Quality assurance needs evidence: who did what, when, why, and whether they were allowed to. Capture records it by design, with an append-only audit trail, re-authenticated signatures and role-based access you can review and export.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Weight changed 68.0 to 68.5 kg
Site coordinator · Reason: Transcription error
Query Q-0014 answered on Weight
Site coordinator · Reason: Source checked
Vital signs form locked
Data manager · Reason: Visit cleaned
What QA teams look for
Audit trail
Every EDC claims an audit trail. The questions QA asks are more specific: is it field-level, does it include the reason for change, is it tamper-evident, can it be filtered and exported, and does it cover every module? In Capture, database triggers write the audit trail, one row per changed field. Updates and deletes are blocked, and each entry carries a hash of the one before it, so tampering breaks the chain.
Clinical data is never hard deleted, approved forms are locked for live use, and the audit trail covers EDC, ePRO, eConsent and randomisation in one study. See audit trail software for clinical trials.
Part 11 compliance depends on how a system is configured and used, not only on the software. Sponsors usually complete a risk-based validation and user acceptance testing on the vendor's platform. Capture provides documentation to support sponsor validation and UAT on Enterprise plans.
Weight changed 68.0 to 68.5 kg
Site coordinator · Reason: Transcription error
Query Q-0014 answered on Weight
Site coordinator · Reason: Source checked
Vital signs form locked
Data manager · Reason: Visit cleaned
Evidence
| Question | Evidence in Capture |
|---|---|
| Who changed this value, when and why? | Field-level audit trail with user, time, old and new value and reason |
| Can the audit trail be altered? | Append-only; updates and deletes blocked; hash chain |
| Was the signer authenticated? | Password re-authentication with a meaning statement |
| Was consent properly obtained? | Signed consent PDF with signature data, timestamps and audit trail |
| Who could see or change data? | Roles with site-level separation; identifying data segregated |
| Was the blind protected? | Blinded roles never receive the treatment arm from the server |
Signatures
Investigator signatures require password re-authentication and carry a legal meaning statement. Participant eConsent signatures are verified with an email one-time code after a legal-binding acknowledgement, and each signature is cryptographically linked to the exact document content at signing.
Meaning of signature
I have reviewed this adverse event and confirm the assessment of seriousness, severity and causality.
Signer
Dr. A. Ozola, PI
Password
••••••••••
Change a value in the free sandbox and read the record.
Vendor qualification
QA usually qualifies a new eClinical vendor with a questionnaire, a documentation review and sometimes an audit. Typical topics are the vendor's quality system, software development and testing, change control, security, hosting, backups, incident management and support. Prepare the questions before the demo, and ask for evidence rather than assurances.
Our vendor security questionnaire guide lists the questions to ask, and the computer system validation guide covers the sponsor side of validation.
Trend review
Beyond individual records, QA looks for patterns: a site with many protocol deviations, unusually few queries, late data entry, or clusters of changes to key data after monitoring visits. These trends point to training needs, process problems or, occasionally, data integrity issues that need investigation and corrective action.
Structured deviation records, the query list with status and age, and an audit trail filterable by user, participant and date make those reviews practical. See protocol deviation tracking software.
QA review
Change, correct and query a value; review the record.
Sign as an investigator; check re-authentication.
Compare roles with delegated tasks.
View the same participant as blinded and unblinded users.
What the vendor provides and what you must do.
Pull records for one participant and date range.
Yes. Deviation records, the query list and the audit trail can be filtered and exported for trend review.
Yes, by category, user, participant and date.
No. Updates and deletes are blocked, and each entry carries a hash of the previous one, so tampering breaks the chain.
Yes. Each change records the user, time, old value, new value and reason.
Documentation to support sponsor validation and UAT is available on Enterprise plans.
Investigator signatures require password re-authentication and carry a meaning statement.
Clinical data is never hard deleted; changes are recorded in the audit trail.
Yes. The free sandbox includes every feature and sample data.