Skip to content

Platform product decision ledger

These are not minor open questions. Each answer changes object meaning, aggregate boundaries, commands, invariants or public contracts. Until decided, the model must expose the fork and refuse unsupported behavior rather than choosing through UI, persistence or integration code.

Records marked Resolved are binding model choices, retained here with their rejected alternatives. Records marked Open must be answered before affected Proposed Core behavior is accepted.

Question: When Sponsor + protocol identifier/title appear duplicative, may both Studies be registered?

Option Consequence
Warn and admit Preserves operations; requires duplicate review projection
Privileged override Adds high-risk admission decision/evidence
Scoped uniqueness refusal Risks false collisions and requires correction path

Needed for VS-01 and RegisterStudy refusal semantics.

PD-PLAT-002 — Study merge/supersession after product roots

Section titled “PD-PLAT-002 — Study merge/supersession after product roots”

Options: prohibit; cross-reference only; or coordinated owner-by-owner migration. Must define reversibility, historical identifiers, product impact acknowledgement and reconciliation owner. Current behavior: STUDY_MERGE_REQUIRES_MODEL_DECISION.

Is a Sponsor change a registry correction, governed transfer, replacement relationship or new Study? Primary Sponsor must not be independently editable both on Study and Participation.

Status: Resolved for vocabulary; transition authority remains open.

planned | active | closed is the accepted shared coordination lifecycle. It never means regulatory approval or product startup. Later transition authority, prerequisites and product effects still require a decision before commands beyond PlanStudyCountry are accepted.

PD-PLAT-005 — Multiple Study Sites for one Site

Section titled “PD-PLAT-005 — Multiple Study Sites for one Site”

May one canonical Site participate more than once in one Study under separate site numbers or investigator units? This changes the uniqueness coordinate Study × Site.

PD-PLAT-006 — Study Site number normalization and reuse

Section titled “PD-PLAT-006 — Study Site number normalization and reuse”

Define case/whitespace/leading-zero rules and whether a corrected-away or closed number remains reserved forever, for a period, or may be reused under evidence.

PD-PLAT-007 — Used-Site country correction

Section titled “PD-PLAT-007 — Used-Site country correction”

Options: prohibit and create successor Site/Study Site; effective-dated reassignment; or governed correction only before product use. Must define EDC/eTMF historical and prospective behavior.

PD-PLAT-008 — Role revision assignment semantics

Section titled “PD-PLAT-008 — Role revision assignment semantics”

Status: Resolved.

Assignments follow the stable Role Definition’s current immutable revision. Every Access Decision pins the exact evaluated revision. Revising a Role requires impact preview, authority evidence and administrator-continuity validation. Pinning assignments to their original revision is the rejected alternative.

PD-PLAT-009 — Last administrator continuity

Section titled “PD-PLAT-009 — Last administrator continuity”

Status: Resolved for normal administration.

Continuity-sensitive Role, Assignment and Principal changes are serialized by Workspace × Product and rejected when they would remove the last effective qualifying administrator. Emergency break-glass remains a separate Candidate; it is not an exception hidden inside normal commands.

PD-PLAT-010 — Person Profile–Principal linkage

Section titled “PD-PLAT-010 — Person Profile–Principal linkage”

Is linkage absent, optional one-to-one, or one Profile to multiple authentication Principals? Define verification, privacy visibility, correction and unlink behavior.

PD-PLAT-011 — Entitlement withdrawal with in-flight enablement

Section titled “PD-PLAT-011 — Entitlement withdrawal with in-flight enablement”

Choose deterministic cutoff: accepted operation completes; explicit cancellation; or manual reconciliation. Arrival order must not decide accidentally.

PD-PLAT-012 — Product disable/re-enable semantics

Section titled “PD-PLAT-012 — Product disable/re-enable semantics”

Define product-root reuse, allowed retained-record/inspection Actions, in-flight command cutoff, lost-acknowledgement recovery and re-enable prerequisites independently for EDC and eTMF.

PD-PLAT-013 — EDC product-root enablement contract

Section titled “PD-PLAT-013 — EDC product-root enablement contract”

The target shape is proposed but EDC must confirm root identity, lifecycle, Site Participation relationship, acknowledgement and disable behavior. eTMF evidence cannot establish EDC semantics.

PD-PLAT-014 — Content verification validity

Section titled “PD-PLAT-014 — Content verification validity”

Can verification expire when malware/integrity policy changes? Can quarantine be released, and does release create another Decision or another Content Revision?

PD-PLAT-015 — Multiple product bindings and retention

Section titled “PD-PLAT-015 — Multiple product bindings and retention”

May one Content Revision bind to both EDC and eTMF purposes? Define blind/privacy compatibility, owner-specific retention requirements and disposition when one binding remains active.

Section titled “PD-PLAT-016 — Retention and legal hold ownership”

Define product-owner retention instruction, Platform enforcement, legal-hold owner, jurisdiction conflict rule, disposition authorization and serialization with a newly placed hold.

PD-PLAT-017 — Electronic-signature ceremony

Section titled “PD-PLAT-017 — Electronic-signature ceremony”

Define which current product commands require signature, decision time for authority, exact meaning statement, reauthentication policy, invalidation conditions and stale/abandoned ceremony retention.

PD-PLAT-018 — Milestone initial catalogue

Section titled “PD-PLAT-018 — Milestone initial catalogue”

Status: Resolved for the initial path.

Initial Proposed Core uses site_activated only, Study Site scope, Civil Date, one retained identity, and authenticated first-person HumanAssertionEvidence. Correction and reversal retain prior assertions. Product-fact proposal/automation remains an extension pressure that requires its own source-policy and reconciliation decision.

PD-PLAT-019 — Development Product necessity

Section titled “PD-PLAT-019 — Development Product necessity”

Confirm that both current EDC/eTMF scenarios require Development Product and Study Intervention. If only future products need them, demote rather than prebuild a registry.

PD-PLAT-020 — Connection contract governance

Section titled “PD-PLAT-020 — Connection contract governance”

Is the contract a code-published immutable descriptor or a customer-governed Definition? Define compatibility window, activation coordination, rollback and manual resolution authority.

When revision N+1 arrives before N, choose: buffer; apply a monotonic snapshot; or stop and reconcile. Define service level and divergence owner.

PD-PLAT-022 — Projection lag and existence hiding

Section titled “PD-PLAT-022 — Projection lag and existence hiding”

Define acceptable asOf lag, whether high-risk reads bypass projections, and whether denied identified access is indistinguishable from missing resource.

For every resolved decision record:

Decision ID
Chosen option and rejected alternatives
Owner and affected Aggregate(s)
New/changed invariant IDs
Commands and refusal codes affected
Facts and evidence profiles affected
EDC/eTMF contract impact
Scenarios updated
Unsupported behavior remaining

The model remains a review candidate until the decisions affecting Proposed Core behavior have explicit answers.