Basic Privileges
Expiration Date: Automatically terminates project access for the user on the date selected. If left blank, no expiration will be enforced on the user account.
Highest-Level Privileges
Project Design and Setup:
Grants the user access to the Project Setup page, allowing them to create, modify, and delete instruments as well as adjust project-level settings, features, and modules.
This right should be allocated only to trained study members and limited to very few users per study.
At least one team member per study should hold this right.
User Rights:
Grants the user access to change the rights and privileges of all users on a particular project, including themselves. Also allows users to add new users to the project.
WARNING: Granting User Rights privileges gives the user the ability to control other users' project access. This user should be very trusted and knowledgeable about both the project and REDCap. Giving User Rights to team members should be a carefully considered decision. Poor assignment of rights can harm both security and data integrity.
For instance, giving record-deletion or project-design rights to an unqualified person could result in data loss or broken workflows.
Potential to access PHI: YES - User can change their own User Rights and grant access to any module where PHI can be viewed or downloaded.
Data Access Groups (DAGs):
Grants user access to create and add users to DAGs. DAGs allow multi-site studies to maintain data separation (e.g., Group A cannot view, export, or edit Group B's data). Users may belong to multiple DAGs simultaneously.
WARNING: Assigning yourself to a DAG will immediately restrict your own access to other DAGs. Users who manage DAGs should not assign themselves to one, as they must see all data to maintain proper oversight.
Other Privileges
Manage MyCap Participants:
Grants access to the MyCap Participant Management page, including the ability to invite or add participants, send and view messages, and manage other MyCap-related features.
NOTE: This user right appears only if MyCap is enabled. MyCap may not be available at all institutions.
Potential to access PHI: YES - Messages with participants may contain PHI.
Survey Distribution Tools:
Grants access to manage public survey URLs, participant contact lists, and the survey invitation log.
NOTE: Appears only if surveys are enabled.
Potential to access PHI: YES - Email addresses and phone numbers may appear in contact lists and invitation logs.
Alerts & Notifications:
Grants access to add and edit alerts and to view the Notification Log of past and scheduled alerts.
Potential to access PHI: YES - Alert Logs may include PHI such as names, email addresses, or phone numbers.
Calendar:
Allows viewing and editing of project calendars and participant schedules.
Potential to access PHI: YES - PHI may appear in calendar notes and can be printed or downloaded.
Add/Edit/Organize Reports:
Allows building custom reports within the project.
NOTE: If a user lacks form-level access to an instrument referenced in the report, that instrument's fields will not appear.
Potential to access PHI: YES - Depending on Data Viewing Rights.
Stats & Charts:
Allows users to view real-time statistics on project data.
NOTE: Forms that the user cannot access will not appear.
Potential to access PHI: YES - Depending on Data Viewing Rights.
Data Import Tool:
Allows downloading and modifying import templates to upload data directly into the project, bypassing data-entry forms.
WARNING: This right enables bulk overwriting of existing data.
Potential to access PHI: YES - Imported files may contain PHI.
Data Comparison Tool:
Allows viewing two selected records side-by-side for comparison.
Potential to access PHI: YES - PHI may be visible and printable.
NOTE: All discrepancies for all fields in the project are displayed and can be downloaded. This tool is not linked to Data Viewing Rights or Data Export Rights.
Logging:
Grants access to the audit trail of all project activity (page views, edits, deletions, etc.).
Potential to access PHI: YES - All changes, including PHI, are listed in the Log and can be downloaded.
File Repository:
Allows uploading, viewing, and retrieving project files such as protocols, instructions, or announcements. It also stores exported data and syntax files.
WARNING: Users with restricted Data Export Rights cannot open saved identified exports but can still view sensitive uploaded content (e.g., photos or scanned documents).
Potential to access PHI: YES - Depending on Data Export Rights.
Randomization Privileges
Randomization Setup:
Allows defining the randomization model and uploading/downloading allocation tables.
NOTE: Appears only if Randomization is enabled.
Randomization Dashboard:
Allows viewing the status of randomization allocations (used/not used).
NOTE: Appears only if Randomization is enabled.
WARNING: Access to this page will reveal which records were assigned to each group and may cause unblinding.
Randomization - Randomize:
Allows performing randomization for records.
NOTE: Appears only if Randomization is enabled.
WARNING: This right permits viewing or editing of stratification fields even if the user lacks form-level access to them.
Potential to access PHI: YES - If PHI (e.g., location) is used in stratification, the user may see it regardless of form-level rights.
Data Quality Privileges
Create and Edit Rules:
Allows creation or editing of custom data-quality rules.
Execute Rules:
Allows running data-quality rules-either the default rules or saved custom ones.
NOTE: If the user lacks access to instruments referenced in a rule, results will not be displayed.
Potential to access PHI: YES - Depending on Data Viewing Rights.
API Privileges
API Export:
Allows extraction of data using the API interface.
NOTE: Data Export Rights still apply.
API Import/Update:
Allows creating or modifying data using the API.
NOTE: Data Viewing Rights still apply to all modified data.
REDCap Mobile App Privileges
Collect Data Offline in the Mobile App:
Allows users to initialize a project and collect data on a device while offline.
NOTE: Appears only if the Mobile App is enabled. The app enforces password protection.
Download Data for All Records to the App:
Allows users to download existing data from REDCap to a device.
NOTE: Data Viewing Rights still apply. Appears only if the Mobile App is enabled.
Potential to access PHI: YES - Users may view PHI on a mobile device depending on Data Viewing Rights.
Settings Pertaining to Project Records
Create Records:
Allows adding new records and entering data.
Rename Records:
Allows changing the Record ID field.
WARNING: Should be granted only to trained staff. Renaming records can disrupt data integrity.
Delete Records:
Allows permanently deleting an entire record (all forms, events, and repeating instances).
WARNING: Records deleted at this level cannot be restored. Should be granted only to trained staff.
Potential to access PHI: YES - Deleted content may include PHI. All deletions are permanently logged.
Form-Level Delete Rights (New in v15.7.0):
Allows deletion of data on specific instruments only-without deleting entire records or events.
-
Appears under Data Viewing Rights in the User Rights dialog.
-
Can be granted per instrument.
-
Requires "View & Edit" privileges for that instrument.
-
If the instrument is enabled as a survey, "Edit Survey Responses" must also be granted.
-
Users with "Delete Records" automatically have this right for all instruments.
Purpose: Provides finer-grained control over deletion privileges.
NOTE: This option may not appear at all institutions depending on configuration or REDCap version.
Potential to access PHI: YES - Form deletions may include PHI. All deletions are logged.
Settings Pertaining to Record Locking and E-Signatures
Record Locking Customization:
Allows access to "Customize & Manage Locking/E-Signatures."
NOTE: Applicable only to users who already have Lock/Unlock rights. This is often used in regulatory projects to define the "meaning" of a lock or e-signature.
Lock/Unlock Records (Instrument Level):
Allows locking and unlocking of individual instruments.
-
Disabled: User cannot lock/unlock.
-
Locking/Unlocking: User may lock/unlock.
-
Locking/Unlocking with E-Signature Authority: User may lock/unlock and apply e-signatures.
Lock/Unlock Entire Records (Record Level):
Allows locking or unlocking an entire record from editing.
Users without this right cannot edit any form within a locked record.
Privileges for Viewing and Exporting Data
Data Viewing Rights:
Controls per-instrument access to view, edit, or delete data.
Options include four core levels plus the optional Delete checkbox:
-
No Access: Instrument and data hidden.
-
Read Only: User may view but cannot edit or delete.
-
View & Edit: User may view and edit data. Required for Delete rights.
-
Edit Survey Responses: User may edit completed survey responses.
-
Delete (Form-Level): User may delete data for this instrument only (if granted).
WARNING: Data Viewing Rights affect only in-application access. They have NO effect on exported or downloaded data.
Potential to access PHI: YES - If a form containing PHI is visible at Read Only, View & Edit, or Delete levels, PHI can be viewed.
Data Export Rights:
Control data exports on an instrument-by-instrument basis.
Levels include:
-
No Access: Cannot export any data or identifiers.
-
De-identified: Exports with date shifting and removal of non-validated text fields.
-
Remove All Tagged Identifier Fields: Removes only fields tagged as identifiers (does not date shift).
-
Full Data Set: Exports all data, including identifiers and free-text fields.
WARNING: "De-identified" and "Remove All Tagged Identifier Fields" depend on correct identifier tagging.
Mark all PHI fields as identifiers and restrict export access whenever possible.
NOTE: Once data is downloaded, the user is responsible for securing it per institutional policies (e.g., HIPAA).
Potential to access PHI: YES - PHI can be exported and downloaded. Export Rights are not linked to Data Viewing Rights.
If the result of concatenating multiple text fields SHOULD NOT be editable, use the @CALCTEXT Action Tag with the concat special function. For example, to concatenate first and last name, with a space between them:
@CALCTEXT(concat([first_name], ' ', [last_name]))
If you are concatenating multiple text fields using the same separator between them, you can use the concat_ws() special function inside the @CALCTEXT instead:
@CALCTEXT(concat_ws(" and ", [dessert1], [dessert2], [dessert3])
If the result of concatenating multiple text fields SHOULD be editable, then use the @DEFAULT Action Tag. For example, to concatenate first and last name, with a space between them, but allow the result to be edited:
@DEFAULT="[first_name] [last_name]"