The capabilities in today's eTMF-intelligence tools are good, and this bundle keeps almost all of them. What it changes is the thing underneath: records stay with the custodian who generated them, and the intelligence reads across all of them. The offering is not a repository you migrate into. It is a graph you join, and a market of vendors competing to read it well.
One sentence, taken seriously and then reversed.
This bundle reimagines one specific published design: IntuitionLabs' eTMF Intelligence prototype, credited in detail in Credit below. That design is explicit about where it starts: the sponsor's electronic Trial Master File stays the system of record, and the reasoning layer sits on top of it. Starting there was the correct call. A single repository was the only substrate available, so software that read trial records had to read one party's copies of them.
Three clauses say it plainly. C.2.3: essential records "should be maintained in or referred to from repositories," plural, and "referred to from" means a pointer discharges the obligation. C.2.4: each party should maintain a record of where essential records are located. C.2.7: "the original records should generally be retained by the responsible party who generated them." And C.2.3's own phrasing, "these repositories may be referred to as a trial master file," makes the TMF a naming convention applied to a slice, not a defined object with required properties.
The second row is the commercially interesting one. A single system of record holds one version of every answer, so it has nothing to compare against, and it cannot form a cross-custodian contradiction at all. Not slowly, not partially. The eTMF holds consent v2.1, the participant's own record holds v3.0, both records are internally valid and correctly filed, and the problem exists only in the relation between them.
A substrate, an encoding of the guideline against it, and a boundary that vendors sit outside.
An offering proposes; only the custodian files. This is the constraint every adopted capability had to be re-expressed under, and it is the reason the market can have more than one vendor in it. When writing is a capability the substrate does not have, no vendor can become the substrate.
See the six capabilities working on synthetic data: the Trials SDG console.
You compete on how well you read, and you publish the rate at which you were wrong.
One surface instead of N integrations. A read grant against a graph rather than a connector per sponsor per platform. The clause registry as a shared vocabulary, so "this discharges C.2.4" means the same thing to you and to your competitor.
And a capability no single-repository product can offer: you can form findings across custodians. Cross-system reconciliation stops being a differentiator you build and becomes a class of finding the substrate makes possible.
The write. You never hold the repository, so you never hold the lock-in. A sponsor who prefers a competitor's classifier switches by changing a grant, and there is no migration to make that expensive.
And your rejection rate becomes public. Trial.Ecosystem.PublishAttestation@v1
publishes adopted-versus-rejected per check. A high rate is not a scandal.
It is a check whose rule nobody agreed yet, or a model wrong about this study. Not publishing
it is the scandal.
Every pathway declares license_terms.survives_fork.
Trial.Ecosystem.ForkOffering@v1 inherits attribution monotonically: a fork may add
attribution requirements and may never narrow one. Take the pathways, change them, ship a better
offering. The one thing you cannot do is remove the credit.
Read this section as the one most likely to contain a cost you did not agree to.
Completeness computed from your own study's records rather than a template list, with a denominator you can dispute. Findings that span custodians. Inspection readiness over a locator index instead of over one repository's contents. Qualification evidence rooted at the person, so one currency check serves every study that references it.
Correction. A data manager cannot edit a participant-rooted record; they raise a query and the custodian resolves it. This is slower and it is more correct. A sponsor-applied correction to someone else's source record, with the sponsor's reason attached, is exactly what E6(R3) 4.2.3's attribution requirement exists to make visible.
The single confident number. Completeness now arrives bounded by index coverage, and the readiness composite refuses to compute when a custodian has not answered. If you need one percentage to put in a board pack regardless of what is behind it, this substrate is worse for you, and you are not wrong to notice.
Your accountability does not change at all. Sponsor responsibility under 3.6.7 for assessing service provider suitability, under 3.9.1 for oversight of delegated activities, and under 3.11.4 for monitoring, is untouched. Delegating an activity to a vendor is not delegating responsibility for it, and nothing in this design pretends otherwise. What changes is where records live and how they are reached.
Submission formats are not touched either.
Trial.Agreement.SubmitToAuthority@v1 defers entirely to the authority's
specification. This bundle has no view on eCTD and proposes no alternative.
The part of this that is a promise, and the part that is not.
A page that only describes winners is a page nobody should trust.
| Party | Direction | Why |
|---|---|---|
| Specialist intelligence vendors | better | One surface instead of N integrations, no platform gatekeeper between them and the records, and a class of cross-custodian finding they could not previously form. |
| Sites and institutions | better | They stop shipping copies of their own records into someone else's repository, and their expectations name them rather than being tracked on a list they cannot see. |
| Participants | better, conditionally | Custody and visible grants, if they want them. A design requiring participant engagement has an adoption problem, and this one has never been tested with a participant. |
| Sponsors and CROs | mixed | Better findings and no migration cost; slower corrections and the loss of the single confident number. Whether that trade is worth it is H-CTM2 and it is untested. |
| Incumbent single-vendor platforms | worse | The repository stops being the moat. This is the honest cost of the design and it is not dressed up as anything else. |
| Anyone selling migration projects | worse | There is much less to migrate. Records stay put; views and grants move. |
Published rejection rates per check, per offering. That is the whole mechanism, and it only works
because writing is not on offer. When a vendor cannot lock a sponsor in by holding their
repository, the only thing left to compete on is whether their proposals get
adopted, which is measurable, publishable, and exactly what
Trial.Oversight.AdoptRecommendation@v1 records over the life of a study.
Custody root as a field that varies. Availability without possession. Refusing to compute over a view known to be partial. An offering that proposes and never files. The custodian member on a derived expectation. The explicit resolved / explained / open terminal states grounded in C.3.3. Locator index coverage as a third denominator. And the argument that a single system of record cannot form a cross-custodian contradiction at all.
ICH has not reviewed or endorsed anything here; the guideline text is reproduced in the bundle and the argument built on it is ours. HL7 and FHIR are registered trademarks of Health Level Seven International, and CDISC, CDASH, SDTM and ADaM are trademarks of CDISC; neither organisation was consulted and no conformance is claimed. The TMF Reference Model project was not contacted; the zone crosswalk is one reading of a published taxonomy and if the model and the crosswalk disagree, the model is right. The oncology SDG supplies the hypergraph-and-pullback formalism and its domain-expert context is David L. Stark's. Nothing in this clinical-trials bundle is his and he was not consulted about it. Sealed Accord supplies the sealed-disclosure mechanism, whose own reference implementation runs against a stub.
Two claims are checkable today. Five are not, and one unanswered question gates most of them.
H-CTM0a: every reference in the trial-domain registry resolves; no orphan domains.
H-CTM0b: every one of the 653 mechanically extracted E6(R3) clauses carries a
disposition, and every encoded_by reference resolves to a pathway on disk.
Run ruby tools/validate_tsdg.rb. The denominator comes from a tool that reads
the PDF, so it cannot be quietly shrunk to make coverage look better. H-CTM0b proves
coverage is complete, not that the readings are right.
H-CTM1 availability without possession · H-CTM2 cross-custodian contradictions occur often enough to matter · H-CTM3 obligations survive a custody change · H-CTM4 signals-only inspection disclosure · H-CTM5 derived expectations differ materially from templates.
H-CTM1 is load-bearing: if it falls, H-CTM2, H-CTM3 and H-CTM4 fall with it. None has a verification command, because each requires a clinical trial.
No regulatory authority has been asked whether a locator handle plus a scoped grant satisfies P9.5. If availability requires the possibility of full record production rather than a sufficient answer to a question, this design does not comply, and no amount of engineering fixes that. It is not our question to answer and we have not answered it.
commons custody has no accountable party. Who is liable when
the locator index is wrong? C.2.4 requires the record of location to exist and says nothing
about who owns it. This is the most legitimate objection to the whole approach.If H-CTM1 is falsified, what survives is the clause registry: 653 addressable E6(R3) nodes with role, obligation strength, page locator and record implication, produced mechanically and useful to anyone reasoning about the guideline. That is the floor, and it does not depend on a single custody argument being right.