Setting up eConsent

Trialflare's eConsent lets participants read your Participant Information Sheet, initial their agreement to your eligibility criteria and conditions, and sign — all from a web link, on any device. Every completed consent produces a signed PDF with an audit trail, stored in the study and emailed to the participant.

This article walks through setting up a single informed consent form (ICF). Studies that need more than one — a parent form and a teen form, say — follow the same steps for each; see Multiple consent forms at the end.

Before you start. The contents of your ICF should already have been reviewed and approved by an appropriate ethics committee (a REC or IRB). Trialflare handles the mechanics of collecting consent; it does not review your wording.

Before you can turn eConsent on

eConsent collects personal data, so Trialflare requires you to publish a privacy statement first. Add it under About in your study settings. Until you do, the enable switch stays greyed out.

You will also need:

  • Trial administrator access to the study (see Permissions below).
  • The study to be unlocked. Consent settings cannot be changed on a locked study or database.

Step 1 — Enable eConsent

Go to Consent > Availability and turn on Enable eConsent.

Once enabled, consent becomes a gate: participants must consent before they can take part in the study. This is deliberate and follows ICH-GCP — nobody should engage with any part of the research before consenting.

The same tab shows the public consent URL for your default form, in the form:

https://app.trialflare.com/consent/<your trial code>

This is the link you share with prospective participants. They can open it on a phone, tablet or desktop; no account or app is needed.

Alongside the switch is a dropdown controlling whether new consents are accepted:

  • Allow new eConsents — the normal state.
  • Prevent further eConsents — closes the form to new submissions while still requiring existing participants to have consented. Use this when recruitment closes; the link then shows that consent is closed rather than breaking.

Go to Consent > Informed consent forms and click Create new. Your first form is created as the Default Consent Form with the form key default.

The editor has five tabs.

Participant Information Sheet

The main body of the form: what the study is, its purpose, what taking part involves, and any risks or benefits. This is a rich text editor and supports images, so you can include diagrams or a study logo.

Eligibility

Your eligibility criteria, as a single block of text. Participants must tick and initial to confirm they meet them. Leave it empty if you do not want an eligibility confirmation step.

Conditions

Individual statements the participant agrees to one at a time — "I understand that I may withdraw at any time without giving a reason", "I agree to my GP being informed", and so on. Each condition has a title and a description, and each is separately ticked and initialled.

Conditions can be reordered with the arrows, and each can be marked Optional. An optional condition can be declined without blocking consent, which is how you handle things like agreeing to be contacted about future studies.

Verification

Verification methods determine how a participant proves the contact details they give are theirs. Choose at least one of Text message (SMS), WhatsApp and Email. SMS and WhatsApp only appear if those channels are enabled for your team.

Each method you enable can also be marked Required. A required method must be provided and verified before the participant can submit their consent; anything left optional can be skipped, as long as at least one method is verified. So if you enable Email and WhatsApp but mark only Email required, a participant can consent with an email address, or with an email address and a WhatsApp number — but not with WhatsApp alone. Mark nothing required and any single verified method is enough.

The participant sees a red Required badge against each contact field you marked required. Nothing is labelled optional: at least one method always has to be verified, so a field with no badge is one they may skip only if they verify another — which the wording above the fields explains. When you enable just one method it is always badged, since it is the only way to consent.

Whatever they use here is what they will later use to log in: when the participant first opens the study in the app, they enter the phone number or email address they consented with and confirm a code sent to it. That is what ties a consent record to a real person and, in turn, to a participant account. The app only offers the methods your consent forms actually enable — if none of your forms use email, the app greys the email option out and starts the participant on the phone one.

If someone reaches that screen without having consented, the app offers them a link to your consent form — but only where the trial has a single form. With more than one, the app cannot tell which form applies to them, so it asks them to use the consent link you gave them instead. Send participants the right form's URL directly if you run several.

Connect contact details automatically attaches the contact details given during consent to the participant record when they join. Turn this on if you want to be able to message that participant later without re-collecting their details.

Identity verification adds an ID document check through our KYC provider, matching the participant's details against official ID. It is useful against participant fraud in remote and incentivised studies. It requires the feature to be enabled for your team, and each completed check is billed to the study wallet. When it is on, the name given on the consent form must match the name on the verified ID, or the submission is rejected.

Settings

Setting What it does
Consent form key Short identifier that forms part of the form's URL (e.g. default, parent, teen).
Consent form name A human-friendly label, used only inside Trialflare so you can tell forms apart.
Notification email An address that receives a copy of every signed consent, with the PDF attached. Typically your study coordinator or a shared study inbox.
Withdrawal contact email If set, the participant's confirmation email tells them how to withdraw consent and gives this address to contact.
Post-consent on-screen text Rich text shown on screen immediately after consent is given. This is where you put "what happens next" — including links.
Post-consent notification A short message (400 character limit) sent to the participant after consenting.
Continue to a questionnaire Adds a button at the end of consent that takes the participant straight to a questionnaire stage, for screening that happens after consent.

The two post-consent fields are worth distinguishing. The on-screen text is seen once, right after signing, and can be as long as you like. The notification is sent to them and so is something they keep — but it is capped at 400 characters to fit within an SMS.

How the post-consent notification is delivered. It is appended to the participant's confirmation email, and sent as a separate SMS where the participant gave a phone number and is not using WhatsApp. It is not included in the WhatsApp confirmation, which uses a fixed template. If your next step matters, put it in the on-screen text as well.

Continue to a questionnaire only offers stages with questionnaire mode enabled that also verify an email address or phone number — the public link is what you send someone to, and the verification is what ties their response back to their consent. The button carries the contact details the participant just gave, so they don't type them again, and links the response they submit back to their consent — which then shows in the Consent column on that questionnaire's responses and the Screening column on your signed consents list, where clicking it opens their answers. The link is personal to that participant and lasts seven days; it is not a way past the questionnaire's own contact checks, so a forwarded link produces an ordinary unlinked response rather than one filed under the consenter's name. Consent and screening from a single link walks through the whole flow.

Don't forget to click Save consent form when you are done.

Step 3 — What the participant sees

The participant opens your link and works down the form: information sheet, eligibility, conditions, then their full name and contact details, then the study conditions and privacy statement. If identity verification is enabled, they complete the ID check before they can submit.

Trialflare checks that all of their initials match before accepting the form — a small guard against someone else initialling part-way through.

When they submit:

  1. A signed PDF is generated, including an audit trail of the consent session.
  2. If they gave an email address, they receive a confirmation with the PDF attached, your post-consent notification, and withdrawal instructions if you configured a withdrawal address.
  3. If they gave a phone number, they receive an SMS confirmation (or a WhatsApp message if they consented via WhatsApp).
  4. Your notification email address, if set, receives its own copy with the PDF attached.
  5. Your post-consent on-screen text is displayed.

Go to Consent > Signed consents. Every consent given against the study is listed here, newest first, with a filter box and pagination.

Each row shows:

  • Consented at — the date and time of signing.
  • Consent key — which of your forms was signed.
  • Name and contact details as given by the participant.
  • Participant — a link to the participant record, once the person has joined the study and verified their contact details. Until then this stays blank, which is normal: a consent exists before a participant account does.
  • Identity verification — status and, where verification ran, the name, address, documents used and any decline reasons.
  • Download — the signed PDF.
  • Events — the session audit trail: each step of the consent session with its timestamp, IP address and browser.

Copies also arrive by email at the notification address you configured, so many teams never need to visit this tab day to day. It is the definitive record, though, and the place to go when you need the audit trail rather than just the document.

You can also see a single participant's consent from their own record in the participants area.

Editing a form after people have consented

Saving changes edits the form in place, and Trialflare will warn you if consents already exist against it.

Existing signed consents are not affected. Each consent PDF is generated from a snapshot of the document as it stood when that participant started their session, and the snapshot is hashed and stored with the record — so what you see in Signed consents is always what that person actually agreed to, regardless of later edits.

That protects the record, but it does not decide the science for you. If the change is substantive, participants who consented to the earlier wording will need to consent again, and that is a decision for you and your ethics committee — Trialflare will not re-prompt them automatically.

Deleting a consent form is possible but leaves any consents signed against it orphaned, and removes linked participant verification records. The confirmation dialog tells you how many consents would be affected.

If your study needs more than one ICF, click Create new again. Each form has its own key, its own settings, and its own URL:

https://app.trialflare.com/consent/<your trial code>/<form key>

The bare /consent/<trial code> link always points at your default form. Each form's URL is shown at the top of the editor when you select it, ready to copy.

Permissions

Consent is split across three permissions because the settings and the signed documents are very different kinds of sensitive.

To do this You need
See the Availability and Informed consent forms tabs trial.readConsentSettings — also implied by trial.read, so trial-wide viewers already have it
Enable or disable eConsent, and create, edit or delete consent forms Trial administratortrial.admin on the study, or trials.manage at team level
See the Signed consents tab and download signed PDFs trial.readTrialConsents
See an individual participant's consent details on their record trial.readParticipantConsent

Consent records are not covered by trial administrator access. trial.readTrialConsents and trial.readParticipantConsent hold personally identifiable information, and Trialflare treats every PII permission as something that must be granted deliberately. A trial administrator can build and publish your consent form without being able to read a single signed one. If your coordinators need to see signed consents, grant them the permission explicitly.

See Roles and permissions for the full picture.