PCProvider ComplianceRegulated case systems
GitHub lane 1 · 42 unique candidates · 12 deep profiles

Case, GRC and QMS systems: how they actually work.

The lane looked for an out-of-the-box backbone. WKS Platform is the closest case/workflow base; OpenQMS is the strongest regulated-QMS reference; Unicis is the strongest current open GRC product. None supplies the complete Provider Compliance authority model.

No repository is an aged-care application workbench.

The best small regulated benchmark is WKS Platform + OpenQMS patterns + Open Policy Agent. Deploying all three would still require a SISO-owned case/evidence schema and would create material Java/Camunda, licensing and integration work.

Architecture useBenchmark their object models, case stages, approvals, CAPA/audit patterns and rules. Do not merge their databases or treat a framework control as an aged-care application question.

Twelve strongest systems

Closest case base · probe

WKS Platform

Spring Boot + React + Camunda. Case/process service owns adaptive work; BPMN executes tasks and stages.

Use
Stages, tasks, timers, assignments and approvals.
Missing
Evidence semantics, aged-care model, tenant hardening.
Repository ↗
Regulated QMS · probe

OpenQMS

Life-science QMS patterns for controlled documents, deviations, CAPA, audits and change control.

Use
Version/approval object patterns.
Risk
AGPL/commercial terms and different domain.
Repository ↗
Open GRC · probe

Unicis Platform CE

Framework controls map to evidence, risk and compliance status in a multi-framework workspace.

Use
Control catalogue and cross-framework evidence.
Missing
Case narrative, forms and client declaration.
Repository ↗
Enterprise case reference

ArkCase

Configurable Java case types, roles, forms, workflows, documents and search.

Use
Case type + work queues.
Burden
Large enterprise surface.
Repository ↗
Case/document API

Open Zaak

Standards-led REST separation of cases, catalogues/types, decisions and documents.

Use
Object boundaries and identifiers.
Risk
Dutch semantics and licence review.
Repository ↗
Social-sector case PWA

Aam Digital

Configurable entities and relationships with tasks, activity history, permissions and offline UI.

Use
People/services/tasks relationship model.
Risk
GPL and no claim/evidence authority.
Repository ↗
Rules · adopt/probe

Open Policy Agent

Structured JSON inputs are evaluated against versioned Rego decisions outside application code.

Use
Category, required-field, expiry and transition checks.
Custom
Rule IDs, source citations and evaluated facts.
Repository ↗
Agent action gate

Lelu

Proposed agent actions pass confidence/policy gates and may route to human review.

Use
Allow/deny/review pattern.
Risk
Newness, persistence and tenancy.
Repository ↗
Dual-store pattern

policy-RAG

Qdrant chunks plus PostgreSQL policy metadata, RBAC, KPIs, evidence and comments.

Use
Structured authority beside retrieval index.
Risk
Course/demo defaults; not production.
Repository ↗
Ingestion + records

Docling + Paperless-ngx

Local layout extraction paired with OCR archive, tags, custom fields and search.

Use
Document ingestion and shelf.
Missing
Claims, categories and approvals.
Docling ↗
Healthcare platform

Medplum

FHIR resources, auth and healthcare application primitives.

Use
Healthcare identity/interoperability reference.
Burden
FHIR is not the application domain model.
Repository ↗
Workflow references

Temporal + LangGraph

Temporal replays durable workflow history; LangGraph checkpoints graph state and human interrupts.

Use
Long waits, retries, resume and approvals.
Decision
Defer until direct state transitions fail.
Temporal ↗

Combination decision

Best out-of-box benchmark is not the recommended MVP.WKS + OpenQMS + OPA covers case flow, QMS objects and deterministic policy, but it creates multiple models and significant integration. The minimum proof build keeps one Supabase authority and treats these systems as benchmark spikes.
Read the minimum-repo decision

Adoption gates

Current licence and commercial terms, tenant isolation, RLS/permissions, audit immutability, export, backup/restore, deletion, data residency, upgrade path and one de-identified Provider Compliance fixture.