Skip to content

ADR-0016: RTSM is a separate application, not an edc-core module - #114

Merged
tgerke merged 1 commit into
mainfrom
docs/adr-0016-rtsm-separation
Jul 23, 2026
Merged

tgerke merged 1 commit into
mainfrom
docs/adr-0016-rtsm-separation

Conversation

@tgerke

@tgerke tgerke commented Jul 23, 2026

Copy link
Copy Markdown
Owner

What

Records the decision that RTSM functionality (randomization and trial supply management) will be built as a sibling application — working name rtsm-core — rather than grown inside edc-core. Docs-only: one new file, docs/adr/0016-rtsm-separate-application.md. ADR-0010 stays accepted; this answers the question its scope note left open.

Why separate

  1. Structural blinding boundary. The master randomization list and kit-to-arm map never enter the EDC's Postgres, so no EDC admin or DBA can reach them. Item-level blinding (ADR-0009) masks values, not sibling tables. E6(R3) Annex 1 §4.1.1 asks that blinding integrity be maintained in system design and access management; separation makes that architectural rather than a policy someone has to audit.
  2. The intake seam gets dogfooded. rtsm-core integrates through the ADR-0010 API exactly as a commercial RTSM would — no private path. A built-in module would bypass and orphan that API.
  3. Validation envelope. Annex 1 §4.3.4(h) names randomisation as critical functionality for validation. Keeping the algorithm out of edc-core keeps this repo's validation pack stable across releases that never touch randomization.

Rejected alternatives recorded in the ADR: in-EDC randomization module (REDCap/OpenClinica pattern), separate service on a shared database, second app in this repo.

Source grounding

All E6(R3) references (glossary DAT definition, Annex 1 §4.1.1–4.1.2, §4.3.4(h)) verified verbatim against ~/claude-clinical-skills/sources/ICH/ich-e6-r3.txt. The characterization of commercial sponsor practice (deliberately splitting RTSM/EDC vendors) is industry observation, not a citation — flagged here per house rule.

Verification

Docs-only; biome check docs confirms the path is outside lint scope. No code, site, or traceability-matrix changes.

RTSM functionality (randomization, supply) will be built as a sibling
application with its own repo and database, integrating through the
ADR-0010 intake like any commercial RTSM. Rationale: structural blinding
boundary (Annex 1 §4.1), dogfooding the integration seam, and keeping
randomization's validation burden (Annex 1 §4.3.4(h)) out of edc-core's
validation envelope. Regulatory wording verified against the E6(R3)
source mirror.
@tgerke
tgerke merged commit 51ce120 into main Jul 23, 2026
1 check passed
@tgerke
tgerke deleted the docs/adr-0016-rtsm-separation branch July 23, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant