Compliance · Access controlUpdated September 28, 2026

Role-based access control for clinical trials

Who can enter data, who can verify it, who can see names, who knows the treatment arm: access control is how a trial protects data integrity, privacy and blinding at the same time. Capture enforces it by role, by site and at the database layer.

  • Seven study roles
  • Site-level separation
  • Blinded and unblinded access

Free sandbox · No credit card · 21 CFR Part 11 aligned

Who does what · Study CAP-201
CoordinatorMonitorData managerPI
Enter visit data
Verify source data
Freeze and lock data
Sign off the casebook
Each role sees its own tasks and permissions

Key points

  • 21 CFR Part 11 expects systems to limit access to authorised individuals and to use authority checks so only permitted people can perform specific actions.
  • ICH GCP expects sponsors to maintain a list of individuals authorised to make data changes and to protect data security.
  • Privacy laws such as HIPAA and GDPR add minimum necessary access and data minimisation: people should see only the personal data their role needs.
  • Randomised trials add blinding: most users must never see the treatment arm.
  • Capture provides seven study roles (study owner, principal investigator, sub-investigator, study coordinator, monitor, data manager and participant), plus blinded and unblinded access.

How it works

Three layers of access control

Good access control in a trial works at three levels. Role decides what someone can do: enter data, raise queries, verify, lock, sign. Site decides whose data they can see: a coordinator at one hospital should never see another hospital's participants. Identity decides whether they see who the participant is: site staff need names to run visits, while sponsor-side reviewers work with coded participant IDs.

In Capture, site coordinators see only their own site, identifying information is segregated from study data, and row-level security enforces the separation at the database layer, not only in the screens. That matters because a rule enforced only in the user interface can be bypassed; a rule enforced in the database cannot.

Blinding

Blinded roles never receive the treatment arm from the server, not even in the data behind the screen. An unblinded administrator handles unblinded work such as the randomisation and medication lists, investigators keep emergency unblinding, and the study owner can approve an unblinding request without seeing the answer. See RTSM software.

Site coordinator

Jane Peterson

DOB: 04-Mar-1978

Subject 01-004

Sees direct identifiers

Researcher

Subject 01-004

DOB: withheld

Coded ID only

Sees coded ID only

Same record, two roles. Row-level security enforces the split.

Requirements

Regulatory expectations and the controls that meet them

ExpectationControl
Access limited to authorised individuals (Part 11)Individual accounts, study roles, site-level separation
Authority checks for specific actions (Part 11)Role permissions for entry, verification, locking and signing
List of people authorised to change data (GCP)User and role records, aligned with the delegation log
Minimum necessary personal data (HIPAA, GDPR)Coded participant IDs for sponsor-side users; names only where needed
Blinding protectedBlinded and unblinded roles; treatment arm never sent to blinded users
Accountability for every changeField-level audit trail with user, time and reason

In Capture

The right work for the right person

Each role sees its own tasks and permissions. Site staff enter data, monitors verify, data managers freeze and lock, and only the principal investigator signs off the casebook. Electronic signatures require password re-authentication, and every action is attributed to an individual in the audit trail.

  • Seven study roles plus blinded and unblinded access.
  • Site coordinators see only their own site.
  • Row-level security at the database layer.
21 CFR Part 11 compliant EDC
  • SO

    Study owner

    Builds and configures the study

  • PI

    Principal investigator

    Oversees the site, signs off the casebook

  • SI

    Sub-investigator

    Enters and signs clinical data

  • SC

    Study coordinator

    Screens subjects, enters visit data

  • CRA

    Monitor (CRA)

    Verifies data, raises queries

  • DM

    Data manager

    Reviews, freezes and locks data

  • PT

    Participant

    Completes their own questionnaires

Open the same participant as different roles

Compare what a coordinator, a monitor and a blinded user see in the free sandbox.

Explore roles in the sandbox

Access over time

Granting, reviewing and removing access

Access control is not a one-time setup. People join and leave, change roles, move between sites. The common inspection findings are predictable: a coordinator who left months ago still has an active account, a monitor has data entry rights, a user has a role that does not match the tasks delegated on the site's log. Align system access with the delegation log: nobody gets a role before they are trained and delegated, and access ends the day delegation ends.

Schedule periodic access reviews, for example at each monitoring visit or quarterly, comparing active users and roles with the delegation logs and study team lists. Record the review and any changes. The audit trail then shows not only who did what, but that they were entitled to do it.

Setup

Access control checklist

Role design

Roles mapped to delegated tasks for each site.

Individual accounts

No shared logins, ever.

Identity separation

Who sees participant names, and who sees coded IDs.

Blinding plan

Blinded and unblinded users and emergency unblinding.

Onboarding and offboarding

Access granted after training; removed when delegation ends.

Periodic review

Users and roles checked against delegation logs.

FAQ

Questions teams ask before they switch

Something not covered here? Ask us directly.

What is role-based access control in a clinical trial?

Controlling what each user can see and do according to their study role, site and need to know.

What roles does Capture support?

Study owner, principal investigator, sub-investigator, study coordinator, monitor (CRA), data manager and participant, plus blinded and unblinded access.

Can site coordinators see other sites' data?

No. Site coordinators see only their own site.

Who sees participant names?

Identifying information is segregated from study data. Site staff see names; sponsor-side reviewers work with coded participant IDs.

How is blinding protected?

Blinded roles never receive the treatment arm from the server. An unblinded administrator handles unblinded tasks, and investigators keep emergency unblinding.

Is access control enforced only in the interface?

No. Row-level security enforces separation at the database layer.

Access control enforced where it counts

Roles, sites and blinding at the database layer. Free sandbox.

Explore roles in the sandbox