Who can enter data, who can verify it, who can see names, who knows the treatment arm: access control is how a trial protects data integrity, privacy and blinding at the same time. Capture enforces it by role, by site and at the database layer.
Free sandbox · No credit card · 21 CFR Part 11 aligned
| Coordinator | Monitor | Data manager | PI | |
|---|---|---|---|---|
| Enter visit data | ||||
| Verify source data | ||||
| Freeze and lock data | ||||
| Sign off the casebook |
Key points
How it works
Good access control in a trial works at three levels. Role decides what someone can do: enter data, raise queries, verify, lock, sign. Site decides whose data they can see: a coordinator at one hospital should never see another hospital's participants. Identity decides whether they see who the participant is: site staff need names to run visits, while sponsor-side reviewers work with coded participant IDs.
In Capture, site coordinators see only their own site, identifying information is segregated from study data, and row-level security enforces the separation at the database layer, not only in the screens. That matters because a rule enforced only in the user interface can be bypassed; a rule enforced in the database cannot.
Blinded roles never receive the treatment arm from the server, not even in the data behind the screen. An unblinded administrator handles unblinded work such as the randomisation and medication lists, investigators keep emergency unblinding, and the study owner can approve an unblinding request without seeing the answer. See RTSM software.
Site coordinator
Jane Peterson
DOB: 04-Mar-1978
Subject 01-004
Sees direct identifiersResearcher
Subject 01-004
DOB: withheld
Coded ID only
Sees coded ID onlySame record, two roles. Row-level security enforces the split.
Requirements
| Expectation | Control |
|---|---|
| Access limited to authorised individuals (Part 11) | Individual accounts, study roles, site-level separation |
| Authority checks for specific actions (Part 11) | Role permissions for entry, verification, locking and signing |
| List of people authorised to change data (GCP) | User and role records, aligned with the delegation log |
| Minimum necessary personal data (HIPAA, GDPR) | Coded participant IDs for sponsor-side users; names only where needed |
| Blinding protected | Blinded and unblinded roles; treatment arm never sent to blinded users |
| Accountability for every change | Field-level audit trail with user, time and reason |
In Capture
Each role sees its own tasks and permissions. Site staff enter data, monitors verify, data managers freeze and lock, and only the principal investigator signs off the casebook. Electronic signatures require password re-authentication, and every action is attributed to an individual in the audit trail.
Study owner
Builds and configures the study
Principal investigator
Oversees the site, signs off the casebook
Sub-investigator
Enters and signs clinical data
Study coordinator
Screens subjects, enters visit data
Monitor (CRA)
Verifies data, raises queries
Data manager
Reviews, freezes and locks data
Participant
Completes their own questionnaires
Compare what a coordinator, a monitor and a blinded user see in the free sandbox.
Access over time
Access control is not a one-time setup. People join and leave, change roles, move between sites. The common inspection findings are predictable: a coordinator who left months ago still has an active account, a monitor has data entry rights, a user has a role that does not match the tasks delegated on the site's log. Align system access with the delegation log: nobody gets a role before they are trained and delegated, and access ends the day delegation ends.
Schedule periodic access reviews, for example at each monitoring visit or quarterly, comparing active users and roles with the delegation logs and study team lists. Record the review and any changes. The audit trail then shows not only who did what, but that they were entitled to do it.
Setup
Roles mapped to delegated tasks for each site.
No shared logins, ever.
Who sees participant names, and who sees coded IDs.
Blinded and unblinded users and emergency unblinding.
Access granted after training; removed when delegation ends.
Users and roles checked against delegation logs.
Controlling what each user can see and do according to their study role, site and need to know.
Study owner, principal investigator, sub-investigator, study coordinator, monitor (CRA), data manager and participant, plus blinded and unblinded access.
No. Site coordinators see only their own site.
Identifying information is segregated from study data. Site staff see names; sponsor-side reviewers work with coded participant IDs.
Blinded roles never receive the treatment arm from the server. An unblinded administrator handles unblinded tasks, and investigators keep emergency unblinding.
No. Row-level security enforces separation at the database layer.
Keep exploring
Roles, sites and blinding at the database layer. Free sandbox.