When you configure a randomization you choose a blinding model, which decides whether treatment arms are visible. Who can then see, configure or unblind them is controlled entirely by role permissions, and those are set separately.
The two blinding models
Model | Who sees the assigned arm |
Open, or single-blind | Any site user with access to the randomization list. |
Double-blind | Nobody, unless they hold the Unblind Access permission. |
The permissions that control it
Randomization and unblinding permissions are set per role, in Platform Settings > Roles > Edit. They sit in three groups.
Group | Permission | Allows |
Randomization Configuration | Access | Viewing the randomization setup. |
Edit | Creating or modifying the configuration. | |
Delete | Removing an existing configuration. | |
Randomization List | Access | Viewing the list, blinded or unblinded depending on the setup. |
Edit | Modifying or importing the list. | |
Unblind Access | Seeing treatment arms even in double-blind mode. | |
eCRF Record | Emergency Unblinding | Performing an emergency unblinding directly from the eCRF. |
⚠️ Warning: on a blinded study, review who holds Unblind Access before you go live, and keep the list as short as your protocol allows. A double-blind configuration protects nothing if the permission has been granted broadly, and the blinding model itself gives you no warning that it has.


