A first trial is a sequence of decisions, not one big project. This roadmap walks a founding team from a signed-off idea to a locked database, and shows which parts you can run with a small team and a self-serve platform.
Free sandbox · No credit card · 21 CFR Part 11 aligned
Stage
Ethics or IRB review
Build and test in the sandbox
The short version
Stages 1 and 2
Every trial that works starts with a single question narrow enough to answer. Write it as a sentence a clinician and an investor would both understand: in this population, does this intervention change this outcome, measured this way, by this time? That sentence becomes your primary endpoint, and everything else in the study exists to measure it cleanly. Secondary and exploratory endpoints are useful, but each one adds forms, visits, queries and cost, so add them deliberately. The clinical trial endpoints entry explains the vocabulary.
The protocol is the document that turns the question into a procedure. First-time teams tend to write it as a scientific argument, when the people who use it daily need an instruction manual: who is eligible, what happens at each visit, what is measured and when, what counts as an adverse event, and what to do when something goes wrong. Our guide to how to write a clinical trial protocol covers structure and the SPIRIT 2025 checklist, and the protocol template gives you a starting skeleton.
Size the study honestly. A sample size calculation should come from the effect you expect and the variability you have evidence for, not from the number of participants you think you can afford. If the honest answer is larger than your budget, that is better learned now. A pilot or feasibility study is often the right first step, and how to run a pilot study explains what such a study can and cannot show.
The roadmap
Use this as a working checklist. Most stages overlap, but the order of the gates does not change.
One primary endpoint, a clear population, a comparator if there is one. Decide what would count as success before you see any data.
Include eligibility, interventions, visit schedule, safety reporting and statistical approach. Build the visit-by-assessment grid early: it drives your forms and your budget.
Requirements depend on the country, the product and the trial type. Confirm with your regulatory adviser; do not assume. The IRB submission checklist helps assemble the pack.
Public registration before first enrolment is the safe default. Registries, deadlines and what an applicable clinical trial is are covered in the registration guide linked above.
Build the eCRFs, edit checks, consent flow and any participant questionnaires, then test with sample data before real participants appear. This is the stage the sandbox is for.
Track screening and enrolment, resolve queries as they arise, review safety events promptly and keep the data clean while the study is running, not at the end.
Resolve open queries, confirm the data against the plan, lock the database, then export for the statistician. A data management plan agreed up front makes this stage routine.
Stages 4 and 5
Founders often defer the data system until the protocol is approved, then find the choice is urgent and the options are poor. A spreadsheet or general survey tool is quick, but it has no field-level audit trail, weak access control and no way to show an auditor who changed a value and why. A large enterprise system has the controls but usually comes with a sales cycle and an implementation project sized for a much bigger company. Neither is a good first answer.
Capture is a self-serve alternative: EDC, an eCRF builder, ePRO, eConsent and randomization in one system with one audit trail. You can upload a protocol as PDF or DOCX and let the AI study builder draft the visit schedule and forms, then review everything, because nothing is saved without human review. Edit checks raise an automatic query when a site enters a value that breaks a rule, forms move through a draft to approved lifecycle and are locked before live use, and the audit trail records timestamp, user, old value, new value and reason for change on every record. These are 21 CFR Part 11-aligned controls; compliance remains a shared responsibility, because you still need validated, documented use of the system. The computer system validation guide covers your side of that.
Because the sandbox is free and has no time limit, you can make this decision with a working study in front of you instead of a slide deck. Build two or three real forms from your protocol, enter sample data, trip an edit check, sign a test consent, and read the audit trail. If it handles your protocol, go live when your approvals are in. If it does not, you have lost nothing but an afternoon. See the EDC overview and platform overview for what is included.
Team and roles
You do not need a large team, but every role below has to be covered by someone, even if one person wears two hats.
| Responsibility | Typical owner in a startup | Where a tool helps |
|---|---|---|
| Scientific design and endpoints | Chief medical or scientific officer, with a statistician | Protocol template, sample size tools |
| Regulatory and ethics submissions | Regulatory lead or external adviser | Blank eCRF PDF export for submission packs |
| Investigator and site conduct | Principal investigator and site coordinators | Site coordinator portal, role-based access |
| Data capture and cleaning | Clinical data manager, or a trained operations lead | EDC, edit checks, auto-queries, exports |
| Safety review | Medical monitor or investigator | Adverse event forms, field-level audit trail |
| Participant consent and diaries | Site staff | eConsent and ePRO in the same system |
| Oversight and quality | Study lead | Audit trail review, by-site filtering |
Role names vary by organisation. What matters is that each responsibility has a named owner before first enrolment.
Build the study, enter sample data, test edit checks, e-signatures and the audit trail. Free sandbox, no credit card, pay only when you go live.
What goes wrong
The first is an over-ambitious protocol. Teams add endpoints, biomarkers and exploratory assessments because the participant is already in the clinic. Each addition is another form to design, another field to query and another reason a visit runs long. A leaner protocol is easier to recruit for, cheaper to run and less likely to need an amendment.
The second is treating registration, ethics and data setup as sequential when they can run in parallel, or as optional when they cannot be skipped. Registration is a good example: it is quick to do early and awkward to explain if done late. The third is under-planning data management. If nobody has written down how queries are raised, who resolves them, how fast, and when the database locks, the answer will be improvised at the worst moment.
The fourth is losing control of the data system. If a vendor builds your forms and charges for every amendment, small protocol changes become negotiations. Self-serve builds keep that control in your team, and protocol amendments without change orders explains how an approved-form lifecycle handles changes. The fifth is leaving the audit trail until an inspector or investor asks. Decide up front who can see and change what, then check the audit-ready clinical trial data guide.
Before the first participant
Confirm requirements with your regulatory adviser; keep the approved documents in your trial master file.
Done before first enrolment as the safe default; record the registry identifier in your protocol and study files.
In Capture, only approved forms appear in the casebook, so test, approve, then go live.
Enter deliberately wrong values in the sandbox and confirm the auto-query fires.
Run a test participant through eConsent, including countersignature, and export the signed PDF.
Site staff see participant names; researchers see coded IDs. Assign before the first record exists.
Query handling, cleaning cadence and lock criteria written down; start from the template.
Resourcing
Costs concentrate in a few places: site and investigator fees, participant visits and procedures, monitoring, data management, and any product manufacturing or supply. Software is rarely the largest line, but a tool that charges per change or per module can quietly grow. Start from your schedule of assessments and the clinical trial budget template, and read how much does a clinical trial cost for how the money actually distributes. If money is the main constraint, the guide to running a clinical trial on a small budget goes through the levers.
On outsourcing, the honest answer is that it depends on what you lack. If you have no experience of site management, safety reporting or regulatory submissions, a CRO may be worth its cost for those pieces. If you have the clinical expertise and need a data system, you may not need one for data capture at all. How to choose a CRO and how to run a clinical trial without a CRO set out both paths.
Whatever you decide, keep the phase in view. Capture is used across Phase 1, 2 and 3, so a system chosen for the first small study does not have to be replaced when the trial grows. The point of the roadmap is to make each decision once, with evidence, rather than twice under pressure.
Work through seven stages: define the question and primary endpoint, write the protocol, obtain ethics or IRB approval and any regulatory clearance, register the trial, set up and test your data system, enrol and monitor, then clean and lock the database. Most stages overlap, but approvals and registration come before the first participant.
No. A CRO is a way to buy expertise or capacity you lack, such as site management, safety reporting or submissions. Teams with clinical experience often run data capture themselves on a self-serve platform. Decide task by task what to outsource.
Before enrolling the first participant is the safe default. ICMJE-following journals expect registration at or before first participant enrolment, and US rules for applicable clinical trials set a deadline of 21 days after the first participant is enrolled. This is general information, not legal advice; confirm with your regulatory adviser.
One with an audit trail, role-based access, e-signatures, edit checks and a way to lock forms for live use. Capture provides these with 21 CFR Part 11-aligned controls, and you can build and test a full study in the free sandbox before paying.
It depends mostly on approvals and the protocol, not on software. On the data side, you can upload a protocol to Capture's AI builder to draft visits and forms, review them, and test in the sandbox. There is no enterprise sales call required to start.
Capture is suitable for Phase 1, 2 and 3, so the system you choose for a first small study can continue as the trial program grows.
Building and testing in the sandbox is free, with every feature, no credit card and no time limit. You pay only once you go live with real participants. Talk to us for details for your study.
Keep exploring
How to write a clinical trial protocol
Structure, SPIRIT 2025 and buildable protocols.
ClinicalTrials.gov registration step by step
When and how to register.
How to choose a CRO
What to outsource and what not to.
How to run a clinical trial on a small budget
Cost levers for lean teams.
Clinical trial software for startup biotech
The software side for founders.
Clinical trial protocol template
A starting skeleton for your protocol.
Open the free sandbox, build your study, test everything with sample data and go live when your approvals are in. No credit card, pay only when live.