AnzarSeha

Methodology

By Dr Rida Akodad · Publication director · Updated 21 August 2026

This page describes the method AnzarSeha applies: six principles, what each constrains in the software, and — for each — what it does not guarantee. It is written to be verifiable, not to persuade.

1. Meaning precedes the value

No value is entered before the meaning of its column is written down. The variable dictionary — type, scale, unit, bounds, categories, reasons for absence — is generated when the study is created and constitutes the specification capture must conform to.

Software translation: the collection form is generated from the dictionary, never maintained alongside it. A column with no definition does not exist.

What this does not guarantee: that a definition is the right one. A coherent dictionary can describe a badly chosen variable.

2. The protocol locks before capture

The primary endpoint, inclusion criteria and variable list are fixed before the first value. This closes the door on retrospectively picking the endpoint that yields a result — the bias personal discipline alone does not remove.

Software translation: the lock refuses to engage while no primary endpoint is declared, and while that endpoint does not point to an existing variable. The lock is a dated, signed event in the log.

What this does not guarantee: the absence of other exploratory analyses. The lock distinguishes pre-specified from exploratory; it does not forbid the latter, it prevents it presenting itself as the former.

3. Every value keeps its origin

A value carries one of four origins — registry field, deterministic rule, model proposal quoting its source sentence, justified human decision — and that origin travels with it into the export.

Software translation: origin is a column of the data model, not a comment. A value cannot be recorded without it. Detail: data provenance.

What this does not guarantee: accuracy. A traced value can be wrong; it is only verifiable.

4. The AI proposes, the human confirms

A model never writes a final value. It produces a proposal accompanied by the exact sentence from the source document; without a citation, the proposal is discarded. An identified reviewer confirms, record by record.

Software translation: the "proposed" and "verified" states are distinct in the model, and the export distinguishes them. A logged consent gate precedes every external call; without it, only the rule engine runs. Detail: assisted extraction.

What this does not guarantee: that the reviewer is right. The method moves responsibility to a named person — which is the point — without removing it.

5. The database freezes before analysis

The dataset analysed is exactly the one exported, on a given date. Reopening a frozen database stays possible but requires a written reason, kept in the log.

Software translation: the freeze is a study state, dated and signed, not a convention. Reopening is not forbidden — it is expensive in traces, which is enough to make it exceptional.

What this does not guarantee: stability of the source records. A record corrected after the freeze diverges from the frozen dataset; that is intended, and it is why the dataset carries its date.

6. The log is chained, therefore verifiable

Each log event is sealed by the digest of the previous one. Altering a past entry breaks the chain visibly.

Software translation: chain integrity is recomputed and displayed as a state, not as an administration option. Detail: the audit trail.

What this does not guarantee: that tampering is impossible. An administrator can recompute the whole chain. What the mechanism achieves is more modest: tampering stops being silent.

Standards followed

These standards are followed, which amounts to no certification and is never presented as one.

StandardWhere it applies
ICH E6(R3)General frame: integrity, traceability, responsibilities
CDISC CDASHNaming and definition of capture variables
CDISC SDTMDownstream tabulation structure
SNOMED CT · LOINC · ICD-10Terminology mappings in the dictionary
UCUMNormalised writing of units
STROBE · EQUATORReporting draft and completeness of the write-up
FAIR principlesRich metadata accompanying the export

What the method does not claim to solve

  • The choice of question and clinical relevance: outside the software's scope.
  • Selection bias: a poorly assembled cohort stays so, however traceable the capture.
  • Statistical power: no management method compensates for insufficient numbers.
  • The regulatory compliance of a given study: that rests with its data controller and the competent committee.
  • The accuracy of the source record: an erroneous observation yields a traced, wrong value.

Frequent questions

Is this method compatible with a regulated clinical trial?

The principles are; the tool is not positioned on that ground. A sponsored trial additionally requires documented software validation, formalised discrepancy management and submission traceability that go beyond investigator-initiated research.

What if the primary endpoint has to change?

It can change, provided the change is dated, justified and logged — and reported as such in the publication. What the method prevents is not change, it is silent change.

Must all six principles be followed to use the tool?

Five are applied by construction and cannot be worked around. The fourth — AI proposes, human confirms — applies only if a model is used; with no recorded consent, only the deterministic rule engine runs, and the study remains possible.

Sources and standards