming conventions. ChatGPT can then locate the correct versions of proposals, reports, meeting notes and project materials more quickly. Best use case: preparing a project summary based on documents, a results spreadsheet and a status presentation. Example prompt: “Find materials in Google Drive related to Project X from the last 30 days and prepare a summary of decisions, risks and next steps.” The video shows how to connect Google Drive to ChatGPT, create an SEO-optimised blog post and save it as a document in Google Drive. It also highlights the importance of detailed prompts for improving the quality of generated content. 2. SharePoint integration with ChatGPT – access to organisational knowledge, procedures and files SharePoint is a natural source of information for organisations using Microsoft 365. It stores documents, intranet pages, procedures, policies and project materials. The SharePoint integration with ChatGPT enables users to find these resources and use them when preparing responses or documents. It is particularly useful in larger organisations where knowledge is distributed across sites, document libraries and teams. The SharePoint permission structure continues to determine which information is available to each employee. Best use case: finding current policies, instructions, templates and project documentation. Example prompt: “Based on the current procedures in SharePoint, prepare an onboarding checklist for a new supplier.” 3. Box integration with ChatGPT – secure analysis of company documents Box combines content management with access controls and is often used by organisations working with confidential documents. The Box integration with ChatGPT can retrieve data on demand or synchronise selected content. On-demand access retrieves the required information while a prompt is being processed, while synchronisation indexes approved resources in advance and speeds up searches across large repositories. The choice of access mode should take into account data classification, retention requirements and the expected response time. Best use case: analysing contracts, project materials, client documentation and approved company resources. Example prompt: “Find the current versions of documents for Client X in Box and identify discrepancies in the project scope.” 4. Gmail integration with ChatGPT – summarising correspondence and preparing replies The Gmail integration with ChatGPT enables users to search for messages, summarise long threads and prepare draft replies based on their email history. Gmail in ChatGPT is useful in sales, customer service, recruitment and day-to-day coordination when important decisions are distributed across multiple messages. To help the Gmail connector return an accurate result, specify the relevant period, senders, subject and expected outcome. ChatGPT can then find the appropriate messages and turn them into a summary, list of decisions or ready-to-use draft reply. Best use case: summarising an email thread, preparing a follow-up and identifying the commitments made by each party. Example prompt: “Summarise the correspondence with Company X from the last two weeks. List the agreed actions, deadlines and questions that still require a response.” The video shows how to connect Gmail to ChatGPT step by step using the official app. Once the Gmail integration with ChatGPT has been configured, users can search for messages, summarise long threads, find important information and prepare draft replies directly within the conversation. 5. Outlook Email integration with ChatGPT – analysing messages in Microsoft 365 The Outlook Email integration with ChatGPT enables users to find messages, analyse long email threads and prepare replies that take the conversation history into account. Outlook in ChatGPT is particularly useful for organisations using Microsoft 365. If ChatGPT is also connected to SharePoint and Microsoft Teams, it can combine email discussions with documents and team conversations. The Outlook Email integration operates only within sources approved by the organisation and available to the individual user. Best use case: preparing a client response based on email history and current project materials. Example prompt: “Find the latest email thread about renewing the contract with Company X and prepare a draft reply that addresses the outstanding issues.” 6. Slack integration with ChatGPT – summarising team conversations, decisions and actions The Slack integration with ChatGPT gives the model access to context from messages, files, channels and team member profiles. Slack in ChatGPT helps reconstruct the history of decisions, prepare project status updates and identify recurring problems in team conversations. The Slack MCP server also supports selected actions, such as sending messages and creating or viewing Canvas documents. The Slack integration with ChatGPT only uses channels available to the authenticated user and operates according to the rules configured by the administrator. Best use case: preparing a weekly status update covering decisions, blockers, owners and open questions. Example prompt: “Review the project channel from Monday onwards and prepare a status update covering completed actions, risks, decisions and tasks for the coming week.” 7. Microsoft Teams integration with ChatGPT – analysing conversations, meetings and tasks The Microsoft Teams integration with ChatGPT enables users to search and analyse messages from individual chats, group conversations and channels available to them. Microsoft Teams in ChatGPT can also work with Microsoft Planner plans and tasks. When the relevant actions are enabled, it can create chats and channels, as well as send messages and replies. On the Enterprise plan, the integration can also retrieve transcripts from scheduled meetings if the user has the appropriate permissions. Files shared in Teams channels are usually stored in SharePoint, so analysing them requires an additional connection between ChatGPT and SharePoint. Best use case: finding decisions in team conversations and turning them into summaries, tasks and status materials. Example prompt: “Review the conversations in the project channel from the last five days and prepare a list of decisions, open questions, responsible individuals and deadlines.” 8. Notion integration with ChatGPT – creating and updating company knowledge The Notion integration with ChatGPT enables users to read, create and update content on Notion pages directly from a conversation. Notion in ChatGPT can support product documentation, campaign plans, knowledge bases, feature specifications and implementation checklists. The Notion MCP server operates within the permissions of the signed-in user. A person with broad access to the workspace gives the integration an equally broad scope of data and operations, so it is worth beginning the implementation with clearly limited use cases and accounts with appropriately assigned roles. Best use case: transforming notes and analysis results into structured pages, databases and action plans. Example prompt: “Create a feature specification in Notion based on these notes. Add objectives, requirements, acceptance criteria, risks and open questions.” The video shows how to connect Notion to ChatGPT and work with content stored in a workspace. The Notion integration with ChatGPT enables users to search for information and create or update pages directly from a conversation. 9. Atlassian Rovo integration with ChatGPT – working with Jira, Confluence and Bitbucket The Atlassian Rovo integration with ChatGPT connects the model to Jira, Jira Service Management, Confluence and Bitbucket. Jira and Confluence content can be searched and summarised in ChatGPT, while users can also create and update tasks, tickets and pages using natural language commands. The Atlassian Rovo MCP server supports software development, ticket management, change management and documentation processes. OAuth 2.1 authentication preserves existing user roles and permissions, while actions affecting data should be subject to approval and monitoring. Best use case: creating tickets from meeting notes, updating statuses and connecting Confluence documentation with Jira tasks. Example prompt: “Based on this specification, create five Jira tasks with descriptions, acceptance criteria and priorities. Show me the proposed tasks before saving them.” 10. Asana integration with ChatGPT – creating tasks and managing projects The Asana integration with ChatGPT provides information about projects and portfolios, and allows users to create and assign tasks, set up new projects and monitor progress. Asana in ChatGPT can turn decisions made during a conversation into a structured plan saved directly in the work management system. The Asana integration with ChatGPT is useful for planning campaigns, implementations, product launches and cross-departmental initiatives. The integration produces the most accurate results when projects, owners and custom fields have clear and consistent names. Best use case: creating a project plan and turning decisions into assigned tasks. Example prompt: “Create a plan in Asana for launching a new product page. Divide the work into stages, tasks, dependencies and responsible team members. Show me the proposed structure for approval before saving it.” 11. HubSpot integration with ChatGPT – CRM analysis and record updates The HubSpot integration with ChatGPT provides information about contacts, companies, sales opportunities, tickets and customer interaction history. HubSpot in ChatGPT can analyse the sales funnel, campaign results and customer activity, as well as create and update selected records and log activities. The HubSpot integration with ChatGPT is one of the most extensive solutions available to sales and marketing teams. The quality of its results depends on the completeness of CRM data, consistently defined funnel stages and correctly assigned permissions. Best use case: preparing an account brief, analysing the pipeline, updating an opportunity and creating a follow-up. Example prompt: “Analyse the sales opportunities in HubSpot that have had no activity for 14 days. Identify the priorities and prepare a plan for the next contact.” 12. Salesforce Agentforce Sales integration with ChatGPT – opportunity analysis and CRM management The Salesforce Agentforce Sales integration with ChatGPT combines information about customers, sales opportunities and the pipeline with analysis and planning capabilities. Salesforce in ChatGPT allows sales representatives to prioritise opportunities, prepare account plans, update records and run Agentforce actions directly from a conversation. The Agentforce Sales app for ChatGPT is currently available through the Open Beta programme to eligible customers using the required Agentforce add-ons. Before implementation, organisations should verify their Salesforce edition, access requirements and regional availability. Best use case: preparing a sales representative for a meeting, prioritising opportunities and updating the CRM after a client conversation. Example prompt: “Show me five Salesforce opportunities that require attention this week. Include their value, stage, most recent activity, risk and recommended next step.” 13. GitHub integration with ChatGPT – analysing code, issues and project changes The GitHub integration with ChatGPT gives the model access to context from repositories, code, issues, proposed changes and automated test results. GitHub in ChatGPT can help analyse code changes, organise issues, prepare documentation and identify dependencies between project components. Administrators can specify which repositories the GitHub integration with ChatGPT can access and which operations it can perform. This makes it possible to test the integration on a small number of selected projects before gradually making it available to additional teams. Best use case: analysing proposed code changes, organising issues, reviewing automated test results and preparing change documentation. Example prompt: “Review the open pull requests in the mobile application repository. Identify risks, missing tests and issues blocking the release.” The video shows how to connect GitHub to ChatGPT and give the integration access to selected repositories. The GitHub integration with ChatGPT enables users to explore project structures, analyse code and documentation, and summarise changes, commits and pull requests directly within a conversation. 14. Canva integration with ChatGPT – creating and editing visual content The Canva integration with ChatGPT enables users to search and summarise existing materials, as well as create, edit and display designs directly within a conversation. Canva in ChatGPT is useful for preparing presentations, social media posts, documents and other visual materials. Designs created through the Canva app for ChatGPT remain editable in Canva, allowing the team to continue refining their content and appearance. The best results can be achieved by specifying the intended audience, objective, format, source materials and brand requirements. Best use case: presentations, social media content, sales documents and visual summaries. Example prompt: “Create a presentation in Canva for the management team based on this report. Use eight slides, concise conclusions and one chart on the results slide.” 15. Adobe integration with ChatGPT – editing photos, videos, graphics and PDF documents Adobe for ChatGPT is a package that brings together features from Adobe applications, including Photoshop, Premiere, Firefly, Express and Acrobat. It supports photo editing, consistent batch processing, preparation of social media formats, video shortening, work with PDF documents and searches across Creative Cloud assets. The solution supports workflows intended to produce a finished file. For example, a workflow may begin with a set of employee photos, include lighting correction and consistent cropping, and finish with the export of materials ready for publication. Best use case: repeatable photo editing, adapting content for different channels, working with PDF documents and quickly creating designs from templates. Example prompt: “Standardise the lighting and colours in these photos, apply consistent cropping and prepare versions for employee profiles on the company website.” 15 ChatGPT integrations with business applications – comparison table No. ChatGPT integration Area Best use case Primary type of work 1 Google Drive Documents and knowledge Analysing files from Drive, Docs, Sheets and Slides Search, reading and analysis 2 Microsoft SharePoint Organisational knowledge Working with controlled Microsoft 365 resources Search, reading and analysis 3 Box Content management Secure work with company files and folders On-demand access or synchronisation 4 Gmail Email Summarising email conversations and preparing replies Search, analysis and drafting 5 Outlook Email Microsoft 365 email Analysing email in a business environment Search, analysis and drafting 6 Slack Team communication Finding decisions and summarising channels and messages Search, reading and actions 7 Microsoft Teams Collaboration Analysing conversations, meetings and team context Search and summarisation 8 Notion Knowledge and documentation Creating and updating pages, databases and plans Real-time reading and writing 9 Atlassian Rovo Projects and IT Working with Jira, Confluence, Jira Service Management and Bitbucket Search, creation and updates 10 Asana Work management Managing project portfolios and creating tasks Analysis and project actions 11 HubSpot CRM, marketing and sales Analysing customers, the sales funnel and contact history Analysis, record creation and updates 12 Salesforce Agentforce Sales Enterprise sales Prioritising opportunities, planning accounts and updating the CRM Analysis and sales actions 13 GitHub Software development Working with repositories, issues, proposed changes and automated tests Search, analysis and issue organisation 14 Canva Design and communication Creating editable presentations and marketing materials Search, generation and editing 15 Adobe Creative work and documents Photos, videos, social media content, PDF files and Creative Cloud assets Search, generation, editing and export Security of ChatGPT integrations in a business environment Secure integration of ChatGPT with company systems requires appropriate permission management, separation of read and write operations, selection of the right data access method, approval of actions and operation logging. Data processing terms, OAuth scopes, retention and data residency requirements should also be reviewed for every connected service. In ChatGPT Business, Enterprise and Edu plans, data retrieved through integrations is not used to train OpenAI models. When is it worth building a custom ChatGPT integration? Ready-made ChatGPT integrations cover popular business applications and common use cases. A custom integration becomes justified when critical data is stored in an internal system, the process requires specific logic or the organisation needs greater control over its architecture and information flows. The most common reasons include: a private API, legacy system, internal database or on-premises solution; a workflow involving several systems and rules specific to the organisation; requirements concerning data residency, auditability and approval of operations; the need to combine RAG-based search, business logic and actions performed in external systems; a regulated environment requiring risk assessment, documentation and controlled implementation; a scale at which a custom integration simplifies access and cost management. Such a solution may use a dedicated integration, MCP server, GPT Actions, API layer or an architecture combining several approaches. The starting point should be a specific process, a clearly identified data owner and the expected business outcome. ChatGPT integrations as part of a secure enterprise AI ecosystem ChatGPT integrations provide the greatest value when the connection supports a real process, respects user roles and produces an output that is ready to use. For one organisation, this may mean faster knowledge retrieval. For another, it may involve CRM updates, document automation or a controlled process spanning several systems. Transition Technologies MS designs and implements AI solutions for business tailored to an organisation’s data, architecture, security requirements and operating model. The scope of a project may include API and MCP integrations, RAG solutions, action automation and a model for managing access, risk and accountability. Our approach to AI has been confirmed by ISO/IEC 42001 certification for our Artificial Intelligence Management System (AIMS). TTMS was the first company in Poland to obtain accredited certification for compliance with this standard and is among the first organisations in Europe operating within its framework. This means that we deliver AI projects according to structured principles covering security, accountability, documentation and risk management. TTMS also develops proprietary AI products that support specific business processes: AI4Content analyses documents and creates structured reports; AI4Knowledge helps employees use company knowledge more effectively; AI4E-learning transforms source materials into editable online training courses; AI4Localisation supports the translation and adaptation of content for different markets; AI4Legal automates document analysis and selected legal processes; AML Track supports customer verification, risk monitoring and compliance with AML obligations; AI4Hire structures application analysis and supports the initial assessment of candidates; QATANA uses AI to create test cases and manage the software testing process. This expertise allows us to combine integration, product and regulatory experience. We can help organisations establish a single connection to a company data source or design a solution spanning several systems, access controls and end-to-end process automation. FAQ: Frequently asked questions about ChatGPT integrations Can ChatGPT use multiple connected apps in a single task? Yes. Supported ChatGPT environments can use several approved sources within a single task. For example, a workflow could collect project decisions from Slack, retrieve a report from Google Drive and prepare an action plan in Asana. Availability depends on the ChatGPT plan, the interface or mode being used and the workspace configuration. The prompt should clearly identify the required sources, expected result and point at which ChatGPT should request approval. The organisation should also define which types of data may be combined in a single output. Does an integration give ChatGPT access to all of a user’s data? The scope of access depends on the permissions granted to the integration and the user’s role in the source system. Many integrations respect existing permissions for folders, channels, repositories and CRM records. An administrator account may therefore expose significantly more data than an employee account assigned to a specific team. During configuration, review the OAuth scopes, user roles and options for restricting access to selected resources. A pilot should ideally use an account with permissions corresponding to the intended user role. Can ChatGPT send messages and modify data in external applications? Selected apps, integrations and MCP servers support write actions such as sending messages, creating tasks, updating CRM records or adding pages. The available actions vary by provider, subscription plan and integration version. Some tools show the proposed change and request confirmation before completing it. Administrators may also restrict an integration to read-only access or allow only selected operations. Actions affecting customers, financial data, publications or regulated processes should always have clearly defined human approval requirements. Do I need a paid ChatGPT plan to use integrations? Not always. A limited selection of apps may also be available on the free ChatGPT plan, although search and analysis features may have lower usage limits. Broader access, including data synchronisation and custom MCP-based integrations, usually requires a paid plan such as Plus, Pro, Business, Enterprise or Edu. Availability may also depend on the user’s region, administrator settings and subscription to the external service. The current requirements for a specific integration should be checked directly in the ChatGPT app or plugin directory. Can ChatGPT be connected to a company’s internal system? Yes. An organisation can build a custom MCP server, dedicated integration or API connection that gives ChatGPT access to selected data and actions. A private system may remain behind a firewall or operate on-premises if the architecture uses a secure tunnel and controlled authentication. The project should define tool schemas, roles, logging, action approvals, error handling and protection against prompt injection. Before production deployment, the integration should be tested using valid requests, edge cases and tasks that it is expected to refuse. How do you connect an app to ChatGPT? First, define the task the integration should perform and the data required to complete it. Then open the app or plugin directory in ChatGPT, select the appropriate service and start the configuration process. Sign in to the external application, carefully review the requested permissions and approve only the access that is necessary. Once configuration is complete, open a new conversation, select the connected app and test it using a limited dataset. In a business environment, it is best to begin with a pilot for a small group of users before making the integration available to the wider organisation. Can a company administrator restrict access to apps in ChatGPT? Yes. A workspace administrator can decide which apps and plugins are available within the organisation, who may use them and which actions they can perform. For example, the administrator may allow read-only access while blocking message sending or CRM record updates. In managed workspaces, access can also be assigned according to user roles and groups. Integrations continue to respect permissions in the source system, so users should not gain access through ChatGPT to information they cannot view in the connected application. Does ChatGPT store copies of data retrieved from connected systems? It depends on how the integration works. With on-demand access, data is retrieved when a specific request is processed and is not indexed in advance. Integrations that use synchronisation may create an indexed copy of selected content to speed up searches and improve response quality. Disconnecting an app prevents further access, while its synchronised index is scheduled for deletion from OpenAI systems, typically within 30 days. Information previously used in conversations may remain in chat history, so removing it may also require deleting the relevant conversations and saved memories.

Read
Content Hub Enterprise: How to Scale Digital Asset Management with AEM Assets?

Content Hub Enterprise: How to Scale Digital Asset Management with AEM Assets?

Enterprise teams often manage large volumes of digital assets across brands, regions, campaigns, and partner networks. In Adobe’s ecosystem, what many teams call an enterprise content hub is best understood as AEM Assets Content Hub: a part of Experience Manager Assets as a Cloud Service that helps teams find, share, and work with approved brand assets in a governed way. 1. What Is Content Hub at the Enterprise Level? At enterprise level, a content hub is not just a folder structure with search. In Adobe’s ecosystem, AEM Assets Content Hub gives organizations and business partners a governed way to access, share, and work with approved brand assets through an intuitive portal. It is available as part of Experience Manager Assets as a Cloud Service and focuses on distributing assets for activation at scale and supporting the creation of on-brand content variants. This makes Content Hub useful for teams that need broader access to approved assets without giving every user the same level of access to the full DAM. AEM Assets remains the source of truth, while Content Hub helps marketing teams, regional teams, agencies, and partners find approved content, use collections, share assets, and download materials in a more accessible interface. For enterprise organizations, the value is not only faster access to assets. Content Hub also supports governance by exposing approved assets, using configurable metadata and filters, and helping teams work with brand-ready content. When Adobe Express entitlements are available, users can also create or edit on-brand content variants using Adobe Express and Adobe Firefly capabilities. 2. Content Hub in the Adobe Experience Manager (AEM) Ecosystem AEM Assets Content Hub is available as part of Experience Manager Assets as a Cloud Service. In this setup, AEM Assets acts as the central source of truth for approved assets, while Content Hub provides a more accessible portal for teams, agencies, and business partners to find, share, download, and work with approved brand content. This distinction is important for enterprise teams. AEM Assets supports digital asset management capabilities such as asset organization, metadata, governance, permissions, and activation. Content Hub extends access to approved assets through an intuitive interface, configurable search filters, collections, sharing options, and asset download workflows. 2.1 Brand Governance and Rights Management: Maintaining Full Asset Control Governance is one of the main reasons enterprise teams use AEM Assets and Content Hub together. AEM Assets supports metadata, permissions, workflows, versioning, and digital rights management, while Content Hub helps expose approved assets to broader teams in a controlled way. For enterprise use, governance should be planned before rollout. Teams need clear metadata standards, approval workflows, access rules, and asset lifecycle policies. AI-powered tagging and automation can support asset organization and discovery, but taxonomy, permissions, and review processes still need to be configured carefully, especially for content with brand, regional, or rights-related restrictions. 3. Using AI, Adobe Express, and Firefly in AEM Assets Content Hub AEM Assets and Content Hub can support faster asset discovery and content adaptation through AI-assisted capabilities. In AEM Assets, AI-powered tagging and metadata can help teams organize, classify, and find relevant assets more efficiently. This supports better discovery while reducing reliance on fully manual tagging processes. Content Hub can also work with Adobe Express when the organization has the required entitlements. This allows users to edit approved assets and create on-brand content variants using templates, brand elements, and Adobe Firefly capabilities. For enterprise teams, this can make it easier to adapt approved assets for different campaign or channel needs while keeping the work connected to governed content workflows. These capabilities should still be supported by clear governance. Metadata standards, access rules, approval workflows, and brand guidelines need to be configured carefully so that AI-assisted discovery and content variation remain aligned with the organization’s asset strategy. 4. Streamline Your Enterprise Media Workflow with AEM Assets Content Hub AEM Assets Content Hub helps enterprise teams make approved brand assets easier to find, share, download, and adapt through a governed portal. Instead of treating asset management as a static file repository, Content Hub supports broader access to approved assets while keeping that access connected to AEM Assets as the central source of truth. For marketing, regional, sales, and partner teams, this can simplify common asset workflows. Users can search and filter approved assets, work with collections, share selected content, and download the materials they need for campaigns or digital experiences. When the right Adobe Express entitlements are available, teams can also edit assets and create on-brand variants using templates, brand elements, and Adobe Firefly capabilities. The strongest Content Hub rollouts usually start with governance. Before expanding self-service access, teams should define metadata standards, approval workflows, access rules, asset lifecycle policies, and brand guidelines. This helps ensure that broader access to assets supports consistency rather than creating another unmanaged content repository. 5. How TTMS Can Help with Your Content Hub Enterprise Strategy Implementing AEM Assets Content Hub successfully requires more than enabling a new access point for digital assets. The real value comes from designing the right foundation first: clear taxonomy, reliable metadata, approval logic, access rules, and a rollout model that reflects how marketing, regional, sales, and partner teams actually work. This is where we can help. We work with organizations to turn AEM Assets Content Hub into a governed, scalable environment for approved brand content, not just another place to store files. Our role is to help teams connect the technology with the operational model behind it, so self-service access, asset discovery, content adaptation, and governance all support the same business goals. If your organization is planning a Content Hub Enterprise rollout or wants to improve how AEM Assets supports digital asset workflows, we can help you shape the strategy, prepare the governance model, and move toward a more efficient, self-service approach to asset management. 6. Frequently Asked Questions About Content Hub Enterprise How Does an Enterprise Content Hub Differ from Basic File Repositories? A basic file repository mainly stores and organizes files. An enterprise content hub gives teams a governed way to find, share, download, and reuse approved brand assets. In Adobe’s ecosystem, AEM Assets acts as the central source of truth, while AEM Assets Content Hub provides a more accessible portal for approved content. How Does AEM Content Hub Empower Marketing and Sales Teams? AEM Assets Content Hub helps marketing, sales, regional, and partner teams access approved assets without relying on manual file requests. Users can search, filter, use collections, share assets, and download content from a governed portal. With the right Adobe Express entitlements, they can also create or edit on-brand content variants. Do You Need an Official Adobe Partner to Implement AEM Content Hub? An Adobe partner is not always required, but enterprise rollouts often involve configuration, metadata, taxonomy, permissions, approval workflows, and governance planning. Working with an experienced implementation partner can help align Content Hub with a broader AEM Assets and digital asset management strategy.

Read
Top 7 AI QA Tools for Pharma in 2026

Top 7 AI QA Tools for Pharma in 2026

In the pharmaceutical industry, test results become part of quality documentation and must be reproducible during an audit. A complete record includes links to requirements, execution details, change history, approvals and audit evidence. When selecting an AI-powered quality assurance tool for pharma, organisations should therefore consider test automation, traceability, data integrity and compliance with GxP requirements. The ranking opens with QATANA, a platform designed for comprehensive test process management. It combines AI capabilities, manual and automated testing, role-based access, audit logs and on-premise deployment. These features address the key needs of pharmaceutical QA teams by accelerating testing, maintaining control over data and supporting complete test documentation. The ranking covers seven solutions addressing different layers of the quality assurance process. Their capabilities include test management and traceability, end-to-end test execution, digital validation, visual testing and device labs. This comparison will help you select a tool suited to a specific system and validation model. Top 7 AI QA Tools for Pharma – Comparison at a Glance Rank Tool Main category Deployment model Best use case in pharma 1 QATANA AI-assisted test management On-premise Controlled testing lifecycle, auditability, and manual and Playwright tests managed in one environment 2 Tricentis Tosca + qTest + Vera Enterprise automation and digital validation Cloud, on-premise or hybrid, depending on the component Large CSV programmes, formal approvals and complex application environments 3 Opkey Enterprise application automation and continuous validation Cloud or on-premise Veeva, TrackWise, Oracle, SAP, Workday and other frequently updated systems 4 Leapwork No-code test automation and continuous validation Cloud, on-premise or hybrid Regression testing of business processes across web, desktop, Salesforce, SAP and Oracle systems 5 Applitools Visual AI and regulated content control Public cloud, private cloud or on-premise Product websites, portals, applications, eIFUs, PDF documents and mandatory safety communications 6 ACCELQ Full-stack no-code automation Public cloud, private cloud, on-premise or hybrid Omnichannel processes covering web, mobile, API, desktop and enterprise applications 7 TestGrid CoTester Agentic testing and device infrastructure Cloud, private cloud or on-premise device lab Mobile applications, patient portals and testing on real devices and browsers What Makes an AI QA Tool Ready for Pharmaceutical Applications? In a regulated environment, test case generation speed is one of several important selection criteria. The tool should support a controlled process in which requirements, risks, test cases, executions, defects and approvals form a consistent chain. Data integrity, decision traceability and the retention of evidence for the required period are equally important. Compliance with GxP, EU GMP Annex 11 and 21 CFR Part 11 depends on how the system is used, configured and maintained within a specific organisation. The assessment should cover procedures, roles, data, supplier qualification and risk analysis. AI capabilities can support this process, while computerised system validation confirms that the solution is fit for its intended use. We assessed AI-powered QA tools for pharmaceutical applications across six areas: Fit for pharmaceutical environments: capabilities, documentation and use cases in pharma, biotech, healthcare or life sciences. Traceability and audit evidence: links between requirements, tests and results, change history, roles, approvals, reports and data exports. Control over AI: review of AI-generated content, execution predictability, change management and human involvement in decision-making. Security and deployment: on-premises deployment, private cloud, data residency, communication with the AI model and access control. Technology coverage: manual, web, mobile, API, desktop, ERP, CRM and legacy application testing, as well as document and device testing. Operational scalability: integrations with Jira, CI/CD and automation frameworks, reporting, licensing models and the effort required to maintain tests. 1. QATANA QATANA combines AI capabilities with features that are particularly important in regulated QA environments. The platform centralises test cases, executions, defects, reporting, and the results of manual and automated tests. This enables teams to manage the testing process and documentation within a single controlled environment. AI generates draft test cases from tickets and requirements and helps select regression suites based on the scope of a given release. In a pharmaceutical environment, generated proposals should be reviewed by the people responsible for requirements, quality and risk assessment. QATANA supports this operating model because every AI-generated item remains an editable test artefact, while the team retains responsibility for its final assessment and approval. QATANA is particularly well suited to pharmaceutical companies that need a central test management system, want to keep data within their own environment and combine manual testing with Playwright automation. During a proof of concept, organisations should verify specific requirements for electronic signatures, retention, artefact versioning and export formats defined in their applicable SOPs. QATANA: for pharma: key facts Tool provider: Transition Technologies MS (TTMS) Website: ttms.com/ai-software-test-management-tool/ Solution type: AI-assisted test lifecycle management platform Key AI capabilities: Draft test case generation, intelligent regression selection, and analysis of ticket data and release information Best use case in pharma: Controlled test management for GxP and non-GxP applications, patient and HCP portals, internal systems and successive software releases Deployment model: On-premises, with the option to configure integration with the organisation’s selected AI model Integrations: Jira, Playwright, AI models and ticketing systems, as well as test artefact import and export Pricing: Custom pricing with a scalable multi-user licensing model What to verify before selection: Signatures and approvals required by SOPs, retention policies, versioning, evidence package exports and AI model governance rules 2. Tricentis Tosca, qTest and Vera Tricentis combines three complementary solutions: Tosca for test automation, qTest for test management and Vera for digital validation and process approvals. The platform supports more than 160 technologies and enables end-to-end testing of processes spanning ERP and CRM systems, web applications, APIs and data layers. The integration of Tosca, qTest and Vera supports requirements management, electronic signatures, formal approvals and the collection of evidence required for CSV. The solution can operate in the cloud, on-premises or in a hybrid model, with the latest agentic capabilities developed primarily for cloud environments. Tricentis for pharma: key facts Tool provider: Tricentis Website: www.tricentis.com Solution type: Ecosystem for enterprise automation, test management and digital validation Key AI capabilities: Agentic test creation from natural language, Tosca Copilot, portfolio and results analysis, and model-based test automation Best use case in pharma: Large CSV programmes, complex end-to-end processes, formal approvals and organisations using multiple enterprise applications Deployment model: Cloud, on-premises or hybrid, depending on the product and required AI capability Integrations: Tosca, qTest and Vera within one process, as well as popular enterprise applications, CI/CD pipelines, APIs, user interfaces and data layers Pricing: Custom pricing based on the selected products, number of users and execution scale What to verify before selection: Required licence scope, availability of AI capabilities in the selected deployment model, data flows and completeness of the validation package 3. Opkey Opkey automates testing for enterprise applications commonly used in life sciences, including Veeva Vault, TrackWise, Oracle, SAP, Salesforce and ServiceNow. Its AI engine analyses the impact of updates, generates test scenarios and automatically repairs tests following interface changes. The platform supports processes spanning multiple systems and provides pre-built libraries of business processes. For GxP applications, it offers IQ, OQ and PQ protocols, electronic signatures, traceability and automated collection of validation evidence. It is particularly well suited to organisations automating the validation of changes in widely used business applications. Opkey for pharma: key facts Tool provider: Opkey Website: www.opkey.com Solution type: No-code test automation and continuous validation for enterprise applications Key AI capabilities: Change impact analysis, test generation, self-healing, root cause analysis and intelligent regression scope selection Best use case in pharma: Validation of updates to Veeva, TrackWise, Oracle, SAP, Workday and Salesforce, as well as processes spanning multiple applications Deployment model: Cloud or on-premises, adapted to the customer’s infrastructure Integrations: Veeva, TrackWise, Oracle, SAP, Workday, Salesforce, Jira, Azure DevOps, qTest, Jenkins, ServiceNow and GitHub Pricing: Custom pricing; demo and test coverage assessment available What to verify before selection: Alignment of pre-built tests with the system configuration, validation protocol content, control over self-healing and maintenance costs following updates 4. Leapwork Leapwork enables visual, no-code automation for web, desktop, ERP, CRM and legacy applications. Its AI capabilities support test generation from natural language, requirements analysis and self-healing while maintaining deterministic scenario execution. The platform’s suitability for GxP environments is demonstrated by its implementation at NecstGen, where 110 workflows were automated and 270 functions within laboratory and quality systems were covered by a compliant process. Leapwork supports cloud, on-premises and hybrid deployment. When selecting a deployment model, organisations should verify the availability of AI capabilities, data processing location and the method used to approve changes proposed by the model. Leapwork for pharma: key facts Tool provider: Leapwork Website: www.leapwork.com Solution type: No-code test automation and continuous validation platform Key AI capabilities: Natural language test creation, self-healing, knowledge building from requirements and documentation, and coverage generation with traceability to source materials Best use case in pharma: Regression automation for web and desktop systems, Salesforce, SAP, Oracle and applications used by quality and operational teams Deployment model: Cloud, on-premises or hybrid Integrations: Playwright, Selenium, Cucumber, GitHub, CI/CD pipelines, test management systems, SAP, Oracle, Salesforce and Microsoft technologies Pricing: Annual subscription with custom pricing based on architecture and execution scale What to verify before selection: Availability status of AI capabilities, data processing location, human approval mechanisms and the ability to freeze a validated configuration 5. Applitools Applitools uses Visual AI to detect visual defects that conventional functional tests may overlook. It compares websites, application screens and PDF documents against approved baselines, identifying issues such as obscured messages, insufficient contrast and incorrect content placement. In pharma, it helps control risk information, instructions for use, regulatory messages and approved product content across devices, markets and language versions. Version history, screenshots, detected differences and approvals create an evidence set that supports QA and compliance teams. Applitools is particularly effective as a visual validation layer supporting functional testing and CSV processes. Applitools for pharma: key facts Tool provider: Applitools Website: www.applitools.com Solution type: Visual AI, visual, functional and cross-browser testing Key AI capabilities: Deterministic visual comparison, detection of significant changes, difference grouping, visual element-based self-healing and root cause analysis Best use case in pharma: Control of approved content, warnings, eIFUs, PDFs, product portals, patient applications and digital accessibility Deployment model: Public cloud, private cloud or on-premises Integrations: Playwright, Cypress, Selenium, Appium, more than 50 frameworks, Jira and popular CI/CD tools Pricing: Free trial; Starter and Enterprise plans priced individually What to verify before selection: Baseline approval rules, retention of screenshots and detected differences, language version support, audit package exports and the scope of accessibility testing 6. ACCELQ ACCELQ is a no-code platform for testing web, mobile, API and desktop applications, as well as enterprise systems. Its AI capabilities support scenario design, change impact analysis, self-healing and automation maintenance. The platform can test processes spanning multiple systems, such as portals, APIs, Salesforce, SAP and Oracle. SaaS, private cloud, on-premises and hybrid deployment models allow organisations to align the architecture with their data processing policies. ACCELQ for pharma: key facts Tool provider: ACCELQ Website: www.accelq.com Solution type: Unified no-code platform for test management and full-stack automation Key AI capabilities: Scenario generation, process modelling, change impact analysis, self-healing and AI-assisted automation maintenance Best use case in pharma: End-to-end processes spanning web, mobile, API, desktop, backend, Salesforce, SAP, Oracle and other enterprise applications Deployment model: Public cloud, private cloud, on-premises or hybrid Integrations: Jira, Azure DevOps, Jenkins, GitHub, GitLab, TeamCity, Bamboo, Salesforce, SAP, Oracle and Workday Pricing: Annual subscription with custom pricing; a 14-day free trial is available What to verify before selection: Validation documentation package, signatures and approvals, complete AI data flow, and the cost of private cloud or on-premises deployment 7. TestGrid CoTester TestGrid combines the CoTester agent with a cloud of real devices and browsers and a private device lab. AI generates tests from requirements or an application URL, updates them following interface changes and allows users to approve each scenario before execution. The platform supports web, mobile, API, visual and performance testing, as well as existing Selenium, Appium, Cypress and Playwright test suites. In pharma, it can support the testing of patient portals, therapeutic applications and solutions used in clinical trials on real devices. For on-premises deployments, organisations should note that the AI capabilities require a connection to TestGrid’s hosted infrastructure. TestGrid CoTester for pharma: key facts Tool provider: TestGrid Website: www.testgrid.io Solution type: Agentic testing, test management, and cloud or on-premises device lab Key AI capabilities: Test generation from requirements, conversational editing, AgentRx self-healing, error summarisation and results analysis Best use case in pharma: Mobile and web applications, patient portals, field solutions and testing on real devices and browsers Deployment model: Cloud, private cloud or on-premises device lab; AI capabilities may require an outbound connection Integrations: Jira, Jenkins, GitHub Actions, GitLab, Azure DevOps, Selenium, Appium, Cypress and Playwright Pricing: Starter plan from USD 199 per user per month, based on pricing available in August 2026; Growth and on-premises plans are priced individually What to verify before selection: Scope of data sent to the hosted AI service, data residency, log immutability, retention policies and the ability to operate without external connectivity AI-generated image. The people depicted are fictional. Before Implementing an AI QA Tool in Pharma: 9 Questions to Ask the Vendor Before selecting a tool, conduct a proof of concept under conditions that closely reflect the actual testing process. This allows you to assess test creation and execution speed, documentation completeness and the ability to reconstruct the entire process during an audit. Before selecting and implementing an AI QA tool in a pharmaceutical company, ask the vendor the following questions: Does the platform connect requirements, test cases, test executions and reported defects? Which activities and changes are recorded in the audit logs? Can roles and permissions be configured according to the organisation’s procedures? Can AI-generated test cases be reviewed, edited and approved before use? Are manual and automated test results available in one consistent view? How does on-premises deployment work, and how can the platform connect to an AI model selected by the organisation? Does the platform integrate with the organisation’s existing tools, such as Jira, Playwright and CI/CD pipelines? Can test data, reports and other artefacts be imported and exported in the required formats and scope? How do licensing, deployment, integrations, training and ongoing support affect the total cost of the solution? Best AI QA Tool for Pharma: Final Recommendation The final decision should reflect the intended use, risk assessment and a proof of concept conducted on a representative process. The solution provider also plays an important role, as its experience affects implementation quality, change management and the audit readiness of the testing process. TTMS, the provider of QATANA, has worked in the pharmaceutical industry since 2011, involving more than 400 specialists in over 100 projects and services. The company combines QA engineering with expertise in quality management and computerised system validation in line with GAMP 5 and EU GMP Annex 11. These capabilities are supported by the TTMS Integrated Management System, which includes ISO 9001 and ISO 27001. This enables TTMS to support the entire implementation lifecycle, from requirements definition and tool configuration to validation, maintenance and controlled change management. FAQ Is a “21 CFR Part 11 compliant” claim sufficient when selecting an AI QA tool for pharma? No. Such a claim usually describes the available features or the way the product has been designed, while compliance is assessed for a specific intended use and implementation. The organisation must determine which electronic records and signatures fall within scope, configure roles, permissions, audit trails, retention policies and procedures, and then demonstrate that the system is fit for its intended use. Integrations with Jira, CI/CD pipelines, code repositories and other systems are also important because data flows may extend beyond the QA tool itself. Vendor documentation can facilitate validation, but responsibility remains with the pharmaceutical company. A proof of concept should therefore include the reconstruction of a complete evidence chain from the original requirement to the approved test result. How should AI-generated test cases be validated in pharma? An AI-generated test case should be treated as a draft requiring expert review. A person familiar with the requirement and its associated risk should verify the preconditions, test data, steps, expected results, negative scenarios and traceability to the source requirement. The system should record the source, model version, generation date, approver and all subsequent changes. Functionality with a greater potential impact on product quality, patient safety or data integrity requires more rigorous review and independent approval. AI performance should be evaluated against a controlled reference set using measures such as coverage completeness, the number of rejected suggestions and errors identified during review. This approach preserves the time-saving benefits of AI while keeping accountability with qualified personnel. Are self-healing tests safe in a validated GxP environment? They can be used when the mechanism operates in a controlled manner and maintains a complete record of every change. Automatically correcting a technical locator can reduce false failures, provided that the repair does not alter the meaning of a step, the acceptance criterion or the scope of the test. A well-configured system displays the proposed change, its rationale, and the previous and new values, and requires approval for significant modifications. The organisation should define in its SOPs which repairs may be accepted automatically, which require review and when a test must be reapproved. False positives, false negatives and the effects of self-healing engine updates should also be reviewed periodically. Execution repeatability and decision traceability are more important than the number of tests repaired without tester involvement. Can production data from pharmaceutical systems be sent to an external AI model? The preferred starting point is to use synthetic, anonymised or masked data limited to the minimum required for testing. Sending production data requires a legal basis, information classification assessment, vendor agreement, transfer controls, retention rules, processing location controls and clear policies regarding model training. Patient data, clinical trial information, safety data and confidential product information require particular protection. An on-premises deployment may still rely on a hosted AI service if an agent or interface communicates with an external model. The architecture should therefore show separately where tests are stored, where automation is executed and where AI processing takes place. Access to sensitive data should be granted only after the vendor provides a clear and verifiable description of the complete data flow. What should be done after an update to the AI model used by a QA tool? A model update should be managed as a controlled change, with the scope of assessment determined by risk. The first step is to identify which functions use the model and whether the update could affect test generation, regression selection, self-healing, defect classification or reporting. A previously approved reference test set should then be executed, and the results compared with those produced by the earlier version. Any differences should be assessed, documented and approved before the updated model is used more broadly. The change record should include the model version, date, scope, assessment results, accepted limitations and the person responsible for the decision. When a vendor updates the model without offering the option to freeze a version, the agreement should define advance notification, a testing window and a rollback procedure. Effective model version control is essential for maintaining the validated state.

Read
AQAP 2210 in Defence IT Projects: Software Quality Requirements

AQAP 2210 in Defence IT Projects: Software Quality Requirements

In a defence project, software quality does not end with an application working correctly on the acceptance date. The customer needs control over requirements, configuration, changes, testing, subcontractors and the evidence demonstrating that the product complies with the contract. The customer must also know which version was delivered, on what basis it was accepted and whether it can be maintained and developed safely. AQAP 2210 brings structure to these matters at software project level. The publication sets out NATO requirements for software quality assurance and is used as a supplement to AQAP 2110 or AQAP 2310. Its significance, however, does not arise merely from the use of the acronym AQAP. In practice, the requirements of the specific contract, the scope of supply, software criticality and the agreed arrangements for oversight and acceptance are decisive. For the customer, this means that selecting an IT supplier should involve much more than assessing technology, developer availability and price. The organisation needs a partner capable of developing software under controlled conditions, maintaining traceability and producing credible quality evidence. This article explains how to interpret AQAP 2210 requirements and apply them when selecting an IT supplier for the defence sector. KEY TAKEAWAY: AQAP certification is important evidence of the maturity of a supplier’s quality management system. It does not, however, replace analysis of the specific contract requirements or the quality evidence generated during project delivery. 1. AQAP 2210 at a glance AQAP 2210 addresses software quality assurance in projects delivered in a defence environment. The current publication is AQAP 2210, Edition B, Version 1, issued in 2022. It supplements AQAP 2110 or AQAP 2310 and is not designed as a completely standalone set of requirements. Its application to a project primarily results from the contract, procurement specification and referenced quality documents. It covers management and technical processes, including quality planning, criticality analysis, requirements, configuration, verification, validation, testing and subcontractor control. It does not mandate a single software development model. It can coexist with Agile and DevSecOps provided that the organisation maintains control, accountability and objective evidence. A supplier’s certificate does not automatically demonstrate the compliance of every product or project. The certification scope, contract requirements and application of processes to the specific undertaking all matter. 2. What is AQAP 2210? AQAP stands for Allied Quality Assurance Publications. The AQAP family supports a common approach among NATO nations to the quality of defence supplies. Its purpose is to increase confidence that a supplier can deliver a product that meets contractual requirements and provide the customer with appropriate visibility of processes affecting quality. AQAP 2210, Edition B, Version 1, contains NATO supplementary software quality assurance requirements. It is project-oriented and covers both management and technical processes. It does not prescribe a particular software methodology, programming language, tool or architecture. Its purpose is to establish a level of planning, control and evidence that gives the customer justified confidence in both the process and the product. AQAP 2210 is to be used in conjunction with AQAP 2110 or AQAP 2310, depending on the core set of requirements referenced in the contract. In Poland, current publications used in certification processes are described by the Polish Centre for Testing and Certification and the Quality Certification Centre of the Military University of Technology. The status of AQAP 2210 Edition B as an active publication can also be verified in the US ASSIST standardisation document database. 2.1 A contractual requirement, not universally applicable legislation AQAP 2210 should not be presented as legislation that automatically applies to every company developing defence software. Binding obligations arise primarily from the contract, specification, quality clause and documents referenced by the customer. In one project, AQAP 2210 may cover the full development lifecycle of a new system. In another, it may apply to the modification of an existing solution, component integration or software maintenance. Requirements may be subject to justified tailoring where the publication and the customer permit it. Such decisions should nevertheless be transparent, approved and documented. A supplier should not independently declare an inconvenient requirement inapplicable. 3. AQAP 2110 and AQAP 2210: what is the difference? AQAP 2110 and AQAP 2210 are related but perform different functions. AQAP 2110 establishes broad quality assurance requirements for design, development and production. AQAP 2210 expands on these requirements for software and for work performed at individual project level. Area AQAP 2110 AQAP 2210 Principal scope Quality assurance in design, development and production Supplementary software quality assurance Role Core set of quality assurance requirements Software-specific supplement to AQAP 2110 or AQAP 2310 Perspective Supplier quality management system and product delivery Project, processes and software-related evidence Example areas Planning, risk, suppliers, nonconformities and delivery oversight Project Software Quality Plan, criticality, requirements, SCM, V&V and testing Application Depends on contract requirements and the type of supply Applies when the contract covers software and references the relevant requirements Standalone use May serve as the core quality publication Used in conjunction with AQAP 2110 or AQAP 2310 ISO 9001 remains an important foundation for systematic quality management, but it does not describe every mechanism needed in a defence project or the detailed quality requirements for software. Assessment of a potential partner should therefore go beyond asking whether the company holds ISO 9001 certification. The customer should establish whether the supplier’s system covers the relevant AQAP scope and whether the organisation can apply it to the specific project. 4. When does AQAP 2210 apply to an IT project? The contractual documentation provides the most reliable answer. The requirement may be stated directly in the contract, procurement specification, quality clause or quality plan, or in requirements imposed on the prime contractor and flowed down to subcontractors. AQAP 2210 may be relevant to projects involving: development of new bespoke software; development or substantial modification of an existing system; software maintenance and support; integration of software with hardware, sensors, effectors or platforms; command, control and situational awareness systems; C2, C4ISR and combat support systems; embedded software or a component forming part of a larger product; use or modification of commercial off-the-shelf software; delivery of a software component by a subcontractor to the prime contractor. The mere presence of code in a product does not, however, determine an identical scope of requirements. An application supporting an administrative process may require different controls from a component affecting a critical function. Before work begins, the parties should therefore identify at least the scope of supply, their respective responsibilities, software criticality, dependencies, acceptance arrangements and the evidence required by the customer. 4.1 Questions to ask before signing the contract Which AQAP publications and editions are referenced? Do the requirements apply to the entire supply, a specific component or selected processes? Is tailoring permitted and, if so, who approves it? What oversight and access rights are granted to the customer or Government Quality Assurance Representative? Which plans, records, reports and evidence are required for reviews and acceptance? Which obligations must be flowed down to subcontractors? How will software criticality be assessed, and how will it affect the rigour of project activities? Clarifying these points early reduces the risk of costly rework to documentation, testing processes or the supply chain once delivery is under way. 5. Why does AQAP 2210 matter to the customer? In a conventional commercial project, some ambiguities can be resolved by renegotiating scope or moving a deadline. In a defence project, the consequences of an incorrect configuration, incomplete test or loss of traceability may be much more serious. The system may interact with hardware, process operationally significant data or operate in an environment with limited connectivity and elevated threats. AQAP 2210 helps the customer reduce risks including: delivery of functionality that does not comply with contractual requirements; changes introduced without impact assessment and approval; absence of links between requirements, design, code and test results; inability to identify unequivocally the configuration submitted for acceptance; detection of critical defects only during acceptance testing; lack of objective evidence that tests were performed; uncontrolled use of external components; insufficient oversight of subcontractors; loss of knowledge needed to maintain and further develop the system; closure of a nonconformity without confirmation that the correction was effective. The principal value is therefore not the number of documents produced, but transparency. The customer can verify how the supplier interprets requirements, controls work, manages open risks and determines that a product is ready. 6. Key AQAP 2210 requirements in a software project AQAP 2210 covers numerous interrelated processes. Their detailed application depends on the contract, but the areas below are among the most important when assessing a supplier and planning delivery. 6.1 Project Software Quality Plan The Project Software Quality Plan should demonstrate how the organisation will meet the quality requirements of a specific undertaking. It is not a general quality policy or a document produced only immediately before an audit. A robust plan connects contractual requirements with the actual way in which the team works. It defines the scope, roles, responsibilities, lifecycle, reviews, verification and validation methods, configuration management, subcontractor control, metrics and required records. It should also identify dependencies between documents and explain how the plan will be updated when the project changes. The customer should be able to use it to understand not only what the supplier declares, but also when evidence will be provided, who will make decisions and how deviations will be handled. 6.2 Software criticality analysis Criticality helps align the rigour of project activities with the consequences of a potential failure. The analysis should consider the function of the software, its relationship with the overall system and the potential effect of malfunction on people, the mission, equipment, information and continuity of operations. The outcome may affect the independence of reviews, test scope, required coverage, reporting frequency, level of change control and treatment of risk. The objective is not to impose the most expensive controls on every component, but to reach a conscious, documented and justified decision. 6.3 Requirements management and traceability Requirements should be unambiguous, verifiable and subject to change control. The supplier must understand system, software and component requirements, together with constraints arising from architecture, interfaces, security and the operating environment. Traceability makes it possible to move from a requirement to the design solution, implementation and test, and then back from the test result to the contractual basis. It may be maintained in a matrix or a dedicated tool. What matters is that it remains current and reveals requirements without design coverage, code without justification or tests without a corresponding requirement. In a mature project, a requirement change triggers an assessment of its impact on architecture, code, tests, documentation, schedules and subcontractors. Updating a backlog item alone is insufficient if the remaining evidence is left out of date. 6.4 Software configuration management Software configuration management, or SCM, provides unambiguous identification of product items and control over their changes. It does not concern source code alone. Its scope may include requirements, models, scripts, environment configurations, libraries, documentation, test data, tools, build artefacts and installation packages. The customer should expect clear answers to practical questions such as: Which items make up a particular product version? Who approved a change, and on what basis? Can the build submitted for testing or acceptance be reproduced? How are the status of changes and nonconformities recorded? Does the supplier control dependencies, libraries and tool versions? How are repositories protected and access restricted? Without these mechanisms, even correctly tested functionality may enter the wrong release or be overwritten by a later change. 6.5 Verification, validation and testing Verification asks whether the product has been built in accordance with specified requirements and design. Validation establishes whether the solution meets the needs and intended use in its target context. In practice, both types of activity should be planned, have defined criteria and owners, and produce retained results. The test programme may cover unit, integration, system, performance, security, resilience and acceptance testing. The scope depends on the product and contract. Key considerations include: linking tests to requirements; defined test environments and test data; identification of the product version under test; test entry and exit criteria; results, deviations and evidence of execution; separation of roles where independence is required; handling of defects, retesting and regression testing. Automation can improve repeatability, but a pipeline report is not complete evidence on its own if it does not identify what was tested, which version was used and which criteria governed the assessment. 6.6 Nonconformities and corrective action The supplier should operate a controlled process for recording, assessing and closing nonconformities. A correction that addresses an immediate defect should be distinguished from corrective action intended to eliminate its cause. The record should make it possible to determine the impact of the problem, affected versions, the disposition decision, responsibility, retest results and any need to inform the customer. Recurring problems should lead to trend analysis and an assessment of process effectiveness, rather than another sequence of isolated code fixes. 6.7 Subcontractors, COTS and external components Modern software uses libraries, tools, services, devices and ready-made components. AQAP 2210 does not allow them to be treated as areas outside the supplier’s responsibility. The organisation should assess a component’s suitability, constraints, rights of use, documentation, configuration and effect on requirements. For commercial off-the-shelf software, objective grounds are needed to establish that the product will fulfil the required function. Where full traceability is not possible, the limitation should be identified, assessed and appropriately managed. Modifying ready-made software may also change the risk profile and responsibility for maintenance. The same principle applies to subcontractors. The prime contractor should specify requirements, monitor performance and retain evidence of oversight. A subcontractor’s certificate may support qualification, but it does not release the prime contractor from responsibility for compliance of the overall supply. 7. Can Agile and DevSecOps be reconciled with AQAP 2210? Yes. AQAP 2210 does not prescribe a single lifecycle model or mandate a waterfall approach. Agile and DevSecOps can be used if the organisation can demonstrate control over requirements, configuration, testing, accountability and releases. Agile or DevSecOps practice Corresponding quality mechanism Product backlog Controlled record of requirements, priorities and changes Definition of Ready Criteria establishing that a requirement is ready for implementation Definition of Done Quality, testing, documentation and acceptance criteria Pull request and code review Documented review and approval of a change Code repository Item identification and configuration control CI/CD Repeatable build, automated controls and retained results Test management Link between requirement, test case, product version and result Release pipeline Controlled release and unambiguous identification of its contents Retrospective Process improvement and corrective action The most common mistake is to equate agility with an absence of documentation. Documentation in an Agile project may be lighter, generated automatically and maintained in tools. It must nevertheless remain credible, accessible and understandable to those responsible for oversight. A second risk is excessive reliance on automation. A pipeline may execute thousands of tests, but the customer also needs context: the product version, test scope, criteria, deviations and approval. DevSecOps supports AQAP when it automates a controlled process, not when a stream of logs obscures the absence of accountability. 8. What documents and evidence may the customer expect? The final evidence set is determined by the contract. There is no single file or binder suitable for every project. In practice, the customer may expect materials such as: Area Examples of documents and records Control question Planning Project Software Quality Plan, review schedule and responsibility matrix Is it clear who makes each decision, when and against which criteria? Requirements Specifications, change history, traceability matrix and review records Does every requirement have a source, an owner and a verification method? Configuration SCM plan, configuration item list, baselines and release register Can the exact version delivered to the customer be reproduced? Testing Plans, cases, data, reports, results and defect records Does the result relate to the correct version and an approved requirement? Nonconformities Problem reports, decisions, root-cause analysis and retest records Has the problem been effectively resolved rather than merely marked closed? Suppliers Qualification criteria, assessments, purchasing requirements and reviews Have quality obligations been flowed down and are they monitored? COTS and dependencies Suitability assessment, versions, licences, constraints and functional evidence Does the organisation understand the risk and can it maintain the component? Acceptance and delivery Release documentation, acceptance results and list of deviations Are the contents of the delivery and any remaining limitations unambiguous? Evidence should be credible, current, linked to the relevant scope and reproducible. A screenshot without a date, version or owner has limited value. Equally, a policy describing a process does not demonstrate that the process was actually applied to the project. 9. What does AQAP certification demonstrate, and what does it not guarantee? Certification of a quality management system by a competent body is an important signal to the customer. It shows that a defined scope of the organisation’s activities has been assessed against the specified requirements and that the company maintains processes necessary for controlled delivery. A certificate may demonstrate: implementation and maintenance of a quality system conforming to a specified AQAP publication; assessment of the stated scope of activities and locations; the existence of controlled processes, responsibilities and records; periodic third-party assessment of the system; an organisational foundation for performing contracts that require AQAP. A certificate does not automatically guarantee: compliance of every project with every contract; a defect-free product; fulfilment of requirements outside the certification scope; possession of every clearance, authorisation or domain competence required by the project; effective application of processes without the right team and oversight; acceptance of the supplier by every customer without further qualification. The customer should therefore verify the issuing body, certificate validity, AQAP publication and edition, certification scope, locations and alignment of that scope with the planned procurement. It is also worth asking the supplier to demonstrate how its quality management system will be applied to the specific project. 10. How should you select an IT supplier for a defence project? A capable supplier combines three layers: organisational capability, technical competence and understanding of the defence environment. A weakness in any one of them may become apparent only during integration, oversight or acceptance. 10.1 Customer checklist [ ] The certification scope covers software development, delivery or maintenance relevant to the planned project. [ ] The supplier can translate contractual requirements into a quality plan and the team’s daily work. [ ] Requirements, design decisions, implementation and tests remain traceable. [ ] Configuration management covers code, documentation, dependencies, environments and releases. [ ] The build submitted for testing or acceptance can be reproduced unambiguously. [ ] The V&V process has defined roles, criteria, environments and retained results. [ ] Nonconformities are assessed, tracked, retested and closed on the basis of evidence. [ ] Subcontractors and COTS components are subject to qualification and monitoring. [ ] The team understands software-hardware integration and constraints of the target environment. [ ] The supplier understands defence systems, NATO standards and work within a supply chain. [ ] It can produce the quality evidence required for reviews, oversight and acceptance. [ ] It can provide maintenance, change management and controlled development after deployment. [ ] The engagement model clearly allocates responsibility for the product, quality, security and decisions. [ ] The experience claimed is relevant to the actual scope and criticality of the procurement. 10. Warning signs during supplier qualification Answers limited to stating that the company is certified or works in Agile should prompt caution. Other warning signs include: inability to explain the certification scope; a quality plan copied without adaptation to the project; no owner for the configuration management process; tests that are not linked to requirements and the product version; subcontractors treated as solely responsible for their own quality, without prime contractor oversight; no controlled process for approving deviations; documentation prepared only immediately before acceptance; inability to explain how changes will be handled after deployment. The best test is a discussion based on a realistic scenario: a high-criticality requirement changes, affects a subcontracted component and requires a new integration test. A mature partner can explain the impact assessment, decisions, configuration update, testing and evidence without hiding behind a generic procedure. 11. Why choose TTMS as a partner for the defence sector? The selection of a technology partner should be based on its fit with the specific undertaking. In the case of TTMS, the relevant strength is the combination of a certified quality management system, technical capabilities and domain experience. 11.1 Certified quality processes TTMS has obtained AQAP 2110 and AQAP 2210 certification, as described in the TTMS press release. For a prospective customer, this confirms that a defined scope of the company’s quality management system has been independently assessed against requirements used in the defence sector and in software quality assurance. Certification is not presented as a substitute for project analysis. It provides an organisational foundation on which to build the quality plan, traceability, configuration management and evidence required by a particular contract. 11.2 Technical expertise and domain knowledge The public TTMS offering for the defence and space sectors includes software development, defence IT engineering services, hardware-software integration, technical consultancy, project management and the provision of specialist teams. TTMS also describes experience involving C2, C4ISR and combat support systems, as well as work in the environment of international organisations. This combination matters because process conformity cannot replace engineering competence. Conversely, even a highly capable software team may struggle in a defence project if it cannot work with contractual requirements, quality oversight and formal evidence. 11.3 A flexible engagement model A project may require a complete solution, a distinct component, integration, a software team or individual specialist capabilities. The model should be selected after analysing the scope, responsibilities and quality requirements. Regardless of the form of engagement, ownership of requirements, configuration, testing, risk and acceptance should be clearly established. TTMS can join the undertaking as a technology partner supporting software development, integration and maintenance. The final obligations, applicable AQAP publications and required evidence should be defined in the documentation of the specific project. 12. What can an engagement with TTMS look like? 12.1 Context and requirements analysis The first stage establishes the purpose of the system, scope of supply, stakeholders, architecture, quality requirements and security constraints. The team identifies the publications and clauses referenced in the contract and areas requiring clarification. 12.2 Definition of the delivery model The parties establish responsibilities, team composition, interfaces with the customer and other suppliers, lifecycle, reviews, tools, configuration and required evidence. This stage should also plan the flow-down of requirements to subcontractors. 12.3 Controlled development and reporting Delivery combines engineering work with requirements, risk, configuration, quality and nonconformity management. The customer receives the agreed visibility of progress, results and open decisions. 12.4 Verification, validation and acceptance Tests and reviews are performed on controlled versions against approved criteria. The acceptance package should unambiguously identify the delivery contents, results, deviations and remaining limitations. 12.5 Maintenance and controlled development After deployment, configuration management, problem handling, updates, change impact assessment and documentation maintenance remain necessary. The support model should reflect the importance of the system and the required availability. 13. Are you looking for an IT partner for a defence project? A defence project requires a simultaneous understanding of technology, quality, integration, security and contractual accountability. It is worth involving the supplier before the architecture and delivery plan are finalised, so that AQAP requirements are not treated as a documentation exercise postponed until acceptance. Contact TTMS to discuss your project’s technical and quality requirements, allocation of responsibilities and a potential engagement model with the Defence team. 14. Frequently asked questions about AQAP 2210   What is AQAP 2210? AQAP 2210 is a NATO publication containing supplementary software quality assurance requirements. It is project-oriented and covers the management and technical processes needed for controlled software development and delivery. What do AQAP 2210 requirements cover? They include software quality planning, criticality analysis, requirements management, traceability, configuration, subcontractors, COTS software, verification, validation, testing and the treatment of nonconformities. The exact scope in a project is determined by the contract. What is the difference between AQAP 2110 and AQAP 2210? AQAP 2110 establishes broad quality assurance requirements for design, development and production. AQAP 2210 expands on software-specific requirements and is used as a supplement to AQAP 2110 or AQAP 2310. Can AQAP 2210 be used on its own? Not as a completely independent set of requirements. The current edition is intended for use as a supplement to AQAP 2110 or AQAP 2310. The applicable combination should be specified in the contract. When is AQAP 2210 required in an IT project? It is required when referenced in a contract, specification, quality clause or requirements imposed on the contractor. The fact that software is being developed for the defence sector does not, without examination of the documentation, establish an identical set of obligations in every case. Does every military software supplier need AQAP certification? There is no universal rule to that effect. The need for certification and its scope depend on the customer, procurement procedure, contract and type of supply. Even where certification is required, its validity and alignment with the project scope should be verified. Is ISO 9001 sufficient for a defence project? ISO 9001 can provide an important quality management foundation, but it does not replace detailed AQAP requirements referenced in the contract. Nor does it describe every mechanism focused on software quality assurance in a defence environment. Is AQAP 2210 compatible with Agile and DevSecOps? Yes. It does not mandate a single development model. The team must nevertheless retain control over requirements, changes, configuration, testing, accountability and evidence. Agile cannot be used to justify a loss of traceability. What documents should a software supplier prepare? Depending on the contract, these may include a Project Software Quality Plan, configuration management plan, requirements register, traceability matrix, review reports, test plans and results, change and nonconformity records, supplier assessments, and release and acceptance documentation. Does AQAP 2210 cover COTS components and subcontractors? Yes. The supplier should oversee subcontractors and assess the suitability, configuration, documentation, constraints and risks of ready-made components. Responsibility for the overall supply does not disappear because part of the solution originates from another organisation. How can the scope of a supplier’s AQAP certificate be verified? The issuing body, certificate number and validity, AQAP publication and edition, scope of activities, locations and any exclusions should be checked. The scope should correspond to the work actually entrusted to the supplier. Why choose a supplier certified to AQAP 2110 and AQAP 2210? The certificates can reduce uncertainty regarding the maturity of the quality management system and the organisation’s ability to operate controlled processes. The customer should still assess technical capabilities, domain experience, certification scope and the proposed application of requirements to the specific project.

Read
AEM Content Models: A 2026 Guide to Content Fragment Model Best Practices

AEM Content Models: A 2026 Guide to Content Fragment Model Best Practices

Content teams managing digital experiences across multiple channels often face a familiar challenge: the same product description, promotional message, legal disclaimer, or campaign message needs to be adapted for different platforms and formats. In Adobe Experience Manager, Content Fragment Models help address this challenge by giving teams a structured way to define content elements and create reusable content fragments. This guide explains what AEM Content Fragment Models are, how they work, and what to consider when designing structured content in AEM in 2026. 1. What Are AEM Content Models and Why They Matter in 2026 In AEM, what many teams call “content models” usually refers to Content Fragment Models. These models act as blueprints for structured content. They define the fields, data types, and validation rules that content fragments based on the model need to follow. Instead of authors recreating the same information in multiple places, a Content Fragment Model gives teams a repeatable structure for content creation. For example, a product model might include fields for product name, description, specifications, image reference, and related policy information. Every product content fragment created from that model follows the same structure, making the content easier to manage, validate, and deliver. Content Fragment Models also support reusable relationships between pieces of content. For example, a product content model can use a Fragment Reference to connect product entries with a shared policy fragment, such as warranty information. This allows teams to manage reusable structured content in one place and reference it from related content fragments. 1.1 Content Fragment Models vs. Content Fragments: Key Differences It is easy to conflate Content Fragment Models with Content Fragments, but the distinction is fundamental. A Content Fragment Model is the blueprint: it defines which fields exist, which data types they use, and what validation rules apply. A Content Fragment, by contrast, is an actual piece of structured content created from that model and filled in with authored values, such as text, numbers, dates, tags, asset references, or fragment references. Think of the model as a recipe card and the fragment as the dish itself: the model defines the structure, while each fragment contains the authored content. 1.2 How Content Fragment Models Enable Headless and Hybrid Delivery Content Fragment Models help make headless and hybrid delivery practical by separating content structure from page presentation. Because a Content Fragment Model defines structured content independently of a specific page layout, the resulting Content Fragments can support both headless content delivery and page authoring in AEM. For headless delivery, AEM can expose Content Fragments through GraphQL, allowing front-end applications to request structured content based on the models behind those fragments. This makes it possible for development teams to use AEM-managed content in digital experiences that are not limited to traditional AEM page rendering. 2. When to Use Content Fragment Models vs. Editable Templates or Experience Fragments Not every piece of content belongs in a Content Fragment Model. Editable templates and Experience Fragments still have their place, especially when the priority is page structure, layout control, or reusable visual experiences rather than structured content reuse. A campaign landing page, for example, may be better suited to an editable template or an Experience Fragment if the main requirement is flexible page composition, visual layout, and reusable design elements. In AEM, Experience Fragments combine content and layout and can be reused across pages, while Content Fragments are structured editorial content without additional visual design or layout. Product specifications, staff bios, FAQ entries, legal text, and policy information are strong candidates for Content Fragment Models because they often need a consistent structure across multiple contexts. In short, use Content Fragment Models when content needs to be structured and presentation-independent. Use editable templates or Experience Fragments when the priority is page layout, visual composition, or reusable page experiences. 3. Core Building Blocks of an AEM Content Fragment Model Every AEM Content Fragment Model is built from a set of configurable elements: data types, field properties, validation rules, references, and optional structure helpers such as tabs. Getting familiar with these building blocks is the first step toward designing models that remain clear, reusable, and manageable over time. 3.1 Common Data Types and Field Options Several foundational field types cover common structured content needs. Text fields can be used for names, titles, summaries, descriptions, and longer body copy. Number fields capture numerical values. Boolean fields support simple true-or-false choices. Date and time fields are useful for content that needs a scheduled or time-based value, such as a publication date, event date, or availability period. 3.2 Enumerations, Tags, and JSON Object Fields Beyond the basics, enumerations let authors select from predefined options, helping keep values consistent across fragments. Tags can support categorization and filtering by allowing authors to apply defined tag values to content. JSON Object fields allow authors to enter JSON syntax in the corresponding element of a Content Fragment. This can be useful when structured JSON needs to be stored and delivered as JSON, including through GraphQL. However, JSON Object fields should be used carefully. In many cases, clearly defined fields or Fragment References are easier for authors to manage and easier for teams to govern over time. 3.3 Content Reference and Fragment Reference for Nested Content Content Reference fields let authors reference other content, such as assets or other content resources, instead of duplicating information directly inside a fragment. This can help teams keep related content easier to manage. Fragment Reference fields are especially important for structured content because they allow one Content Fragment to reference another Content Fragment. This supports nested content structures and makes it possible to model relationships between fragments. 3.4 Properties, Field Configuration, and Tabs Each field in a Content Fragment Model includes properties that define how the field behaves. Depending on the data type, these properties can include the field label, property name, rendering options, required status, validation settings, allowed models, root paths, or accepted content types. Tabs can also be used to organize the authoring interface. In AEM, a Tab Placeholder helps separate groups of fields in the Content Fragment editor, making larger models easier for authors to navigate. Tabs are used for authoring organization rather than content delivery logic. 3.5 Validation Rules for Data Integrity Validation rules act as guardrails for structured content. They help ensure that authors enter content in the expected format before the fragment is saved and used downstream. Depending on the field type, validation can include requirements such as making a field mandatory, checking text against a predefined pattern, limiting numerical values, restricting referenced content to specific types, or allowing only fragments based on selected models. Thoughtful validation helps reduce inconsistent content, missing required values, and formatting issues. 4. Step-by-Step: Creating and Configuring a Content Fragment Model Creating a Content Fragment Model in AEM usually involves enabling the right configuration, creating the model, defining its structure, enabling it for authoring, and allowing it on relevant Assets folders through policies. 4.1 Setting Up Configuration and Access Before any modeling work begins, teams should make sure that Content Fragment Model functionality is enabled for the relevant AEM configuration. Without this setup, authors and administrators may not be able to create models in the expected location. 4.2 Building the Model Structure and Defining Fields Once the configuration is ready, teams create the model by adding data types, configuring field properties, and applying validation where needed. 4.3 Allowing the Model on Assets Folders A Content Fragment Model needs to be allowed on the relevant Assets folders where authors will create Content Fragments. This is done through folder policies. If the model is not allowed for the folder, authors may not see it as an available option when creating a new Content Fragment in that location. 4.4 Enabling, Disabling, Publishing, and Unpublishing Models Content Fragment Models have lifecycle controls that affect how they are used. A model can be enabled so authors can create Content Fragments based on it, or disabled when it should no longer be used for new fragments. In AEM as a Cloud Service, models can also be published to the Publish or Preview tiers. Publishing controls the availability of the model outside the authoring environment, while enabling controls whether authors can create new Content Fragments from the model. Teams should use these controls carefully, especially when changing models that already have dependent Content Fragments. Structural changes may affect authoring workflows, delivery, integrations, and GraphQL-based use cases. 5. Best Practices for Designing Scalable Content Fragment Models 5.1 Structuring Models for Reuse Across Delivery Scenarios Strong Content Fragment Models are designed around reusable content, not around a single page layout. Because Content Fragments can support both headless delivery and page authoring in AEM, the model should define the content structure independently of how that content will eventually be presented. This means thinking early about which content elements need to be reused, referenced, filtered, or delivered through APIs. For example, a product model, author profile, FAQ entry, or policy fragment should focus on the information authors need to manage rather than the visual layout of a specific page. 5.2 Naming Conventions and Governance Standards Clear naming conventions help teams keep Content Fragment Models easier to understand and maintain. Field labels should be author-friendly, while property names should be consistent, predictable, and suitable for structured delivery. In AEM, property names are especially important because they identify where authored values are stored and can also affect how structured content is exposed downstream. When defining property names manually, they should use only supported characters, such as letters, numbers, and underscores. 5.3 Using Nested Fragments Without Overcomplicating Structure Fragment References are useful when one Content Fragment needs to reference another Content Fragment. They make it possible to create nested content structures and model relationships between pieces of structured content. However, nested structures should be used intentionally. Too many layers of references can make models harder for authors to understand and maintain. A better approach is to use Fragment References where they reduce duplication, clarify relationships, or support reusable content patterns. 5.4 Planning for Variations and Localization Content Fragments can include variations, which makes it important to consider how content may need to differ by use case, market, language, or channel context. The Content Fragment Model should provide a stable structure, while individual fragments and their variations can support different content needs within that structure. When localization is part of the content strategy, teams should consider it early in the modeling process. This includes thinking about which fields may need localized values, which references should remain shared, and how language copies or regional versions will be managed in AEM. 6. Displaying and Delivering Content Fragments in AEM Once Content Fragment Models are built and Content Fragments are created, the next question is how that structured content should be displayed or delivered. AEM supports different approaches depending on whether the content is used in page authoring, delivered through headless APIs, or reused across multiple digital experiences. Content Fragments can be used directly in AEM page authoring when teams want structured content to appear within AEM-managed pages. In this approach, authors can place Content Fragments into page experiences while still relying on the structure defined by the underlying Content Fragment Model. For headless delivery, AEM Content Fragments work with the AEM GraphQL API. GraphQL allows front-end applications to query structured content based on the schemas generated from Content Fragment Models. This helps developers request only the content they need for a given experience. Many AEM implementations can use both approaches. A team might use Content Fragments in AEM pages for the main website while also exposing selected structured content through GraphQL for other supported digital experiences. 7. Common Content Modeling Mistakes and How to Avoid Them Several content modeling mistakes can make AEM Content Fragment Models harder to maintain over time. One common issue is overcomplicating the model structure. Trying to anticipate every possible future use case can lead to too many fields, unnecessary references, or deeply nested fragment structures that are difficult for authors to understand and manage. Another frequent issue is treating validation as optional. Content Fragment Models can include validation settings such as required fields, text patterns, numeric constraints, content reference restrictions, and allowed models for Fragment References. Using these rules thoughtfully helps reduce inconsistent values, missing required information, and content that does not match the intended structure. Unclear naming conventions can also create problems. Field labels should be easy for authors to understand, while property names should remain consistent and technically safe. In AEM, manually defined property names should use only supported characters, such as letters, numbers, and underscores. The best way to avoid these issues is to plan models before building them. Start with the content types that need to be managed, identify which fields are required, decide where references are genuinely useful, and keep the model as simple as the content requirements allow. 8. Migrating and Evolving Content Fragment Models Without Disrupting Content Content Fragment Models may need to evolve as content requirements change. New fields may be added, existing fields may need clearer validation, and references may need to be adjusted as the content structure becomes more mature. These changes should be handled carefully because editing an existing Content Fragment Model can affect dependent Content Fragments. A safe approach starts with understanding which Content Fragments are based on the model being changed and how those fragments are used in authoring, delivery, and integrations. This is especially important when structured content is exposed through GraphQL, because schemas are generated from Content Fragment Models and downstream applications may rely on specific fields being available. Before making structural changes, teams should review the model, identify required updates, and test changes in a non-production environment where possible. Adding new optional fields is usually less disruptive than removing or renaming existing fields, especially when those fields are already used by authors or external consumers. When a model needs to change significantly, it can be safer to introduce changes gradually. Teams may choose to update validation rules, adjust references, or create a new version of a model instead of modifying an existing structure too aggressively. This helps protect existing content while still allowing the model to adapt to new requirements. 9. How TTMS Can Support Your AEM Content Models Strategy At TTMS, we support organizations with Adobe Experience Manager implementation, consulting, development, integration, and maintenance services. We are a Bronze Adobe Solution Partner, and our AEM team helps clients design, build, optimize, and maintain AEM solutions tailored to their digital experience needs. If your team is planning to modernize its content architecture, improve structured content governance, or build scalable AEM Content Fragment Models for product catalogs, customer portals, or headless delivery, we can help you design the right foundation and evolve it safely over time. If you want to build a more scalable AEM content architecture, contact us to discuss how we can support your AEM Content Fragment Models strategy.

Read
1272

The world’s largest corporations have trusted us

Wiktor Janicki

We hereby declare that Transition Technologies MS provides IT services on time, with high quality and in accordance with the signed agreement. We recommend TTMS as a trustworthy and reliable provider of Salesforce IT services.

Read more
Julien Guillot Schneider Electric

TTMS has really helped us thorough the years in the field of configuration and management of protection relays with the use of various technologies. I do confirm, that the services provided by TTMS are implemented in a timely manner, in accordance with the agreement and duly.

Read more

Ready to take your business to the next level?

Let’s talk about how TTMS can help.

Sunshine Ang Sen Shuen

Sales Manager