In a blinded trial, almost everyone must never learn the treatment arm, and a few people must. Capture withholds the arm from blinded roles at the database, with masked views and row-level security, so blinding does not depend on a hidden column.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Study coordinator
Subject 01-004
Randomized · R-0012
KitK-10418
Arm columnNot sent
Unblinded administrator
Subject 01-004
Randomized · R-0012
KitK-10418
Arm columnA
Same subject, same screen. The arm never reaches blinded roles.
The short version
The problem
Blinding protects a trial from bias. If participants, investigators or assessors know who is on active treatment, they may rate outcomes, manage side effects or even record data differently. A double-blind design asks the people closest to the participant to stay ignorant of the arm, and ICH E6(R2) section 4.7 expects the investigator to break the code only in accordance with the protocol and to document and explain any premature unblinding to the sponsor, including accidental unblinding.
In practice, blinding is rarely broken by someone looking at a randomization list. It is broken by a side channel. A drug accountability listing that shows kit types, an adverse event form that shows the study drug, a CSV export that includes a "treatment" column a statistician forgot to drop, a screenshot in a support ticket, or a column hidden in the browser but still present in the response behind the page. Each of these is a data-system failure.
That is why role management in an EDC for blinded trials is more than a permissions table. The question is not only "which screens can this role open" but "which values does this role ever receive". A role that is blinded must not receive the arm in any response, view, export or report, whatever the screen shows.
How Capture enforces it
Blinded roles read study data through masked database views, and row-level security decides which rows and values each role can reach. The treatment arm is withheld before the data leaves the server, so there is nothing behind the screen to find.
| Blinded role | Unblinded Administrator | |
|---|---|---|
| Treatment arm in casebook | Treatment assignment blinded | Visible |
| Study drug on the AE form | Blinded | Visible |
| Drug accountability report | Blinded | Visible |
| Randomization list | ||
| Medication list |
Who knows what
Your protocol and blinding plan decide this. The table shows common arrangements, not rules.
| Who | Usually blinded? | Why |
|---|---|---|
| Site investigator, coordinator, outcome assessor | Blinded | They assess efficacy and safety and must not be influenced by the arm |
| Monitor | Blinded | Verifies source data without learning allocation |
| Data manager | Blinded | Cleans data and runs queries without learning the arm |
| Unblinded pharmacist or IP manager | Unblinded | Must know which kit goes to which participant |
| Randomization and list owner | Unblinded | Generates or uploads the list, and holds the codes |
| Sponsor safety, for individual case reporting | Unblinded for those cases | Expedited reports of suspected unexpected serious reactions usually need the arm for that case |
| Data monitoring committee and its statistician | Unblinded, by design | Reviews unblinded safety and efficacy outside the blinded team |
Capture provides the Unblinded Administrator role and emergency unblinding for investigators. Decide in advance how any unblinded outputs, for example for a data monitoring committee, will be produced and by whom.
Open the same sample subject as a blinded user and as an unblinded user in the free sandbox, and try an export with each role.
Role design
Capture provides seven study roles (study owner, principal investigator, sub-investigator, study coordinator, monitor, data manager and participant), with blinded and unblinded access on top, and separates site access and participant identity from data access. See role-based access control for clinical trials for the full model. The design principle for blinding is to keep the unblinded group as small as the protocol allows.
The Unblinded Administrator owns the randomization list and the medication list. Randomization lists can be generated with block size and seed or uploaded after your statistician prepares them. When the list is uploaded, the person who prepared it is by definition unblinded, so name them in your blinding plan. For list design, see block randomization software and the randomization list generator.
The study owner usually wants oversight of the whole trial without learning the arm. Capture supports this: the study owner can approve an unblinding request without seeing the answer. The approval decision and the unblinding are separated, which is useful when the person accountable for the study is also the person who must stay blinded.
Emergency unblinding
The protocol should limit unblinding to cases where knowing the arm changes clinical management, such as a serious event where treatment choice depends on it.
In Capture, the principal investigator and sub-investigators can unblind in an emergency. Record the delegation in your delegation log.
Where your process needs a second person, the study owner can approve an unblinding request without seeing the allocation.
ICH E6(R2) 4.7 expects premature unblinding to be documented and explained to the sponsor. Allocation is logged in the audit trail with who and when. Record the clinical reason in your own unblinding log.
Decide what happens to that participant's blinded assessments and how the blinded team is told, per your blinding plan.
Where blinding leaks
| Side channel | What to check | In Capture |
|---|---|---|
| Study screens | Does the casebook show the arm? | Blinded roles see "Treatment assignment blinded" |
| Safety forms | Does the AE form expose study drug? | Investigational product panel is blinded for blinded roles |
| Exports | Does a CSV include a treatment column? | Blinded roles receive exports without the arm; each export is logged with a blinded flag |
| Drug accountability | Do kit listings reveal kit type? | Accountability report and CSV are blinded for blinded roles |
| Browser inspection | Is the value in the response but hidden on screen? | Not sent: masked views and row-level security withhold it at the database |
| Audit review | Can reviewers see allocation events? | Allocation is logged in the audit trail; plan who reviews it |
Plans and next steps
Randomization and blinding are part of the same platform as the EDC, so there is no separate IRT system, no integration to maintain and no second audit trail. Blinded randomization and unblinded roles for your CRO and statistician are listed under the Full Platform plan on the pricing page, and Core includes simple randomization. Check the plan you need with us before you start, because the study design determines what you will use. Randomization currently runs from a single list per study, so if your design depends on stratification, talk to us first.
The fastest way to judge a blinding implementation is to try to break it. In the free sandbox, build a study with two arms, randomize a sample subject, then open the casebook, AE form, inventory and an export as a blinded user. See also clinical trial randomization software for randomization methods and workflow. If your protocol uses SUSAR reporting, plan how the unblinded case information reaches the people who report it, as covered in the SUSAR reporting page.
Blinded roles never receive treatment-arm values. They read data through masked database views, and row-level security controls access, so the value is not sent to the browser and hidden, it is withheld at the database.
The text "Treatment assignment blinded" in the casebook, on the adverse event form, in inventory and in exports.
A role that owns unblinded work such as the randomization list and the medication list, so that the blinded study team never handles them.
The principal investigator and sub-investigators can use emergency unblinding. The study owner can approve an unblinding request without seeing the answer, where your process calls for it.
Yes. Blinded roles receive exports with the treatment arm withheld, and every export is recorded in the export log with user, role, time, filters, row count and whether it was blinded.
Randomization currently runs from a single list per study. If your design needs stratification, talk to us before you start.
Yes. The free sandbox includes randomization and inventory with sample data, so you can open the same subject as a blinded and an unblinded user. You pay only once you go live with real participants.
Keep exploring
Randomize a sample subject and see the same record as a blinded and an unblinded user. No credit card, no time limit.