Skip to content

eTMF roles and permissions

Proposed Core catalogue and reviewable Role templates. eTMF defines each TMF feature and action. Platform maintains Role revisions, assignments, authentication and access evidence.

An eTMF Role describes permitted product work; it is not the same as a business responsibility such as Sponsor TMF Owner or Functional Record Owner. A person may hold a business responsibility without an account, and an account receives no eTMF access until an effective Role assignment is granted.

Every eTMF action requires:

  • an active authenticated Principal;
  • an effective eTMF Access Assignment for the relevant Study/Country/Site area;
  • the exact feature action in the assigned Role Revision;
  • permission for the record’s privacy, blinding, confidentiality and inspection classifications;
  • any required independence or responsible-function prerequisite; and
  • a valid eTMF record state.
Role template Familiar responsibility Typical access area
eTMF Study Administrator Establish the Study TMF, responsibility model and controlled locations Study
TMF Lead Maintain the Filing Plan, expectations, reconciliation, metrics and readiness Study
Functional Record Owner Oversee records expected from one function and decide functional corrections Study or defined functional area
Record Contributor Submit documents and respond to returned content/findings Study, Country or Site
Classifier / Indexer Classify content, maintain metadata and propose filing placements Study, Country or Site
QC Reviewer Perform assigned quality-control rounds and verify corrections Study, Country or Site
Document Approver / Finalizer Approve content where required and finalize an exact Document Version Study or functional area
Unblinded TMF User Work with specifically classified unblinded records Declared Study area
Inspection Coordinator Assess readiness, prepare disclosure sets and manage controlled inspection access Study
Inspector / Auditor Read the approved disclosure set and permitted evidence One inspection/audit scope
Archivist Reconcile, archive, retrieve, transfer custody and administer retention controls Study/archive area
eTMF Read-only Reviewer View permitted TMF records, status and measures Study, Country or Site
eTMF Integration Account Submit or reference declared external records only Exact connection/study scope

These templates should be copied and narrowed where local responsibilities differ. No template bypasses independence, blinding, privacy or record-state rules.

Column Meaning in eTMF
View See the permitted TMF record, metadata, work status or measure
Create Establish a new draft, intake item, request or controlled record
Change Correct or maintain the allowed current information through retained revisions
Remove Remove only an unused draft or rejected intake item where policy explicitly permits it

Final, superseded, withdrawn, disclosed or archived records are never destroyed through generic Remove permission. They use named correction, withdrawal, supersession, retention and destruction actions.

Feature View Create Change Remove Named actions requiring separate permission Typical Roles
Reference Model candidate Yes Import/create candidate Draft only Draft only validate, publish, retire release eTMF Study Administrator or taxonomy administrator
Zone/Section/Artifact definitions Yes Candidate only Candidate only Candidate only map prior release, approve local extension Taxonomy administrator
Organization filing taxonomy Yes Yes New revision No approve, make effective, retire eTMF Study Administrator
Study TMF Yes Yes Governed correction No establish, close conduct phase, transfer responsibility eTMF Study Administrator
TMF Plan Revision Yes Yes Draft only Draft only submit, approve, make effective, supersede TMF Lead, eTMF Study Administrator
Record Location Yes Yes Correct with history No verify retrieval, suspend, retire, transfer responsibility TMF Lead, Archivist
Filing Plan Revision Yes Yes Draft only Draft only validate, approve, reconcile, make effective, supersede TMF Lead
Filing Plan Reconciliation Yes Generate Resolve mappings No approve carried/new/retired/decision-required outcomes TMF Lead, required functional reviewers
Document Expectation Yes From effective plan Through plan revision No decide applicability, change count through plan revision TMF Lead
Filing Slot Yes From expectation No generic change No link candidate evidence, accept fulfilment, retire through reconciliation TMF Lead, Classifier
Exception Decision Yes Request Add evidence/conditions No approve, reject, return, revoke, supersede, expire Declared accountable Roles

Approval and effectiveness are separate. A person who can draft the Filing Plan does not automatically receive the action to approve it or make it effective.

Feature View Create Change Remove Named actions requiring separate permission Typical Roles
Intake Item Yes Submit Add intake details Rejected/uncommitted only accept for triage, return, reject, quarantine Record Contributor, Classifier
Duplicate Candidate Yes System/reviewer Add assessment evidence No decide exact duplicate, business duplicate, related, or not duplicate Classifier / Indexer
TMF Document Yes Yes Stable identity correction only No mark entered in error, create successor, withdraw Classifier; restricted withdrawal Role
Document Version Yes Yes New version only Draft only submit for QC, reject, finalize, supersede Record Contributor; Finalizer for finalization
Content component Yes Add to draft version Replace through new version Draft only verify availability/readability Record Contributor, Classifier
Classification Revision Yes Yes New revision No propose, confirm, supersede Classifier / Indexer
Metadata Revision Yes Yes New revision No propose, confirm, supersede Classifier / Indexer
Filing Placement Yes Propose No in-place edit No activate after finalization, end, replace, reject Classifier / Indexer, Finalizer where required
Evidence Set Yes Assemble candidate Reconcile candidates No accept for one Filing Slot, replace accepted set TMF Lead / authorized classifier
Externally Held Record Reference Yes Yes New verified reference No verify retrieval, accept for fulfilment, mark unavailable, replace Functional Record Owner, TMF Lead
Rendition Yes Generate No Draft failed rendition only verify fidelity, approve use Classifier / authorized service
Certified Copy Attestation Yes No generic create No No certify exact copy, revoke/replace invalid certification Qualified verifier or validated process identity

“Change TMF Document” never means replacing final content. Content correction creates another Document Version; metadata or classification correction creates another governed revision.

Feature View Create Change Remove Named actions requiring separate permission Typical Roles
QC Criterion/Checklist Yes Draft Draft/new revision Draft only approve, make effective, retire TMF Lead, Quality administrator
QC Request Yes Yes Assign/due date Cancel with reason only assign, acknowledge, start, cancel TMF Lead, Functional Record Owner
QC Round Yes Created from request Results only while open No start, record criterion results, require correction, pass, close QC Reviewer
Criterion Result Yes Yes Before round decision No pass, fail, not applicable with reason QC Reviewer
Quality Finding Yes Yes Status, assignment, evidence No assign, respond, submit correction, verify, close, reopen, accept non-issue Reviewer; Contributor responds
Quality Decision Yes No generic create No No pass or fail exact reviewed evidence QC Reviewer
Functional Approval Yes No generic create No No approve, reject, withdraw approval Document Approver
Finalization Decision Yes No generic create No No finalize exact version/revisions/placement after prerequisites Document Finalizer

The Filing Plan declares where independent review is required. A contributor who submitted a record cannot satisfy an independent QC or approval requirement merely because they also hold a reviewer Role. The access decision may allow the feature, while eTMF refuses the action because separation of duties fails.

Measures, inspection and archive catalogue

Section titled “Measures, inspection and archive catalogue”
Feature View Create Change Remove Named actions requiring separate permission Typical Roles
Completeness snapshot Yes Generate No No approve/report declared snapshot TMF Lead, Read-only Reviewer
Timeliness snapshot Yes Generate No No approve/report declared snapshot TMF Lead
Quality snapshot Yes Generate No No approve/report declared snapshot TMF Lead, Quality reviewer
Inspection Readiness Assessment Yes Yes Add actions/limitations No conclude ready/not ready for exact scope and time Inspection Coordinator
Inspection Request Yes Yes Scope/due details with history No accept, refuse, close Inspection Coordinator
Disclosure Set Yes Assemble Add governed supplement No approve, freeze disclosed set, supplement, close Inspection Coordinator; approval may be separate
Inspection Access Separate permission Request Time/scope only through new decision No approve, activate, suspend, end Access administrator + Inspection Coordinator
Inspection Export Separate permission Request No No generate, verify, release Inspection Coordinator
Archive Package Yes Prepare Reconciliation/addendum No approve archive, archive, verify retrieval, add governed addendum Archivist, TMF Lead for approval
Archive Custody Yes Establish Transfer through retained decision No transfer, accept custody, change location Archivist
Retention Obligation Yes Register Supersede with evidence No apply, recalculate end, close obligation Records policy/Archivist Role
Retention Hold Yes Request Evidence/conditions No approve, release, supersede Legal/Records authorized Role
Destruction Yes Request No No independently approve, execute, certify Qualified Archivist + required approver
TMF Export Package Yes Request No No generate, verify, release, acknowledge receipt TMF Lead, Archivist, Inspection Coordinator by purpose

An Inspector Role is read-only and limited to the approved Disclosure Set. It does not receive general Study TMF visibility, and access activity remains attributable.

eTMF combines Study/Country/Site area with record classifications:

Classification Access effect
Sponsor-managed record Visible according to assigned study/function/scope
Investigator-controlled record Sponsor sees only the permitted reference or transferred record; responsibility does not imply unrestricted access
Blinded record Only Roles compatible with the blinded view
Unblinded record Requires explicit unblinded feature visibility
Direct participant identifiers Refused from ordinary sponsor TMF use; quarantine and privacy response actions are separately controlled
Confidential/legal record Restricted to the declared functional or legal access group
Inspection disclosure Visible only within the approved set and access period
Archived record Read-only through archive/inspection permissions; ordinary filing actions remain unavailable

Visibility is applied before searches, counts, expected-document metrics, worklists and exports. A restricted record must not appear indirectly through a count, placeholder, filename or quality total.

Role Must normally include Must not imply
Record Contributor submit content, see own returned items/findings, respond QC pass, finalization, plan approval, inspection access
Classifier / Indexer classify, correct metadata, propose/activate permitted placement content approval or QC independence automatically
QC Reviewer assigned QC rounds, findings and verification content replacement, filing-plan change, archive destruction
Functional Record Owner expectations for function, contributor coordination, correction decisions unrestricted access to other functions or unblinded records
TMF Lead filing plan, reconciliation, expectations, measures and readiness automatic independent approval of own submissions
Document Finalizer finalization after exact prerequisites editing final content in place
Inspector / Auditor read approved disclosure set and permitted export file, correct, finalize or see outside disclosure scope
Archivist archive, custody, retrieval, retention administration release a hold or destroy without required independent approval
  1. Every eTMF feature action has a stable published meaning and compatible access areas.
  2. View, export, inspection access, QC, approval, finalization, archive and destruction are separate permissions.
  3. Create, Change and Remove never imply approve, finalize, file, fulfil or destroy.
  4. Remove applies only to explicitly permitted drafts or rejected intake; regulated history is retained.
  5. Record visibility evaluates Study/Country/Site, functional responsibility, privacy, confidentiality and blinding.
  6. Visibility is applied before search, counts, metrics, worklists and export.
  7. A Role cannot bypass independent-review or separation-of-duty rules.
  8. An active filing placement pins the exact finalized Document Version, classification and metadata revisions.
  9. An Inspector receives a controlled disclosure set, not unrestricted eTMF access.
  10. Archive destruction requires expiry of all obligations, release of all holds, exact permission, required independent approval and a retained destruction certificate.
  11. Business responsibility does not grant application access.
  12. Product action-catalogue revisions never silently expand existing Roles.

The Principal has both Roles for the Study. They submitted the Document Version. The applicable QC Request requires independent review, so eTMF refuses their attempt to pass the round and routes it to another qualified reviewer. Both the permission result and separation-of-duty refusal remain visible.

Blinded reviewer searches for an unblinded record

Section titled “Blinded reviewer searches for an unblinded record”

The reviewer has Study-wide QC permission but no unblinded action. The record is excluded before search and worklist counts are calculated. A copied URL cannot disclose the title, filename, existence or metadata.

The authenticated session remains valid, but the time-limited Inspection Access Assignment has ended. Further reads and exports are denied. Earlier viewed/exported items remain in the inspection access history.

Filing plan editor cannot approve their revision

Section titled “Filing plan editor cannot approve their revision”

The TMF Lead can create and change the draft. The organization requires independent plan approval, and the Role lacks the approval action. Platform denies the approval attempt; an authorized approver reviews the exact revision and reconciliation evidence.

The Archivist can administer archive custody and request destruction. The active hold prevents destruction even if their Role includes execute-destruction. A separately authorized role must release the hold, and the complete approval chain is required before execution.

See Authentication, roles and access for authentication, Role revisions, access areas, assignments, delegation, visibility evaluation and audit evidence.