Blueprint library/edc

Clinical Electronic Data Capture (EDC) Software

Protocol to eCRF. Entry to query. Clean patient data to a controlled database lock.

Design and validate clinical studies, eCRFs and edit checks; manage subjects, visits and site entry; ingest external data; run medical and data review; govern queries, coding and reconciliation; track cleaning; freeze and lock the database; and deliver traceable analysis-ready datasets.

Clinical Electronic Data Capture (EDC) Software

Electronic data capture is the governed translation of a protocol into patient-level data and, ultimately, an analysis-ready clinical database. The quality of that database depends on more than forms: visit logic, derivations, edit checks, coding, external data, review, queries, corrections, reconciliation, and lock all need one controlled state model.

Seal connects each collected value to the protocol requirement, eCRF version, subject and visit, user action, source or external feed, review history, query, correction, derivation, coding decision, and final lock state.

01

The protocol defines the data contract

Study design, objectives, endpoints, populations, arms, cohorts, visits, windows, procedures, eligibility, treatment, assessments, discontinuation, safety reporting, and analysis needs establish what data must exist and when.

Every form and field retains the protocol concept and downstream use it serves.

02

Study build is versioned configuration

Study, country, site, arm, cohort, schedule, event, form, section, field, codelist, unit, derivation, edit check, workflow, role, notification, integration, and export specification are promoted through design, test, approval, release, amendment, and retirement.

Active subjects remain on the correct effective study version.

03

eCRFs capture meaning, not just values

Question text, concept, data type, unit, precision, controlled terminology, required state, conditional display, repeating structure, source status, completion rule, help, reason for change, and downstream mapping define each field.

04

Visit and event logic handles real subjects

Scheduled, unscheduled, repeating, early-termination, screen-failure, follow-up, re-consent, dose interruption, missed, remote, and out-of-window events remain explicit.

Dates, dependencies and form expectations recalculate without rewriting historical completion.

05

Entry checks prevent avoidable errors

Range, format, chronology, cross-field, cross-form, visit-window, dose, eligibility, missingness, consistency, protocol deviation, and external-data checks can run at entry or asynchronously.

Catch errors at entry, not at lock
Typed value fails a bounds check; correction or override is captured inline — no DM query cycle later.
Site entry
LDL: 42 mg/dL
(should be 142)
Edit check
Value < 50?
Previous: 142
Verify
Corrected
Corrected
LDL: 142 mg/dL
Clean data
No query needed
Override
Override
Reason required
Query opens
DM reviews
90% of errors fixed at entry — before they become queries
Fig. 1 / Clinical edit checks distinguishing accepted correction from a query requiring review and response

Each firing retains rule version, inputs, message, severity, override policy, user action, reason, query, and resolution.

06

Site entry remains attributable

User, role, site, subject, visit, form, field, original value, new value, date, time, reason, signature, source context, device, and audit event remain available throughout the study.

Correcting a value never replaces its provenance.

07

Subjects and identifiers remain controlled

Screening identity, randomized identity, site, cohort, arm, treatment assignment where visible, status, consent, eligibility, enrollment, discontinuation, completion, and privacy controls remain appropriately separated.

08

External data is reconciled, not merely loaded

Laboratory, imaging, ECG, eCOA, device, pharmacokinetic, randomization, drug supply, safety, and specialty-vendor feeds retain file and transfer identity, schema, version, subject matching, visit matching, load result, duplicates, rejected rows, transformations, reconciliation, and approval.

09

Queries have a complete lifecycle

Manual or automatic origin, field or dataset, issue, evidence, assignee, due date, site response, proposed correction, monitor or data-manager review, reopen, escalation, closure, and audit trail define the query.

Query lifecycle / system makes ignoring harder than answering
Query / OPEN
Subject 0144 / DoB and age inconsistent / please verify
Query opened
System / edit check
Site notified
Email + portal badge
Day 3 reminder
Email / direct link
Day 7 escalation
CRA + study manager CC'd
Coordinator responds
Date of birth corrected
Query closed
System / audit trail entry
Fig. 2 / Query opened from a data issue, answered by the site, reviewed, corrected, and resolved without losing history

Response volume and age remain operational signals; closing a query requires resolution of the underlying data state.

10

Medical coding remains reviewable

Verbatim term, dictionary and version, coded term, hierarchy, auto-code confidence, synonym, manual choice, reviewer, query, recode impact, and final state remain linked to the source value.

Dictionary upgrades identify every term and output affected by the new version.

11

Medical and safety review share patient context

Adverse events, serious events, concomitant medications, medical history, laboratory values, vital signs, discontinuations, deaths, protocol deviations, narratives, review comments, queries, and escalation remain navigable by subject and time.

Safety-system reconciliation records matched, missing, discrepant, pending, and resolved cases without conflating the two systems of record.

12

Source review and verification are risk based

Field or form criticality, source status, monitoring strategy, required review, reviewer, evidence, finding, query, completion, and exception define review coverage.

The system distinguishes source-data review, source-data verification, medical review, data-management review, and signature.

13

Data cleaning is a visible matrix

Expected forms, missing fields, open queries, coding, external reconciliation, safety reconciliation, deviations, review, signatures, investigator verification, frozen state, and exceptions roll up by subject, site, country, cohort, and study.

Real-time completeness shows why a subject or site is not ready.

14

Derivations and transformations are controlled

Algorithm, inputs, units, missing-data handling, reference ranges, timing, version, validation, execution, output, discrepancy, and review define a derived value.

The submitted dataset can trace back through mapping and transformation to the collected or received source value.

15

Freeze and lock have enforced prerequisites

Scope, subjects, forms, data cuts, outstanding work, approved exceptions, signatures, coding, reconciliations, exports, validation, authorization, freeze, unfreeze, lock, unlock, reason, and audit trail define database state.

Database lock / every gate closed with evidence
Open queries
0 of 2,847 outstanding
SAE reconciliation
All cases reconciled vs safety DB
Central lab data
All timepoints received / mapped
Protocol deviations
All classified / signed
Medical monitor review
Final pass complete
!
Conformance / SDTM
0 critical issues / 2 warnings reviewed
Database locked / SDTM export ready
CDASH-aligned / controlled terminology / no post-hoc cleanup
Fig. 3 / Database lock gated by clean data, closed queries, coding, reconciliation, review, and approved export readiness

Lock cannot be a ceremonial status applied while required evidence is incomplete.

16

Amendments preserve mixed-version reality

Protocol and eCRF changes identify affected countries, sites, subjects, visits, forms, fields, checks, integrations, mappings, data migrations, training, validation, release dates, and retrospective actions.

Historical data remains interpretable under the configuration that collected it.

17

Inspection and analysis use the same evidence

Study build, validation, access, entry, audit trails, queries, review, signatures, reconciliation, exports, freezes, locks, changes, exceptions, and approvals form the inspection record and the analytical lineage.

18

Where Seal is strongest

Seal is strongest where protocol operations, sites, subjects, clinical data, external feeds, review, quality, documents, and analysis lineage intersect. It owns the protocol-to-database state model while composing CTMS, eTMF, clinical operations, training, and quality controls.

19

Prove one complex subject path end to end

The first implementation should follow one subject through screening, eligibility, randomization, scheduled and unscheduled visits, a conditional repeating form, external laboratory and eCOA data, an edit-check query, medical coding, safety reconciliation, monitoring review, investigator signature, amendment migration, freeze, export, and database lock.

Include a late lab file, a mismatched subject identifier, an overridden edit check, a reopened query, a dictionary upgrade, an approved lock exception, and a post-freeze correction. The system must preserve the exact data and configuration state used at every decision.

Operating model

Native control model
States and decisions owned by this blueprint
06 native controls
Protocol-Driven Study Build
Protocol concepts, arms, cohorts, visits, windows, forms, fields, codelists, derivations, roles, integrations, mappings, validation, releases, amendments, migrations, and effective subject scope stay governed.
eCRF, Visit & Edit-Check Engine
Scheduled and unscheduled events, repeating forms, conditional fields, units, controlled terminology, completion, signatures, range, chronology, cross-form, missingness and protocol checks execute against the correct version.
Attributable Data Entry
Site, user, role, subject, visit, form, field, original and new value, reason, date, time, source context, signatures, permissions, audit events, freeze and correction state remain traceable.
Query, Coding & Reconciliation
Automatic and manual issues, assignees, responses, corrections, reviews, reopen, escalation, medical dictionaries, vendor feeds, subject and visit matching, safety discrepancies, and closure form one cleaning workflow.
Data-Cleaning Readiness
Expected forms, missing fields, queries, coding, external and safety reconciliation, monitoring, medical review, signatures, deviations, frozen state, exceptions, and readiness roll up by subject, site, country, cohort, and study.
Freeze, Lock & Dataset Lineage
Data cuts, snapshots, configuration, derivations, terminology, mappings, exports, prerequisites, approved exceptions, authorizations, freeze, unfreeze, lock, unlock, reasons, hashes, and audit trails remain reproducible.
Clinical Electronic Data Capture (EDC) Software owns the operating state above; connected foundations remain authoritative for their specialized records.

Capabilities

01native controlProtocol-Driven Study Build
Protocol concepts, arms, cohorts, visits, windows, forms, fields, codelists, derivations, roles, integrations, mappings, validation, releases, amendments, migrations, and effective subject scope stay governed.
02native controleCRF, Visit & Edit-Check Engine
Scheduled and unscheduled events, repeating forms, conditional fields, units, controlled terminology, completion, signatures, range, chronology, cross-form, missingness and protocol checks execute against the correct version.
03native controlAttributable Data Entry
Site, user, role, subject, visit, form, field, original and new value, reason, date, time, source context, signatures, permissions, audit events, freeze and correction state remain traceable.
04native controlQuery, Coding & Reconciliation
Automatic and manual issues, assignees, responses, corrections, reviews, reopen, escalation, medical dictionaries, vendor feeds, subject and visit matching, safety discrepancies, and closure form one cleaning workflow.
Expected forms, missing fields, queries, coding, external and safety reconciliation, monitoring, medical review, signatures, deviations, frozen state, exceptions, and readiness roll up by subject, site, country, cohort, and study.
06native controlFreeze, Lock & Dataset Lineage
Data cuts, snapshots, configuration, derivations, terminology, mappings, exports, prerequisites, approved exceptions, authorizations, freeze, unfreeze, lock, unlock, reasons, hashes, and audit trails remain reproducible.
Site activation, personnel, roles, training, subject enrollment, visit status, monitoring strategy, findings, review coverage, protocol deviations, actions, and inspection readiness connect to the collected data.
Protocol, amendments, annotated eCRF, completion guidelines, specifications, validation, data plans, review plans, coding and reconciliation plans, lock approvals, exports, and archival evidence remain controlled.

Entities

Entity
Description
Kind
P
EDC Study
Protocol, countries, sites, arms, cohorts, schedule, build versions, integrations, and database state.
type
B
Study Build Version
Events, forms, fields, codelists, rules, roles, mappings, validation, release, and effective scope.
type
B
Phase II/III EDC Study Build
Visits, eCRFs, rules, roles, external feeds, mappings, validation, migration, and release.
template
B
BUILD-STUDY-014-v09
Current production build after amendment three.
instance
F
Electronic Case Report Form
Protocol concept, event, sections, fields, repeats, display, completion, signature, and version.
type
F
Adverse Event eCRF
Event terms, timing, severity, seriousness, causality, action, outcome, repeats, and signatures.
template
F
AE-SUBJ014-003
Completed serious-event form with one reconciled safety discrepancy.
instance
F
EDC Edit Check
Inputs, logic, timing, severity, message, override, query action, validation, and version.
type
P
Clinical Subject
Study identifiers, site, cohort, arm, consent, eligibility, status, visits, privacy, and state.
type
C
Subject Event
Subject, visit type, planned and actual dates, window, forms, deviations, status, and version.
type
N
Clinical Data Value
Subject, event, form, field, original and current value, unit, source, audit, review, and state.
type
H
Clinical Data Query
Origin, issue, field or data row, assignee, response, correction, review, escalation, and closure.
type
H
Cross-Form Clinical Query
Detected issue, supporting values, site response, correction, review, reopen, and closure.
template
H
QRY-014-00842
Reopened chronology query resolved after a source-date correction.
instance
I
External Clinical Dataset
Vendor, transfer, schema, file, version, matching, validation, rows, exceptions, reconciliation, and state.
type
I
Central Laboratory Transfer
Transfer schedule, schema, files, subject and visit match, tests, ranges, exceptions, and acceptance.
template
I
LAB-XFER-2026-08-14
Accepted transfer after resolution of two unmatched subject identifiers.
instance
T
Medical Coding Decision
Verbatim, dictionary, version, candidates, selected code, reviewer, query, recode impact, and state.
type
EO
Clinical Data Review
Scope, review type, strategy, required fields, reviewer, findings, queries, evidence, and completion.
type
EO
Risk-Based Subject Data Review
Critical data, review type, subject and site scope, findings, queries, exceptions, and completion.
template

FAQ

EDC software translates a clinical protocol into governed study configuration and manages eCRFs, subjects, visits, site entry, edit checks, external data, queries, coding, review, reconciliation, cleaning, freeze, lock, exports and audit trails.
Yes. Amendments version visits, forms, fields, checks, mappings, integrations, training and validation while assigning the correct effective configuration and migration actions to countries, sites, subjects and visits.
Checks declare inputs, logic, timing, severity, message, override policy, query behavior, test evidence and version. Every firing records its input values, user response, correction or approved override, and resolution.
Each transfer retains file identity, schema, version, checks, transformations, subject and visit matching, duplicates, rejected rows, load result, discrepancies, reconciliation, approval and downstream use.
Yes. Verbatim values, dictionary and version, candidate and selected codes, hierarchy, confidence, manual decisions, queries, reviewers, recoding and output impact remain traceable.
The strategy defines critical fields or forms and required review type. Each review retains scope, reviewer, evidence, findings, queries, exceptions and completion, distinguishing source review, verification, medical review and data-management review.
Configured prerequisites evaluate expected data, open queries, coding, external and safety reconciliation, reviews, signatures, protocol deviations, validation, exports and approved exceptions before authorized freeze or lock.
Only through a governed unlock or correction workflow with scope, authorization, reason, affected values and outputs, audit trail, repeated review and a new snapshot or lock state. The prior state remains immutable.
CTMS contributes site, subject, visit and monitoring context. eTMF contributes protocol, plans, approvals, validation and essential documents. EDC supplies data readiness, issues, review and lock evidence back to both.
Prove one complex subject through screening, conditional visits, eCRFs, external data, an edit-check query, coding, safety reconciliation, monitoring, amendment migration, signature, freeze, export and lock with complete audit and configuration lineage.

Go live in 48 hours.