EDC roles and permissions
Review status
Section titled “Review status”Proposed Core catalogue and reviewable Role templates. EDC defines the meaning of each feature and action. Platform maintains Role revisions, assignments, authentication and access evidence.
How to read this page
Section titled “How to read this page”An EDC Role is a bundle of actions, not a job title. The same person may receive different Roles for different studies or sites, and local organizations may copy and narrow the templates below.
Every allowed action still requires:
- an active authenticated Principal;
- an effective EDC Access Assignment for the relevant Study/Country/Site area;
- visibility through blinding and privacy rules;
- any declared training or business-responsibility prerequisite; and
- a valid EDC record state—for example, data must not be locked.
EDC Role templates
Section titled “EDC Role templates”| Role template | Familiar responsibility | Typical access area |
|---|---|---|
| EDC Study Administrator | Establish the EDC Study, activate EDC sites and coordinate design use | Workspace or Study |
| Study Designer | Build visits, CRFs, items, terminology, conditions, derivations and checks | Workspace library or Study |
| Design Approver | Review validation evidence and approve/publish a Study Design | Study |
| Site Data Entry | Create subjects/casebooks and enter or correct site-reported data | Study Site |
| Principal Investigator | Review and sign required subject data; may also have site data-entry access separately | Study Site |
| Monitor / SDV Reviewer | View permitted subject data and perform source data verification (SDV) | Study, Country or Site |
| Clinical Data Manager | Manage queries, data-management review, cleaning, reconciliation and readiness | Study, Country or Site |
| Medical Coder | Code configured verbatim terms and raise coding clarification queries | Study |
| Coding Approver | Independently approve or reject coding decisions where required | Study |
| Database Lock Approver | Review readiness and authorize whole-study database lock or reopen | Study |
| EDC Read-only Reviewer | View permitted data, work status and evidence without changing it | Study, Country or Site |
| EDC Integration Account | Submit or receive only the declared transfer actions | Exact connection/study scope |
Role names do not grant permissions. The published Role Revision contains the exact actions below.
Maintenance action meanings
Section titled “Maintenance action meanings”| Column | Meaning in EDC |
|---|---|
| View | See the feature and the permitted records/fields |
| Create | Establish a new record or draft occurrence |
| Change | Correct or maintain allowed information |
| Remove | Remove only an unused draft/empty occurrence where EDC explicitly permits it |
Submitted clinical data, completed query conversations, review evidence, coding decisions, signatures, freezes and locks are never hard-deleted through a generic Remove permission.
Study build and configuration catalogue
Section titled “Study build and configuration catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| EDC Study setup | Yes | Yes | Yes | Draft only | enable Study, retire future setup | EDC Study Administrator |
| Study Design Version | Yes | Yes | Draft only | Draft only | validate, submit for review, withdraw draft | Study Designer |
| Design Publication | Yes | No | No | No | approve, publish, retire from future assignment | Design Approver |
| Site Design Assignment | Yes | Yes | Yes | No | make effective, end future use | EDC Study Administrator |
| Casebook Design Adoption | Yes | Yes | Resolve conflicts | No | assess, approve, apply, reject | Clinical Data Manager, EDC Study Administrator |
| Periods and cycles | Yes | Draft | Draft | Draft only | validate repetition/limits | Study Designer |
| Visit/event schedule | Yes | Draft | Draft | Draft only | validate anchors/windows, approve dynamic behavior | Study Designer, Design Approver |
| CRF definitions and revisions | Yes | Draft | Draft | Draft only | validate, compare revisions | Study Designer |
| CRF placements | Yes | Draft | Draft | Draft only | validate visit-specific use | Study Designer |
| Item-group definitions/placements | Yes | Draft | Draft | Draft only | validate repetition and row identity | Study Designer |
| Item definitions/placements | Yes | Draft | Draft | Draft only | validate datatype, precision and clinical meaning | Study Designer |
| Codelists and unit lists | Yes | Draft | Draft | Unused draft | retire value, approve version | Study Designer, Design Approver |
| Conditions and requiredness | Yes | Draft | Draft | Draft only | validate applicability behavior | Study Designer |
| Derivations | Yes | Draft | Draft | Draft only | validate formula and recalculation policy | Study Designer |
| Edit checks | Yes | Draft | Draft | Draft only | validate, activate/deactivate through design publication | Study Designer, Design Approver |
| SDV/DM review plan | Yes | Yes | New plan revision | No | approve, assign, make effective | Clinical Data Manager |
| Coding plan | Yes | Yes | New plan revision | No | approve, assign, make effective | Clinical Data Manager, Coding Approver |
| Signature plan | Yes | Yes | New plan revision | No | approve, assign, make effective | EDC Study Administrator, Design Approver |
“Draft” means the action applies only before publication. A published design is corrected through a new version and controlled amendment adoption, not by retaining Change permission on live definitions.
Site, subject and casebook catalogue
Section titled “Site, subject and casebook catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| EDC Site Participation | Yes | Yes | Yes | No | activate, suspend, reactivate, close | EDC Study Administrator |
| Subject | Yes | Yes | Limited correction | No | correct subject number, mark entered in error | Site Data Entry; corrections may require Data Manager |
| Consent Confirmation | Yes | Yes | Governed correction | No | confirm valid consent basis, withdraw confirmation | Authorized Site Data Entry |
| Screening Attempt | Yes | Yes | Yes | Empty mistaken draft only | pass, screen fail, rescreen | Site Data Entry |
| Subject disposition | Yes | No | No generic change | No | enroll, complete, withdraw treatment, withdraw study, lost to follow-up, record death | Authorized Site Data Entry |
| Casebook | Yes | Created with subject | No generic change | No | create, adopt amendment, mark entered in error | Site Data Entry; Data Manager for adoption |
| Visit/event occurrence | Yes | Dynamic/unscheduled | Yes | Empty unused only | start, complete, reopen, record did-not-occur, resolve applicability conflict | Site Data Entry; Data Manager for reopen/conflict |
| CRF occurrence | Yes | Repeat/dynamic | Yes | Empty unused only | complete, reopen, intentionally leave blank | Site Data Entry; Data Manager for reopen |
| Repeating row | Yes | Yes | Yes | Empty unused only | mark duplicate/entered in error with retained history | Site Data Entry |
| Datapoint | Yes | Yes | Correct value | No | assert missing reason, correct with reason | Site Data Entry; source-specific integration account |
| Data audit history | Separate permission | No | No | No | export audit history | Monitor, Data Manager, Auditor |
Subject and casebook visibility is evaluated before lists, search, counts and exports. A Site-level Role cannot discover another Site’s subject numbers or query totals.
Cleaning, review, coding and signature catalogue
Section titled “Cleaning, review, coding and signature catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| Edit-check results | Yes | System/policy | Re-evaluate only | No | suppress with governed reason, reconcile after rule change | Clinical Data Manager |
| Data Query | Yes | Yes | Message/routing only | No | open, answer, reassign, escalate, return, close, cancel, reopen | Site answers; Data Manager/Monitor manages |
| Query administration | Yes | No | Routing | No | assign responder group, change priority, escalate ageing | Clinical Data Manager |
| SDV Requirement | Yes | Plan/policy | Governed override | No | require, waive with reason, reassess | Clinical Data Manager, Monitor |
| SDV Evidence | Yes | Yes | No | No | verify exact data revision, mark superseded | Monitor / SDV Reviewer |
| DM Review Requirement | Yes | Plan/policy | Governed override | No | require, waive with reason, reassess | Clinical Data Manager |
| DM Review Evidence | Yes | Yes | No | No | review exact data level, record outcome, supersede | Clinical Data Manager |
| Coding Request | Yes | Plan/policy | Assignment/status | No | assign, request clarification, cancel, complete, mark needs recoding | Medical Coder |
| Coding Decision | Yes | Yes | New decision revision | No | code, recode, supersede | Medical Coder |
| Coding Review | Yes | Yes | Decision only | No | approve, reject | Coding Approver |
| Dictionary-change assessment | Yes | Yes | Yes | No | start campaign, remap, retain noncurrent, close | Coding Approver, Medical Coder |
| Signature Requirement | Yes | Policy | Status from evidence | No | assign investigator, waive exceptional requirement, require re-signature | EDC Study Administrator; narrow waiver Role |
| Investigator Signature | Yes | No generic create | No | No | sign exact data and attestation after reauthentication | Principal Investigator only |
Separation rules
Section titled “Separation rules”- A site user may answer a query but cannot close it unless a separate close action is assigned.
- A coder may propose a code; independent approval requires the Coding Approver action.
- Only the identified investigator acting as themselves may sign an investigator attestation.
- A monitor’s SDV permission does not grant data correction.
- Viewing audit history, exporting it, and changing data are separate actions.
Freeze, lock and delivery catalogue
Section titled “Freeze, lock and delivery catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| Freeze | Yes | No generic create | No | No | freeze, unfreeze | Clinical Data Manager |
| Scoped Lock | Yes | No generic create | No | No | lock form/visit/casebook/site; request reopen; approve reopen; relock | Clinical Data Manager; Lock Approver for reopen approval |
| Database Lock Readiness | Yes | Generate assessment | Add disposition/exception | No | assess readiness, approve narrow exception | Clinical Data Manager, Database Lock Approver |
| Database Lock | Yes | No generic create | No | No | authorize and lock whole-study final database | Database Lock Approver |
| Database Reopen | Yes | Request | Impact/disposition | No | request, independently approve, reopen, relock | Data Manager requests; Lock Approver approves |
| Analysis Cut | Yes | Yes | No | No | generate declared interim/safety cut | Authorized Data Manager |
| Data Extract | Yes | Request | No | No | generate, approve release, download/export | Data Manager; separate export permission |
| Investigator retained copy | Yes | Request | No | No | generate, deliver, acknowledge review | Authorized Study/Site Role |
| End-of-study package | Yes | Request | No | No | approve, generate, verify delivery | Data Manager, Study Administrator |
No generic “Change casebook” permission can unlock data. Database reopen requires its own request and approval actions, and earlier lock evidence remains visible.
Visibility classifications
Section titled “Visibility classifications”EDC combines the assigned Study/Country/Site area with product classifications:
| Classification | Access effect |
|---|---|
| Site-reported subject data | Restricted to assigned sites unless broader sponsor/monitor access is granted |
| Blinded data | Visible only through Roles compatible with the blinded view |
| Unblinded treatment data | Requires an explicit unblinded action/Role; not implied by Study access |
| Direct identifiers | Generally excluded from sponsor EDC; any permitted use requires explicit purpose and field visibility |
| Coding content | Verbatim and dictionary output require coding feature visibility |
| Audit history | Separate view and export actions |
| Locked/final data | May remain viewable while all mutation actions are refused |
Field masking must not change the meaning of a signature, review or export. Every governed output identifies the visibility profile used.
Recommended Role-action boundaries
Section titled “Recommended Role-action boundaries”| Role | Must normally include | Must not imply |
|---|---|---|
| Site Data Entry | assigned-site subjects, casebooks, data entry, query answer | query close, SDV, coding approval, investigator signature, lock |
| Investigator | assigned-site review and sign | sponsor data-management actions or signature delegation |
| Monitor | assigned-site view, query open, SDV | source-data correction, DM review completion, coding, database lock |
| Clinical Data Manager | study cleaning, query management, DM review, freeze and readiness | investigator signature or automatic database-lock approval |
| Medical Coder | coding requests and decisions | site-data overwrite or coding approval unless separately assigned |
| Design Approver | review/approve/publish design | silently edit published design |
| Database Lock Approver | readiness review, lock/reopen approval | ordinary data correction |
Rules that must always hold
Section titled “Rules that must always hold”- Every EDC feature action has a stable published meaning and supported access-area types.
- View permission is required before an action can expose the target, but view alone grants no change.
- Create, Change and Remove never imply approve, sign, close, freeze, lock, reopen or export.
- Remove applies only to unused draft or empty structures explicitly allowed by EDC.
- Site scope is enforced before search, counts, worklists and export.
- Subject responsibility or Principal Investigator designation does not itself grant EDC access.
- A signature action requires the correct individual, current investigator responsibility, exact scope, current prerequisites and required authentication assurance.
- Every data change retains the originator; sponsor permissions do not authorize silent overwrite of site data.
- Role/action permission cannot bypass freeze, scoped lock, database lock or stale-version checks.
- Product action-catalogue revisions never silently add permissions to existing Roles.
Verification scenarios
Section titled “Verification scenarios”Site coordinator becomes an investigator
Section titled “Site coordinator becomes an investigator”The person already has Site Data Entry. Their new Principal Investigator responsibility does not add the signing action. An access administrator assigns the Investigator Role separately. Signature is still refused until the Signature Requirement is ready and reauthentication succeeds.
Monitor changes sites
Section titled “Monitor changes sites”The existing Site 101 Assignment is ended and a new Site 205 Assignment starts on the approved date. Historical SDV remains attributable. The monitor cannot see Site 205 early or Site 101 afterward merely because an old browser session remains open.
Data manager can clean but cannot lock
Section titled “Data manager can clean but cannot lock”The Data Manager Role allows query close, DM review and freeze. Database lock is absent. The lock request is denied by Platform permission before EDC evaluates readiness; an independently assigned Database Lock Approver must perform the decision.
A published design needs correction
Section titled “A published design needs correction”The designer has Change permission for design drafts. The published version remains uneditable. EDC requires another Design Version, approval, publication and adoption even though the same person can maintain drafts.
Shared Platform model
Section titled “Shared Platform model”See Authentication, roles and access for authentication, Role revisions, access areas, assignments, delegation, visibility evaluation and audit evidence.