Access in TrialPilot is layered. An organization decides who is on the team at all; a role decides what a team member can do; blinding decides what even an authorized team member is allowed to know; and the de-identification boundary decides what anyone on the research side can ever see about a participant. This page walks the four layers in that order.
Every permission is enforced on the server. What the dashboard shows you follows from your role and your organization — the exact options you see also depend on enabled sign-in methods and whether the active study is still in draft or already published.
Organizations are the access boundary#
Studies belong to an organization — a research group, sponsor, site, or institution — and you can only work on studies in organizations you are a member of. The person who creates an organization is automatically its organization administrator.
Membership is by invitation:
- An organization admin invites a member by email and chooses their role. The invited email must already have a TrialPilot researcher account.
- Organization admins can change another member's role or remove a member from the organization. You cannot remove yourself from the members table.
- When you belong to more than one organization, you work in one active organization at a time; make sure the correct organization is active before creating or opening a study.
See Accounts and organizations for the setup walkthrough.
Study-team roles#
Each member of an organization holds a role that shapes what they can do across its studies:
| Role | Typical access |
|---|---|
| Organization Admin | Manage organization settings, members, studies, and study operations. |
| Study Admin | Create and configure studies within an organization. |
| Investigator | Review study status, participants, recruitment, safety, and reporting workflows. |
| Coordinator | Monitor participants and day-to-day trial operations. |
| Viewer | Read-only visibility where granted. |
Some capabilities are granted more narrowly than the role headline. For example, organization admins, study admins, and investigators can run registry recruitment feasibility and invite matching registry members when the server grants the required permission. When a workspace or action is missing from your dashboard, ask your organization admin about your role before assuming something is broken.
What participants can see#
Participants use the TrialPilot app, not the Researcher Dashboard — and their view is scoped to themselves:
- Their own data. A participant sees their own check-ins, assessments, trends, pacing views, and — when a study completes and results are available — understandable results for the studies they took part in.
- Never other participants. Nothing in the app shows one participant another participant's data.
- Their own account. Participants can review what data categories are shared with their study, download their data, and delete their account from the app's More tab.
See Your data and privacy for the participant-facing view of this boundary.
Blinding-related access#
In a blinded study, role-based access is not enough — some information must be withheld even from people who are otherwise fully authorized. TrialPilot treats the arm assignment mapping as a firewall:
- The dashboard never reveals the blinded code-to-arm mapping to blinded users.
- Emergency unblinding is available for when a participant's care requires it — it always requires a reason, and it is recorded in the immutable randomization audit.
- In adaptive platform studies, blinded team members see a blinded operational arm status view, while unblinded decisions flow through a firewalled DSMB / statistician console.
Unblinding is deliberate and audited
The de-identification rule#
The final layer applies to everyone on the research side, regardless of role: study teams operate on de-identified data.
- Participants appear as study-scoped pseudonyms such as
P-0001— stable within a study, not linkable across studies, and not reversible to an identity. Names, contact details, and account credentials are never accessible from the dashboard. - Demographics are shown in generalized form, such as age bands rather than exact birth dates.
- Participant-level researcher views are suppressed for small cohorts until a study has at least 20 participants.
- Registry recruitment shows counts, never identities; TrialPilot sends the invitations.
- Safety and operational workflows expose the minimum information needed for study-team review.
This boundary is architectural rather than a matter of policy — the research-facing system is built on de-identified access paths. The full model is described in Privacy and de-identification.
