Randomization · Role managementUpdated October 10, 2026

Blinded and unblinded role management in your EDC

In a blinded trial, almost everyone must never learn the treatment arm, and a few people must. Capture withholds the arm from blinded roles at the database, with masked views and row-level security, so blinding does not depend on a hidden column.

  • Masked views and row-level security
  • Unblinded Administrator role
  • Emergency unblinding for investigators

Free sandbox · No credit card · 21 CFR Part 11 aligned

Study coordinator

Subject 01-004

Randomized · R-0012

Treatment assignment blinded

KitK-10418

Arm columnNot sent

Unblinded administrator

Subject 01-004

Randomized · R-0012

Treatment: Active (A)

KitK-10418

Arm columnA

Same subject, same screen. The arm never reaches blinded roles.

The short version

  • Blinded roles never receive treatment-arm values. This is enforced by masked database views and row-level security, not only by the screen.
  • Blinded users see "Treatment assignment blinded" in the casebook, on the AE form, in inventory and in exports.
  • An Unblinded Administrator role owns the medication list and the randomization list, so unblinded work stays away from the blinded study team.
  • Emergency unblinding is available to the principal investigator and sub-investigators, and the study owner can approve an unblinding request without seeing the answer.
  • Allocation is logged in the audit trail, and every export is recorded in the export log with whether it was blinded.

The problem

Blinding fails quietly, and usually through the data system

Blinding protects a trial from bias. If participants, investigators or assessors know who is on active treatment, they may rate outcomes, manage side effects or even record data differently. A double-blind design asks the people closest to the participant to stay ignorant of the arm, and ICH E6(R2) section 4.7 expects the investigator to break the code only in accordance with the protocol and to document and explain any premature unblinding to the sponsor, including accidental unblinding.

In practice, blinding is rarely broken by someone looking at a randomization list. It is broken by a side channel. A drug accountability listing that shows kit types, an adverse event form that shows the study drug, a CSV export that includes a "treatment" column a statistician forgot to drop, a screenshot in a support ticket, or a column hidden in the browser but still present in the response behind the page. Each of these is a data-system failure.

That is why role management in an EDC for blinded trials is more than a permissions table. The question is not only "which screens can this role open" but "which values does this role ever receive". A role that is blinded must not receive the arm in any response, view, export or report, whatever the screen shows.

How Capture enforces it

Masked at the database, not just hidden on the page

Blinded roles read study data through masked database views, and row-level security decides which rows and values each role can reach. The treatment arm is withheld before the data leaves the server, so there is nothing behind the screen to find.

  • Blinded roles never receive treatment-arm values from the server.
  • The casebook, AE form, inventory and exports all show "Treatment assignment blinded" to blinded roles.
  • The investigational product panel on the AE form is blinded for blinded roles.
  • The drug accountability report and its CSV export are blinded for blinded roles.
  • Every export is logged with user, role, time, filters, row count and whether it was blinded.
RTSM software for clinical trials
Same subject, two roles (demo study)
Blinded roleUnblinded Administrator
Treatment arm in casebookTreatment assignment blindedVisible
Study drug on the AE formBlindedVisible
Drug accountability reportBlindedVisible
Randomization list
Medication list
Illustrative layout. Role assignments are made per study by your team.

Who knows what

Typical blinded and unblinded work in a double-blind trial

Your protocol and blinding plan decide this. The table shows common arrangements, not rules.

WhoUsually blinded?Why
Site investigator, coordinator, outcome assessorBlindedThey assess efficacy and safety and must not be influenced by the arm
MonitorBlindedVerifies source data without learning allocation
Data managerBlindedCleans data and runs queries without learning the arm
Unblinded pharmacist or IP managerUnblindedMust know which kit goes to which participant
Randomization and list ownerUnblindedGenerates or uploads the list, and holds the codes
Sponsor safety, for individual case reportingUnblinded for those casesExpedited reports of suspected unexpected serious reactions usually need the arm for that case
Data monitoring committee and its statisticianUnblinded, by designReviews unblinded safety and efficacy outside the blinded team

Capture provides the Unblinded Administrator role and emergency unblinding for investigators. Decide in advance how any unblinded outputs, for example for a data monitoring committee, will be produced and by whom.

See blinding from both sides

Open the same sample subject as a blinded user and as an unblinded user in the free sandbox, and try an export with each role.

Start building your study free

Role design

Setting up roles so unblinded work stays small

Capture provides seven study roles (study owner, principal investigator, sub-investigator, study coordinator, monitor, data manager and participant), with blinded and unblinded access on top, and separates site access and participant identity from data access. See role-based access control for clinical trials for the full model. The design principle for blinding is to keep the unblinded group as small as the protocol allows.

The Unblinded Administrator owns the randomization list and the medication list. Randomization lists can be generated with block size and seed or uploaded after your statistician prepares them. When the list is uploaded, the person who prepared it is by definition unblinded, so name them in your blinding plan. For list design, see block randomization software and the randomization list generator.

The study owner usually wants oversight of the whole trial without learning the arm. Capture supports this: the study owner can approve an unblinding request without seeing the answer. The approval decision and the unblinding are separated, which is useful when the person accountable for the study is also the person who must stay blinded.

Emergency unblinding

Plan the unblinding procedure before the first participant

  1. 1

    Define when it is allowed

    The protocol should limit unblinding to cases where knowing the arm changes clinical management, such as a serious event where treatment choice depends on it.

  2. 2

    Name who can do it

    In Capture, the principal investigator and sub-investigators can unblind in an emergency. Record the delegation in your delegation log.

  3. 3

    Make the approval path explicit

    Where your process needs a second person, the study owner can approve an unblinding request without seeing the allocation.

  4. 4

    Document the reason

    ICH E6(R2) 4.7 expects premature unblinding to be documented and explained to the sponsor. Allocation is logged in the audit trail with who and when. Record the clinical reason in your own unblinding log.

  5. 5

    Review exposure afterwards

    Decide what happens to that participant's blinded assessments and how the blinded team is told, per your blinding plan.

Where blinding leaks

A checklist of side channels, and how each is handled

Side channelWhat to checkIn Capture
Study screensDoes the casebook show the arm?Blinded roles see "Treatment assignment blinded"
Safety formsDoes the AE form expose study drug?Investigational product panel is blinded for blinded roles
ExportsDoes a CSV include a treatment column?Blinded roles receive exports without the arm; each export is logged with a blinded flag
Drug accountabilityDo kit listings reveal kit type?Accountability report and CSV are blinded for blinded roles
Browser inspectionIs the value in the response but hidden on screen?Not sent: masked views and row-level security withhold it at the database
Audit reviewCan reviewers see allocation events?Allocation is logged in the audit trail; plan who reviews it

Plans and next steps

Where this sits in the product

Randomization and blinding are part of the same platform as the EDC, so there is no separate IRT system, no integration to maintain and no second audit trail. Blinded randomization and unblinded roles for your CRO and statistician are listed under the Full Platform plan on the pricing page, and Core includes simple randomization. Check the plan you need with us before you start, because the study design determines what you will use. Randomization currently runs from a single list per study, so if your design depends on stratification, talk to us first.

The fastest way to judge a blinding implementation is to try to break it. In the free sandbox, build a study with two arms, randomize a sample subject, then open the casebook, AE form, inventory and an export as a blinded user. See also clinical trial randomization software for randomization methods and workflow. If your protocol uses SUSAR reporting, plan how the unblinded case information reaches the people who report it, as covered in the SUSAR reporting page.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

How does Capture keep blinded users from seeing the treatment arm?

Blinded roles never receive treatment-arm values. They read data through masked database views, and row-level security controls access, so the value is not sent to the browser and hidden, it is withheld at the database.

What does a blinded user see instead of the arm?

The text "Treatment assignment blinded" in the casebook, on the adverse event form, in inventory and in exports.

What is the Unblinded Administrator role?

A role that owns unblinded work such as the randomization list and the medication list, so that the blinded study team never handles them.

Who can unblind a participant in an emergency?

The principal investigator and sub-investigators can use emergency unblinding. The study owner can approve an unblinding request without seeing the answer, where your process calls for it.

Are exports blinded?

Yes. Blinded roles receive exports with the treatment arm withheld, and every export is recorded in the export log with user, role, time, filters, row count and whether it was blinded.

Is stratified randomization supported?

Randomization currently runs from a single list per study. If your design needs stratification, talk to us before you start.

Can I test blinding before going live?

Yes. The free sandbox includes randomization and inventory with sample data, so you can open the same subject as a blinded and an unblinded user. You pay only once you go live with real participants.

Start building your study free

Randomize a sample subject and see the same record as a blinded and an unblinded user. No credit card, no time limit.

Start building your study free