Electronic data capture is the governed translation of a protocol into patient-level data and, ultimately, an analysis-ready clinical database. The quality of that database depends on more than forms: visit logic, derivations, edit checks, coding, external data, review, queries, corrections, reconciliation, and lock all need one controlled state model.
Seal connects each collected value to the protocol requirement, eCRF version, subject and visit, user action, source or external feed, review history, query, correction, derivation, coding decision, and final lock state.
The protocol defines the data contract
Study design, objectives, endpoints, populations, arms, cohorts, visits, windows, procedures, eligibility, treatment, assessments, discontinuation, safety reporting, and analysis needs establish what data must exist and when.
Every form and field retains the protocol concept and downstream use it serves.
Study build is versioned configuration
Study, country, site, arm, cohort, schedule, event, form, section, field, codelist, unit, derivation, edit check, workflow, role, notification, integration, and export specification are promoted through design, test, approval, release, amendment, and retirement.
Active subjects remain on the correct effective study version.
eCRFs capture meaning, not just values
Question text, concept, data type, unit, precision, controlled terminology, required state, conditional display, repeating structure, source status, completion rule, help, reason for change, and downstream mapping define each field.
Visit and event logic handles real subjects
Scheduled, unscheduled, repeating, early-termination, screen-failure, follow-up, re-consent, dose interruption, missed, remote, and out-of-window events remain explicit.
Dates, dependencies and form expectations recalculate without rewriting historical completion.
Entry checks prevent avoidable errors
Range, format, chronology, cross-field, cross-form, visit-window, dose, eligibility, missingness, consistency, protocol deviation, and external-data checks can run at entry or asynchronously.
Each firing retains rule version, inputs, message, severity, override policy, user action, reason, query, and resolution.
Site entry remains attributable
User, role, site, subject, visit, form, field, original value, new value, date, time, reason, signature, source context, device, and audit event remain available throughout the study.
Correcting a value never replaces its provenance.
Subjects and identifiers remain controlled
Screening identity, randomized identity, site, cohort, arm, treatment assignment where visible, status, consent, eligibility, enrollment, discontinuation, completion, and privacy controls remain appropriately separated.
External data is reconciled, not merely loaded
Laboratory, imaging, ECG, eCOA, device, pharmacokinetic, randomization, drug supply, safety, and specialty-vendor feeds retain file and transfer identity, schema, version, subject matching, visit matching, load result, duplicates, rejected rows, transformations, reconciliation, and approval.
Queries have a complete lifecycle
Manual or automatic origin, field or dataset, issue, evidence, assignee, due date, site response, proposed correction, monitor or data-manager review, reopen, escalation, closure, and audit trail define the query.
Response volume and age remain operational signals; closing a query requires resolution of the underlying data state.
Medical coding remains reviewable
Verbatim term, dictionary and version, coded term, hierarchy, auto-code confidence, synonym, manual choice, reviewer, query, recode impact, and final state remain linked to the source value.
Dictionary upgrades identify every term and output affected by the new version.
Adverse events, serious events, concomitant medications, medical history, laboratory values, vital signs, discontinuations, deaths, protocol deviations, narratives, review comments, queries, and escalation remain navigable by subject and time.
Safety-system reconciliation records matched, missing, discrepant, pending, and resolved cases without conflating the two systems of record.
Source review and verification are risk based
Field or form criticality, source status, monitoring strategy, required review, reviewer, evidence, finding, query, completion, and exception define review coverage.
The system distinguishes source-data review, source-data verification, medical review, data-management review, and signature.
Data cleaning is a visible matrix
Expected forms, missing fields, open queries, coding, external reconciliation, safety reconciliation, deviations, review, signatures, investigator verification, frozen state, and exceptions roll up by subject, site, country, cohort, and study.
Real-time completeness shows why a subject or site is not ready.
Derivations and transformations are controlled
Algorithm, inputs, units, missing-data handling, reference ranges, timing, version, validation, execution, output, discrepancy, and review define a derived value.
The submitted dataset can trace back through mapping and transformation to the collected or received source value.
Freeze and lock have enforced prerequisites
Scope, subjects, forms, data cuts, outstanding work, approved exceptions, signatures, coding, reconciliations, exports, validation, authorization, freeze, unfreeze, lock, unlock, reason, and audit trail define database state.
Lock cannot be a ceremonial status applied while required evidence is incomplete.
Amendments preserve mixed-version reality
Protocol and eCRF changes identify affected countries, sites, subjects, visits, forms, fields, checks, integrations, mappings, data migrations, training, validation, release dates, and retrospective actions.
Historical data remains interpretable under the configuration that collected it.
Inspection and analysis use the same evidence
Study build, validation, access, entry, audit trails, queries, review, signatures, reconciliation, exports, freezes, locks, changes, exceptions, and approvals form the inspection record and the analytical lineage.
Where Seal is strongest
Seal is strongest where protocol operations, sites, subjects, clinical data, external feeds, review, quality, documents, and analysis lineage intersect. It owns the protocol-
Prove one complex subject path end to end
The first implementation should follow one subject through screening, eligibility, randomization, scheduled and unscheduled visits, a conditional repeating form, external laboratory and eCOA data, an edit-check query, medical coding, safety reconciliation, monitoring review, investigator signature, amendment migration, freeze, export, and database lock.
Include a late lab file, a mismatched subject identifier, an overridden edit check, a reopened query, a dictionary upgrade, an approved lock exception, and a post-freeze correction. The system must preserve the exact data and configuration state used at every decision.
