eTMF roles and permissions
Review status
Section titled “Review status”Proposed Core catalogue and reviewable Role templates. eTMF defines each TMF feature and action. Platform maintains Role revisions, assignments, authentication and access evidence.
Access principle
Section titled “Access principle”An eTMF Role describes permitted product work; it is not the same as a business responsibility such as Sponsor TMF Owner or Functional Record Owner. A person may hold a business responsibility without an account, and an account receives no eTMF access until an effective Role assignment is granted.
Every eTMF action requires:
- an active authenticated Principal;
- an effective eTMF Access Assignment for the relevant Study/Country/Site area;
- the exact feature action in the assigned Role Revision;
- permission for the record’s privacy, blinding, confidentiality and inspection classifications;
- any required independence or responsible-function prerequisite; and
- a valid eTMF record state.
eTMF Role templates
Section titled “eTMF Role templates”| Role template | Familiar responsibility | Typical access area |
|---|---|---|
| eTMF Study Administrator | Establish the Study TMF, responsibility model and controlled locations | Study |
| TMF Lead | Maintain the Filing Plan, expectations, reconciliation, metrics and readiness | Study |
| Functional Record Owner | Oversee records expected from one function and decide functional corrections | Study or defined functional area |
| Record Contributor | Submit documents and respond to returned content/findings | Study, Country or Site |
| Classifier / Indexer | Classify content, maintain metadata and propose filing placements | Study, Country or Site |
| QC Reviewer | Perform assigned quality-control rounds and verify corrections | Study, Country or Site |
| Document Approver / Finalizer | Approve content where required and finalize an exact Document Version | Study or functional area |
| Unblinded TMF User | Work with specifically classified unblinded records | Declared Study area |
| Inspection Coordinator | Assess readiness, prepare disclosure sets and manage controlled inspection access | Study |
| Inspector / Auditor | Read the approved disclosure set and permitted evidence | One inspection/audit scope |
| Archivist | Reconcile, archive, retrieve, transfer custody and administer retention controls | Study/archive area |
| eTMF Read-only Reviewer | View permitted TMF records, status and measures | Study, Country or Site |
| eTMF Integration Account | Submit or reference declared external records only | Exact connection/study scope |
These templates should be copied and narrowed where local responsibilities differ. No template bypasses independence, blinding, privacy or record-state rules.
Maintenance action meanings
Section titled “Maintenance action meanings”| Column | Meaning in eTMF |
|---|---|
| View | See the permitted TMF record, metadata, work status or measure |
| Create | Establish a new draft, intake item, request or controlled record |
| Change | Correct or maintain the allowed current information through retained revisions |
| Remove | Remove only an unused draft or rejected intake item where policy explicitly permits it |
Final, superseded, withdrawn, disclosed or archived records are never destroyed through generic Remove permission. They use named correction, withdrawal, supersession, retention and destruction actions.
Reference model and filing-plan catalogue
Section titled “Reference model and filing-plan catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| Reference Model candidate | Yes | Import/create candidate | Draft only | Draft only | validate, publish, retire release | eTMF Study Administrator or taxonomy administrator |
| Zone/Section/Artifact definitions | Yes | Candidate only | Candidate only | Candidate only | map prior release, approve local extension | Taxonomy administrator |
| Organization filing taxonomy | Yes | Yes | New revision | No | approve, make effective, retire | eTMF Study Administrator |
| Study TMF | Yes | Yes | Governed correction | No | establish, close conduct phase, transfer responsibility | eTMF Study Administrator |
| TMF Plan Revision | Yes | Yes | Draft only | Draft only | submit, approve, make effective, supersede | TMF Lead, eTMF Study Administrator |
| Record Location | Yes | Yes | Correct with history | No | verify retrieval, suspend, retire, transfer responsibility | TMF Lead, Archivist |
| Filing Plan Revision | Yes | Yes | Draft only | Draft only | validate, approve, reconcile, make effective, supersede | TMF Lead |
| Filing Plan Reconciliation | Yes | Generate | Resolve mappings | No | approve carried/new/retired/decision-required outcomes | TMF Lead, required functional reviewers |
| Document Expectation | Yes | From effective plan | Through plan revision | No | decide applicability, change count through plan revision | TMF Lead |
| Filing Slot | Yes | From expectation | No generic change | No | link candidate evidence, accept fulfilment, retire through reconciliation | TMF Lead, Classifier |
| Exception Decision | Yes | Request | Add evidence/conditions | No | approve, reject, return, revoke, supersede, expire | Declared accountable Roles |
Approval and effectiveness are separate. A person who can draft the Filing Plan does not automatically receive the action to approve it or make it effective.
Intake, document and filing catalogue
Section titled “Intake, document and filing catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| Intake Item | Yes | Submit | Add intake details | Rejected/uncommitted only | accept for triage, return, reject, quarantine | Record Contributor, Classifier |
| Duplicate Candidate | Yes | System/reviewer | Add assessment evidence | No | decide exact duplicate, business duplicate, related, or not duplicate | Classifier / Indexer |
| TMF Document | Yes | Yes | Stable identity correction only | No | mark entered in error, create successor, withdraw | Classifier; restricted withdrawal Role |
| Document Version | Yes | Yes | New version only | Draft only | submit for QC, reject, finalize, supersede | Record Contributor; Finalizer for finalization |
| Content component | Yes | Add to draft version | Replace through new version | Draft only | verify availability/readability | Record Contributor, Classifier |
| Classification Revision | Yes | Yes | New revision | No | propose, confirm, supersede | Classifier / Indexer |
| Metadata Revision | Yes | Yes | New revision | No | propose, confirm, supersede | Classifier / Indexer |
| Filing Placement | Yes | Propose | No in-place edit | No | activate after finalization, end, replace, reject | Classifier / Indexer, Finalizer where required |
| Evidence Set | Yes | Assemble candidate | Reconcile candidates | No | accept for one Filing Slot, replace accepted set | TMF Lead / authorized classifier |
| Externally Held Record Reference | Yes | Yes | New verified reference | No | verify retrieval, accept for fulfilment, mark unavailable, replace | Functional Record Owner, TMF Lead |
| Rendition | Yes | Generate | No | Draft failed rendition only | verify fidelity, approve use | Classifier / authorized service |
| Certified Copy Attestation | Yes | No generic create | No | No | certify exact copy, revoke/replace invalid certification | Qualified verifier or validated process identity |
“Change TMF Document” never means replacing final content. Content correction creates another Document Version; metadata or classification correction creates another governed revision.
Quality-control catalogue
Section titled “Quality-control catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| QC Criterion/Checklist | Yes | Draft | Draft/new revision | Draft only | approve, make effective, retire | TMF Lead, Quality administrator |
| QC Request | Yes | Yes | Assign/due date | Cancel with reason only | assign, acknowledge, start, cancel | TMF Lead, Functional Record Owner |
| QC Round | Yes | Created from request | Results only while open | No | start, record criterion results, require correction, pass, close | QC Reviewer |
| Criterion Result | Yes | Yes | Before round decision | No | pass, fail, not applicable with reason | QC Reviewer |
| Quality Finding | Yes | Yes | Status, assignment, evidence | No | assign, respond, submit correction, verify, close, reopen, accept non-issue | Reviewer; Contributor responds |
| Quality Decision | Yes | No generic create | No | No | pass or fail exact reviewed evidence | QC Reviewer |
| Functional Approval | Yes | No generic create | No | No | approve, reject, withdraw approval | Document Approver |
| Finalization Decision | Yes | No generic create | No | No | finalize exact version/revisions/placement after prerequisites | Document Finalizer |
Required independence
Section titled “Required independence”The Filing Plan declares where independent review is required. A contributor who submitted a record cannot satisfy an independent QC or approval requirement merely because they also hold a reviewer Role. The access decision may allow the feature, while eTMF refuses the action because separation of duties fails.
Measures, inspection and archive catalogue
Section titled “Measures, inspection and archive catalogue”| Feature | View | Create | Change | Remove | Named actions requiring separate permission | Typical Roles |
|---|---|---|---|---|---|---|
| Completeness snapshot | Yes | Generate | No | No | approve/report declared snapshot | TMF Lead, Read-only Reviewer |
| Timeliness snapshot | Yes | Generate | No | No | approve/report declared snapshot | TMF Lead |
| Quality snapshot | Yes | Generate | No | No | approve/report declared snapshot | TMF Lead, Quality reviewer |
| Inspection Readiness Assessment | Yes | Yes | Add actions/limitations | No | conclude ready/not ready for exact scope and time | Inspection Coordinator |
| Inspection Request | Yes | Yes | Scope/due details with history | No | accept, refuse, close | Inspection Coordinator |
| Disclosure Set | Yes | Assemble | Add governed supplement | No | approve, freeze disclosed set, supplement, close | Inspection Coordinator; approval may be separate |
| Inspection Access | Separate permission | Request | Time/scope only through new decision | No | approve, activate, suspend, end | Access administrator + Inspection Coordinator |
| Inspection Export | Separate permission | Request | No | No | generate, verify, release | Inspection Coordinator |
| Archive Package | Yes | Prepare | Reconciliation/addendum | No | approve archive, archive, verify retrieval, add governed addendum | Archivist, TMF Lead for approval |
| Archive Custody | Yes | Establish | Transfer through retained decision | No | transfer, accept custody, change location | Archivist |
| Retention Obligation | Yes | Register | Supersede with evidence | No | apply, recalculate end, close obligation | Records policy/Archivist Role |
| Retention Hold | Yes | Request | Evidence/conditions | No | approve, release, supersede | Legal/Records authorized Role |
| Destruction | Yes | Request | No | No | independently approve, execute, certify | Qualified Archivist + required approver |
| TMF Export Package | Yes | Request | No | No | generate, verify, release, acknowledge receipt | TMF Lead, Archivist, Inspection Coordinator by purpose |
An Inspector Role is read-only and limited to the approved Disclosure Set. It does not receive general Study TMF visibility, and access activity remains attributable.
Visibility classifications
Section titled “Visibility classifications”eTMF combines Study/Country/Site area with record classifications:
| Classification | Access effect |
|---|---|
| Sponsor-managed record | Visible according to assigned study/function/scope |
| Investigator-controlled record | Sponsor sees only the permitted reference or transferred record; responsibility does not imply unrestricted access |
| Blinded record | Only Roles compatible with the blinded view |
| Unblinded record | Requires explicit unblinded feature visibility |
| Direct participant identifiers | Refused from ordinary sponsor TMF use; quarantine and privacy response actions are separately controlled |
| Confidential/legal record | Restricted to the declared functional or legal access group |
| Inspection disclosure | Visible only within the approved set and access period |
| Archived record | Read-only through archive/inspection permissions; ordinary filing actions remain unavailable |
Visibility is applied before searches, counts, expected-document metrics, worklists and exports. A restricted record must not appear indirectly through a count, placeholder, filename or quality total.
Recommended Role-action boundaries
Section titled “Recommended Role-action boundaries”| Role | Must normally include | Must not imply |
|---|---|---|
| Record Contributor | submit content, see own returned items/findings, respond | QC pass, finalization, plan approval, inspection access |
| Classifier / Indexer | classify, correct metadata, propose/activate permitted placement | content approval or QC independence automatically |
| QC Reviewer | assigned QC rounds, findings and verification | content replacement, filing-plan change, archive destruction |
| Functional Record Owner | expectations for function, contributor coordination, correction decisions | unrestricted access to other functions or unblinded records |
| TMF Lead | filing plan, reconciliation, expectations, measures and readiness | automatic independent approval of own submissions |
| Document Finalizer | finalization after exact prerequisites | editing final content in place |
| Inspector / Auditor | read approved disclosure set and permitted export | file, correct, finalize or see outside disclosure scope |
| Archivist | archive, custody, retrieval, retention administration | release a hold or destroy without required independent approval |
Rules that must always hold
Section titled “Rules that must always hold”- Every eTMF feature action has a stable published meaning and compatible access areas.
- View, export, inspection access, QC, approval, finalization, archive and destruction are separate permissions.
- Create, Change and Remove never imply approve, finalize, file, fulfil or destroy.
- Remove applies only to explicitly permitted drafts or rejected intake; regulated history is retained.
- Record visibility evaluates Study/Country/Site, functional responsibility, privacy, confidentiality and blinding.
- Visibility is applied before search, counts, metrics, worklists and export.
- A Role cannot bypass independent-review or separation-of-duty rules.
- An active filing placement pins the exact finalized Document Version, classification and metadata revisions.
- An Inspector receives a controlled disclosure set, not unrestricted eTMF access.
- Archive destruction requires expiry of all obligations, release of all holds, exact permission, required independent approval and a retained destruction certificate.
- Business responsibility does not grant application access.
- Product action-catalogue revisions never silently expand existing Roles.
Verification scenarios
Section titled “Verification scenarios”Contributor also holds QC Role
Section titled “Contributor also holds QC Role”The Principal has both Roles for the Study. They submitted the Document Version. The applicable QC Request requires independent review, so eTMF refuses their attempt to pass the round and routes it to another qualified reviewer. Both the permission result and separation-of-duty refusal remain visible.
Blinded reviewer searches for an unblinded record
Section titled “Blinded reviewer searches for an unblinded record”The reviewer has Study-wide QC permission but no unblinded action. The record is excluded before search and worklist counts are calculated. A copied URL cannot disclose the title, filename, existence or metadata.
Inspector access expires
Section titled “Inspector access expires”The authenticated session remains valid, but the time-limited Inspection Access Assignment has ended. Further reads and exports are denied. Earlier viewed/exported items remain in the inspection access history.
Filing plan editor cannot approve their revision
Section titled “Filing plan editor cannot approve their revision”The TMF Lead can create and change the draft. The organization requires independent plan approval, and the Role lacks the approval action. Platform denies the approval attempt; an authorized approver reviews the exact revision and reconciliation evidence.
Retention ends while a hold remains
Section titled “Retention ends while a hold remains”The Archivist can administer archive custody and request destruction. The active hold prevents destruction even if their Role includes execute-destruction. A separately authorized role must release the hold, and the complete approval chain is required before execution.
Shared Platform model
Section titled “Shared Platform model”See Authentication, roles and access for authentication, Role revisions, access areas, assignments, delegation, visibility evaluation and audit evidence.