Practice·August 25, 2026 · 3 min read

No cron sends this. A person does.

FDA Radar's digest job writes an HTML file and a text file to disk. It does not have a send function. The last step — pasting the result into a mail client and pressing send — belongs to a person, on purpose, because that is the same step FDA's own complaint-handling rule refuses to let happen silently.

By Connor Griggs — Regulatory & Quality Strategist

Run npm run digest against this product today and here is exactly what happens: it reads the approved items from the last seven days, renders them into an email, writes digest.html and digest.txt to disk, and prints the subject line to the terminal. Then it stops. There is no function anywhere in the codebase that sends that file to anyone. The script’s own header comment says why in one line: a human pastes this into a mail client and presses send, because that human is the last check before roughly fifty regulatory professionals act on it, and the moment an automated sender exists, that check is one forgotten cron job away from disappearing.

That is a real cost, stated plainly rather than hidden. A weekly digest that requires a person to open a file and paste it somewhere does not scale the way a cron-triggered send does, and the product says so: automate the send once the curation is proven, not before. What that buys, in the meantime, is a specific and narrow thing — not better curation, but a standing, un-automatable point at which a person looks at what is about to leave the building.

The quiet week is the case that matters most

The interesting failure mode isn’t a normal week with fifteen items in it. It is the week with zero. If no item cleared human review in the window, the digest still renders — as “nothing material changed,” per the product’s own design principle that silence has to be a stated finding, never a blank screen. But the script does not let that quiet output pass for free. It prints a warning in the terminal before handing control back: this renders as a finding, not a blank — confirm the review queue is actually empty at /review before treating it as one, because a quiet digest caused by nobody working the queue is wearing the same clothes as a quiet digest caused by an honestly quiet week, and only a person looking at the actual queue can tell them apart. The per-subscriber path is built the same way: quiet personal digests are generated and shown to the operator alongside the busy ones, specifically so nothing — including a subscriber’s all-clear — goes out unseen.

A decision to send nothing is still a decision. The product is built so that decision has to be made by someone, every time, rather than defaulted into by an empty inbox.

The same shape FDA asks of a complaint file

21 CFR 820.198(b) governs a different silence: a manufacturer decides a complaint does not need investigating. FDA does not forbid that outcome. It forbids it from happening quietly — the rule requires the manufacturer to maintain a record that includes the reason no investigation was made and the name of the individual responsible for that decision. “Nothing to investigate here” is allowed to be the right call. It is never allowed to be a call nobody made.

That is the same discipline this digest script applies to its own quiet weeks, at a much smaller scale and with nothing filed with a regulator. “Nothing material happened” is a legitimate thing for the digest to say. The script simply refuses to let that sentence leave the building without a named person having actually looked at the review queue and agreed with it — the same reason the busy weeks require a paste and a keypress rather than a cron entry.

This is regulatory intelligence about how the pipeline is built, not regulatory advice about your own complaint-handling procedure; §820.198 applies to your quality system, on your facts, and belongs with your own regulatory judgment. See our editorial standards for the rest of what stays human in this product and why.

Regulatory intelligence, not regulatory advice. This post describes method and published FDA records as of its date; decisions about a specific device belong with your regulatory professional.

Method
The lab is accredited. Not the device.
Practice
Breakthrough is law. STeP is a guidance.
Practice
MDSAP replaces routine. Not for-cause.
Method
No field on a 510(k) says what it treats
Method
Discretion is a policy. Exclusion is a statute.
Practice
Designated by one office. Approved by another.
Method
MedSun sits beside MAUDE, not inside it
Practice
The five-unit device never gets a K-number
Practice
Meeting the criteria isn't a tracking order
Method
The PMA clock doesn't stop at approval
Practice
The K-number doesn't track today's device
Method
A MAUDE report proves it was filed
Practice
Not every MDR starts with the manufacturer
Method
Completed. Not terminated.
Practice
The device-ban list has three entries
Method
The UDI exception has its own deadline
Method
MDUFA VI is being negotiated in public
Practice
The inspection manual changed, not the rule
Method
The count Congress had to legislate
Practice
The small-business rate isn't retroactive
Method
A detention order has no docket to read
Practice
PMA approvals moved off the Federal Register
Method
A citizen petition names names
Practice
A market withdrawal isn't a recall
Method
Not every device letter comes from CDRH
Practice
Closed on one device. Open on the rest.
Method
No IDE is confirmed until the PMA is
Practice
The remedial-action call sets the clock
Method
Jurisdiction is a letter, not a field
Practice
An address is not a footprint
Method
The final rule that isn't final yet
Practice
The special controls aren't in the record
Method
Exempt from GMP. Not from complaints.
Practice
The notify list isn't the shortage list
Method
A constraint can't be skipped. A script can.
Method
Corrected, not rewritten
Practice
Quiet is a finding, not a default
Method
The summary is public. The statement isn't.
Practice
A competitor's 513(g) leaves no trace
Practice
An empty response field proves nothing
Method
A petition is public. Its outcome isn't.
Practice
The panel is a category, not a meeting
Method
An accessory carries its own classification
Method
A TPLC report is a category, not a device
Practice
A 522 order is a question, not a verdict
Method
A PCCP change leaves no new record
Practice
Not every signal becomes a recall
Method
eSTAR did not remove the acceptance check
Practice
An early alert has no recall number yet
Practice
A consent decree isn't a database row
Method
The record has no cybersecurity field
Practice
Classification Change is not one event
Method
Publication date is not effective date
Method
One event. Many recall numbers.
Practice
Quantity is a sentence, not a number
Practice
How a firm told you is a field too
Method
A RIN outlives the document number
Method
The docket ID is not the comments
Practice
The 510(k) record doesn't name the predicate
Practice
The 510(k) FDA didn't review first
Method
The letter FDA doesn't have to post
Practice
Cleared doesn't say which track it took
Method
The clock stops. The calendar doesn't.
Method
Why a guessed match never reaches you
Practice
The standards list never names a device
Method
The guidance isn't in the Federal Register.
Practice
Filtered. Not discarded.
Method
There are two recall databases, not one
Practice
Breakthrough status is confidential by law
Practice
One MAUDE report is not one malfunction
Method
A supplement number is not a track
Method
Cleared is not approved
Practice
Nationwide doesn't mean your building
Practice
Not every correction reaches FDA
Method
Registered. Not reviewed.
Method
Contact ODE is not a pathway
Practice
Almost no recall is FDA-mandated
Method
FDA's device names read like a card catalog
Practice
openFDA is free. It is not unlimited.
Method
GUDID stores the model. Not the box.
Practice
Detention doesn't need a warning letter
Method
A Class I device, a Class I recall
Practice
21 CFR 820 didn't move. Its contents did.
Method
The product code that doesn't exist yet
Practice
The classification posts. The 483 behind it doesn't.
Method
A recall has three dates, and the pipeline had to pick one
Practice
The count is real. The rate is not.
Method
The firm on the record is not the firm on the box
Practice
Low confidence is an instruction, not a hedge
Method
The same company, spelled three ways
Practice
A device that was never a medical device
Method
FDA's warning letters, addressed by column number
Practice
Your regulation has a decimal. FDA's watch doesn't.
Method
Three letters is too short to search for
Practice
Most warning letters never close
Method
The guidance that skipped the draft
Practice
Ongoing, as of when?
Method
The least interesting fact in a 510(k)
Practice
No recall arrives with a product code attached
Practice
The deadline that doesn't email you
Method
The warning letter has two dates
Method
How to monitor FDA without drowning
Practice
Your predicate was recalled. Now what?
Method
Why no item reaches you without a human