Summary
- The problem
- A clean clinical database depends on more than forms. Visit logic, edit checks, external feeds, coding, queries, corrections, reconciliation and lock each change the data state, and when they are tracked separately nobody can say exactly why a subject or site is not ready.
- Seal’s approach
- Each collected value stays linked to its protocol requirement, eCRF version, subject and visit, source or feed, review history, query, correction, derivation and coding decision. Freeze and lock are gated on that evidence.
- What changes
- Data managers see outstanding work by subject, site and study as it happens, amendments keep historical data interpretable under the version that collected it, and the submitted dataset traces back to the source value.
- Where to start
- One complex subject path, from screening to database lock, including a late laboratory file, a reopened query and a post-freeze correction. Book a demo.
1A clean database needs one record of change.
Electronic data capture turns a protocol into patient-level data and, eventually, an analysis-ready clinical database. Forms are only part of that work. Visit logic, edit checks, external feeds, coding, queries, corrections, reconciliation and lock all change the state of the data, and the database is only as trustworthy as the record of those changes.
Seal keeps each collected value linked to the protocol requirement it serves, the eCRF version that collected it, the subject and visit, the user or feed that supplied it, and every review, query, correction, derivation and coding decision that followed. Freeze and lock are then gated on that evidence rather than on a status someone sets.
1.1Why teams choose Seal for electronic data capture
A standalone EDC holds the collected values while protocol operations, sites, external data, safety, documents and quality live elsewhere, so the connections are rebuilt at every cleaning cycle and inspection. Seal owns the protocol-
| EDC beside the trial | Seal | |
|---|---|---|
| Study build | Form definitions, with protocol intent held in documents | Fields that retain the protocol concept and downstream use they serve |
| External data | Files loaded into the database | Transfers with identity, matching, rejected rows and reconciliation retained |
| Queries | Counts and ages on a report | A lifecycle that closes when the underlying data is resolved |
| Lock readiness | A checklist compiled before the lock meeting | Outstanding work rolled up by subject, site and study as it happens |
| Amendments | New forms, with older data read under the current build | Each value interpreted under the configuration that collected it |
2The protocol defines the data contract.
Endpoints, populations, visits, windows, procedures and safety reporting establish what data must exist and when. Every form and field in Seal retains the protocol concept and the downstream use it serves, so a question about a field can be answered by pointing at the requirement behind it.
The study build is versioned. Events, forms, fields, codelists, derivations, edit checks, roles, integrations and export specifications move through design, test, approval, release and amendment together, and active subjects stay on the correct effective version.
Visit logic has to handle real subjects: unscheduled, repeating, missed and out-of-window visits, early termination, screen failure and re-consent. Dates and form expectations recalculate when those events occur without rewriting completion history that has already been recorded.
3Capture data at the site with its provenance intact.
Edit checks can run at entry or asynchronously: ranges, chronology, cross-form consistency, visit windows, dosing and eligibility. When a check fires, Seal retains the rule version, the inputs it evaluated, the message shown, the user’s action and any reason for override. A corrected value and a value that needs a query are different outcomes, and the record shows which occurred.
Site entry, LDL
42 mg/dL
Below 50. The previous value was 142.
Corrected to 142 at entry: clean data, no query.
Kept with a reason: a query opens for data management to review.
Site entry stays attributable. The user, role, site, subject, visit, field, original value, new value, time, reason and signature remain available for the life of the study; correcting a value does not replace its history.¹ Screening and randomised identities, treatment assignment and privacy restrictions stay separated according to who is permitted to see them.
4Reconcile, code and review against the source value.
Laboratory, imaging, ECG, eCOA, device, randomisation and drug-supply data arrive as transfers, not as rows that silently appear. Each transfer keeps its file identity, schema version, subject and visit matching, duplicates, rejected rows and transformations, so a late laboratory file or a mismatched subject identifier remains visible work.
Medical coding keeps the verbatim term, dictionary and version, coded term, reviewer and any manual choice linked to the source value. A dictionary upgrade identifies every term and output affected by the new version.
Safety reconciliation records matched, missing, discrepant and resolved cases without conflating the EDC with the safety system of record. Source-data review, source-data verification, medical review and data-management review remain distinct activities, with coverage set by field criticality and the monitoring strategy.²
5A query closes when the data is resolved.
A query records where it came from (an edit check or a reviewer), the field and evidence involved, the assignee, the site’s response, any proposed correction and the review that accepted or reopened it. Response volume and age are operational signals for follow-up; they are not the measure of whether the data is clean.
An answered query can still be waiting for data-management review. Seal keeps it open until the recorded data state changes, and keeps the full history when a closed query is reopened.
6Lock is a gated state, not a status.
Expected forms, missing fields, open queries, coding, external and safety reconciliation, protocol deviations, reviews and investigator signatures roll up by subject, site, country and study. The team can see why a subject or site is not ready while the work is in progress, rather than discovering it in the week before lock.
Derived values keep their algorithm, inputs, units, missing-data handling and version. A submitted dataset can be traced back through mapping and transformation to the collected or received value.
- Open queries (met)0 of 2,847 outstanding
- Medical coding (met)MedDRA 847/847, WHODrug 2,341/2,341
- SAE reconciliation (met)All cases reconciled
- Central lab data (met)All timepoints received
- Protocol deviations (met)All classified and signed
- Medical monitor review (met)Final pass complete
- Conformance (met)2 warnings approved as exceptions
Freeze and lock depend on that evidence. Scope, outstanding work, approved exceptions, authorisation and any unfreeze or unlock keep their reasons and audit trail. When a protocol amendment changes forms or checks, Seal identifies the affected sites, subjects, integrations and mappings, and historical data remains interpretable under the configuration that collected it.
7Prove one complex subject path end to end.
Follow one subject through screening, randomisation, scheduled and unscheduled visits, a conditional repeating form, external laboratory and eCOA data, an edit-check query, coding, safety reconciliation, monitoring review, investigator signature, an amendment, freeze and lock.
Include a late laboratory file, a mismatched subject identifier, an overridden edit check, a reopened query, a dictionary upgrade and a post-freeze correction. Then check that the data and configuration used at every decision can be reproduced from the record.
References
- 121 CFR 11.10, Controls for closed systems: procedures and controls must include system validation, limiting access to authorised individuals, and secure, computer-generated, time-stamped audit trails that record operator entries and actions without obscuring previously recorded information. eCFR
- 2ICH E6(R3), Guideline for Good Clinical Practice (2025). ICH
AOperating model
Included in this blueprint
- Protocol-driven study configuration
- eCRF, visit and edit-check engine
- Attributable data entry
- Query, coding and reconciliation
- Data-cleaning readiness
- Freeze, lock and dataset lineage
Connected across Seal
BCapabilities
| Capability | What it covers |
|---|---|
| Protocol-driven study configuration | Build arms, cohorts, visits, windows, forms, fields, codelists and roles from the protocol as a versioned study build. Amendments carry their migration and the subjects each version applies to. |
| eCRF, visit and edit-check engine | Scheduled and unscheduled visits, repeating forms and conditional fields run against the correct build version. Range, chronology, cross-form and missing-data checks fire with their inputs recorded. |
| Attributable data entry | Each value keeps its site, user, role, original and new value, reason and time, with signatures and freeze or correction state. |
| Query, coding and reconciliation | Queries raised by edit checks or reviewers, medical coding and vendor-feed reconciliation form one cleaning workflow, each linked to the source value it concerns. |
| Data-cleaning readiness | Roll up expected forms, missing fields, open queries, coding, reconciliation, reviews and signatures by subject, site, country and study as the work happens. |
| Freeze, lock and dataset lineage | Freeze and lock keep their scope, prerequisites, approved exceptions and authorisation. Snapshots and exports record the data cut and configuration they came from. |
| Site, monitoring and training context | Connect site activation, personnel, training, monitoring findings and protocol deviations to the data collected at each site. |
| Documents and essential evidence | Keep the protocol, amendments, annotated eCRF, specifications, data management and review plans, lock approvals and exports under document control. |
CConnected records
DQuestions and answers
What is electronic data capture software?
EDC software turns a clinical protocol into a study configuration for collecting patient data. It manages eCRFs, subjects, visits, site entry, edit checks, external data, queries, coding, review, reconciliation and database lock, with audit trails throughout.
Can Seal handle protocol amendments during an active study?
Yes. An amendment versions the affected visits, forms, fields, checks and mappings. Each country, site and subject is assigned the correct effective version, and historical data stays interpretable under the version that collected it.
How do edit checks work?
Each check declares its inputs, logic, timing, severity, message, override policy and query behaviour, and is tested before release. Each time it fires, the input values, user response and resolution are recorded.
How are external laboratory and vendor data managed?
Each transfer keeps its file identity, schema, version, checks and subject and visit matching. Rejected rows, discrepancies and reconciliation decisions are recorded before the data is accepted.
Does the system support medical coding?
Yes. The verbatim term, dictionary version, candidate and selected codes, reviewer decisions and any recoding stay traceable to the value they code.
How are source review and verification represented?
The review strategy defines the critical fields or forms and the review type required. Each review records its scope, reviewer, findings and queries, and source review, verification, medical review and data-management review stay distinct.
What prevents premature database lock?
Configured prerequisites check expected data, open queries, coding, reconciliation, reviews, signatures and approved exceptions. Freeze or lock is then authorised against that evidence.
Can data be corrected after freeze or lock?
Only through a controlled unfreeze, unlock or correction workflow with its scope, authorisation, reason and affected values. The correction is reviewed and produces a new snapshot or lock state, while the earlier state is retained.
How does EDC connect to CTMS and eTMF?
CTMS contributes site, subject, visit and monitoring context, and the eTMF holds the protocol, plans, approvals and essential documents. EDC supplies data readiness, issues, review and lock evidence back to both.
What should the first implementation prove?
Follow one complex subject from screening through conditional visits, external laboratory data, an edit-check query, coding and safety reconciliation to database lock. Include a protocol amendment and a post-freeze correction.
