Set the study up
From the plan you were sent, not from a blank form.
It reads the study plan you were sent
Point it at the sponsor’s .docx and it fills identity, the treatment-groups table, dosing frequencies and the schedule. Then it shows you what the document said, so you check the extraction rather than trust it. The file is hashed on the way in.
The arithmetic runs while you decide
Cage counts, tag prefixes, arrival and receive dates, arm colours and the balance variables reconcile on every step of the wizard, so the reconciliation happens while you are deciding rather than after you have committed.
GLP mode blocks what it should
On a GLP study, randomisation stays shut until the Study Director approves the plan, and an unwritten protocol element blocks approval rather than printing blank.
§ 58.120(b)And the tables the protocol prints
The treatment-groups table is the protocol’s, not a re-typing of it: scheduled end, route, dose and n per group, with the interim cohorts carried as their own rows, so the schedule and the table cannot drift apart.
| Group # | Treatment | Scheduled end | Route | Dose | Total per group |
|---|---|---|---|---|---|
| G1 | Vehicle | day 54 terminal | IV (bolus) | — | 6 |
| G2 | Mock-transduced T cells | day 54 terminal | IV (bolus) | 1×107 cells/animal | 6 |
| G3 | CAR-T 1×106 | day 54 terminal | IV (bolus) | 1×106 CAR+/animal | 6 |
| G4 | CAR-T 3×106 | day 54 terminal | IV (bolus) | 3×106 CAR+/animal | 6 |
| G5 | CAR-T 1×107 | day 54 terminal | IV (bolus) | 1×107 CAR+/animal | 6 |
| G6 | CAR-T 1×107 + IL-15 | day 54 terminal | IV (bolus) | 1×107 CAR+/animal | 6 |
| G5a | CAR-T 1×107 | day 21 interim necropsy | IV (bolus) | 1×107 CAR+/animal | 3 |
| G6a | CAR-T 1×107 + IL-15 | day 21 interim necropsy | IV (bolus) | 1×107 CAR+/animal | 3 |
Randomise it defensibly
The moment a study becomes something you can defend.
Nothing is written until you commit
Stratified or blocked allocation with a live preview and a balance table across every variable, all of it seen before anything is written. Committing asks you to authenticate again.
A method of record
Seed, method, the measurement allocated on, and who signed, all on the record. Revoking an allocation takes a verbatim reason and is itself a protocol amendment.
§ 58.130(e) · ARRIVE 2.0 item 3Out in the forms the site works from
The roster prints with the cage on it, because animals are placed from a cage card. The allocation also comes out as a workbook for the facility in one click.
Run it
At the rack, in gloves, with the software refusing the things that go wrong quietly.
The dose basis is today’s weight
Volume comes from the most recent weight and the row names the study day it came from, because a nine-day-old weight is not today’s dose basis. The route ceiling blocks rather than advises, and a welfare hold cannot be cleared from this screen.
Welfare has a tier before the flag
Rules run at every capture. Above the open flags sits Approaching thresholds: the animals near a limit across every in-life study, with USDA-aligned pain and distress counts. A technician sees a flag and cannot stand it down.
§ 11.10(g)The site’s file, however it arrives
.xlsx, legacy .xls, delimited text, or a range pasted straight out of a spreadsheet. Columns are guessed per measurement kind and every row gets a verdict: Ready, Check value, Conflicts with record, Unknown animal, Already on record.
Read it out
The part that usually costs a week.
Every figure is drawn from the record as it stands: group means with SEM, per-arm small multiples, the response waterfall, bioluminescence, body-weight nadir, and Kaplan–Meier with a two-sided log-rank p against the reference control.
Then seven buttons, each replacing something somebody used to assemble by hand. The labels below are the app’s own.
Composes the report from the record: design, group summary at the analysis day, tumour figures, waterfall, bioluminescence, body weight, Kaplan–Meier, welfare and mortality, protocol deviations, data provenance, individual animal data. Then it freezes the document byte for byte with a SHA-256, tags it Interim or Final with its data-cut day, and prints. Asked in a year what March received, you reprint it rather than rebuild it.
Day matrices, animals down and study days across, one sheet per endpoint: body weights, tumour volumes, bioluminescence. Then group summaries, dosing, welfare, and the audit chain in the same file.
Everything the workbook has, plus the rows that were superseded and retracted, labelled in the status column. The copy you hand an inspector rather than the one you hand a biostatistician.
The card exports its own chart with the page’s colours resolved to literal values, so the file stands alone in a deck and still reads. Screenshot-and-crop was the only route to a figure before this.
The audit trail as JSON, carrying the verification result, the genesis hash, the digest algorithm, the canonicalisation rule and both versions of the hashed field list, so a recipient can re-verify a chain written across a schema change. The export is itself recorded.
The inspection log as § 58.35(c) asks for it: date, phase, inspector, findings, action recommended, action taken, who it was reported to, and the re-inspect-by date.
Every study at the facility indexed by test article, derived rather than typed, and exported as a CSV dated in its filename. It counts the gaps it will not guess at, including studies with no named Study Director.
Prove it
Compliance is not a module bolted on here. It is what the other four stages were doing all along, which is why the citations below are screens rather than promises.
The four records the unit must keep
Master schedule, inspection log, periodic status report and the signed statement. The log is the one screen in VivoDock a Study Director reads and cannot write, because § 58.35(a) separates the unit from the people conducting the study.
Who did this, and for whom
Name, role and organisation are hashed into every event, so a record three companies write to can still say which one acted. The prior value is shown un-obscured beside the new one, with the reason that was given.
An export that verifies without us
The chain leaves with the algorithm that checks it. A sponsor, a QA unit or an inspector can re-verify the record on their own machine, including across the version change in how events are hashed.
What § 58.130(e) looks like when it is a screen
A protocol amendment, with the prior wording beside the new, the addition marked, the reason in the words the operator typed, and the signature that closed it. Not a note that something changed. The change itself, kept.
Two of those are marked partial on purpose. § 11.70 record linking and the § 11.200 signature controls are built far enough to use and not far enough to claim. VivoDock says the same thing on its own compliance screen, under a heading called “What is and is not implemented”, because a claim you cannot check on the day an inspector asks is worth less than nothing.
Ask to see it running.
We walk you through VivoDock as it stands, on a study already in it: the capture screens at the rack, the figures redrawing as measurements land, and the report coming out the other end. Thirty minutes, or as long as your questions take.