Skip to main content
OpenIRB

Registry

Make review findable without making sensitive evidence public.

An OpenIRB registry records review metadata, decision status, policy version, continuing review obligations, and optional custody references. It should support accountability while respecting privacy, confidentiality, and regulated data boundaries.

Registry principles

Layered registry privacy: public metadata over permissioned artifacts over sensitive source material.
A registry can preserve accountability without exposing sensitive evidence.

Minimum necessary disclosure

Publish only what should be public. Protect sensitive evidence.

Permissioned depth

Public metadata can coexist with permissioned artifacts for reviewers, auditors, regulators, or institutional stakeholders.

Versioned decisions

A review can change. The registry should preserve versions and decision history.

Continuing obligations

Approval conditions, monitoring schedules, and renewal dates should remain visible to authorized users.

Custody references

Where relevant, a registry entry can reference a trust receipt, hash, or custody record.

The registry is not a data dump.

Potential fields include registry ID, review ID, object title and type, sponsor organization, domain, risk class, decision status, conditions summary, review date, continuing review due date, policy version, evidence packet hash, decision artifact hash, trust receipt reference, public summary, and access classification.

The purpose of a registry is not to expose private or regulated material. The purpose is to preserve enough review metadata for accountability, coordination, oversight, and institutional memory.