Deciphera Lets Data Managers Grant CRO Access on Files.com Without Risking Blinded Studies

Deciphera Pharmaceuticals is a biopharmaceutical company running an active pipeline of clinical and pre-clinical research programs. Its clinical studies depend on external partners: contract research organizations, labs, and specialist vendors, all exchanging clinical and medical study data with Deciphera for the life of each study.
The same CRO contact tends to recur, working across several studies over the years. And some of those studies must stay blinded, which means data segregation is not only a compliance requirement but a scientific one. If the wrong person sees blinded results, the study itself is at risk. At Deciphera, deciding who can reach which study's files is a question about the integrity of the science.
Every Access Change Ran Through One Administrator
On Deciphera's legacy on-premises SFTP server, every user account was created by hand, and folder access lived in permissioning embedded in the server's virtual file shares, a structure only a central administrator could safely change. Every access change for clinical collaboration therefore routed through central IT: a new study starting, a vendor picking up work on an additional protocol, a CRO contact rolling onto their third project.
The cost landed on the studies. The people who knew exactly who needed access, the data managers who own each study, could not act on that knowledge. They filed a request and waited on a central queue, and that queue grew with every new study and every new collaborator, while the team behind it did not. As the pipeline expanded, provisioning became a standing tax on clinical collaboration itself.
The Obvious Fix Was Also the Dangerous One
The obvious answer is to hand data managers administrative rights so they can grant access themselves. In a blinded-study environment, that answer is exactly the problem. Broad administrative authority is the ability to see, or grant, anything.
“We have a lot of data on the platform that, if people who are not supposed to see it see it, could jeopardize the project.”
So the fix had a precise specification. Data owners had to be able to stand up study folders and add or remove collaborators themselves. The authority they held had to stop at their own studies, with no way to grant broader rights. And every permission and every file operation had to land in a record that could later prove segregation held. The legacy server offered no such role: its permissioning was central or nothing. Deciphera had already brought in Files.com to retire that server, and the platform's delegated administration supplied exactly the bounded role the specification called for.
A Group Admin per Study, a Scoped Folder per Vendor
Each clinical study runs as a project folder tree on Files.com. The data manager who owns the study holds read-write or full access at the top of the tree, and Deciphera made each of them a Files.com group admin for their study's groups. External vendors get scoped read-write access within subfolders, dropping files off and picking files up under the same folder and reaching nothing beyond it.
When a CRO contact already working one study picks up a second, the second study's data manager adds that existing user to the group they manage, and the group's predefined folder permissions decide what the membership grants. Each project remains under the control of the data manager who owns it.
The boundary is structural rather than procedural. A group admin's reach ends at the groups they manage. Site security settings, protocol configuration, and the granting of administrative authority stay with Deciphera's central IT. And Files.com records the whole arrangement: permissions audit reports show exactly who could reach each study's folders, while action logs, login history, and complete file-operation logs show what actually happened to every upload of clinical and medical study data.
Provisioning Moved to the Study Owners
With the study folders live on Files.com, Deciphera replaced a central provisioning queue with a delegation model its data managers run themselves.
- Adding a collaborator or standing up a new study no longer touches central IT. The study's data manager creates the folders, manages group membership, and assigns vendor access directly.
- Delegation added no new exposure. A data manager's authority ends at their own studies, and the settings that govern the site's security posture never left central hands.
- Access integrity is provable rather than asserted. Permissions reports show who could see what, and complete file-operation logs show what was done, which is the evidence that blinded data stayed segregated and that study results stand up.
The compounding effect is the larger one. Because the pattern is a folder tree, a group, and a group admin, every future study inherits it. Growth in the clinical pipeline no longer produces growth in the central provisioning queue.
The People Who Own the Science Own the Access
Today, when a study starts, the data manager who runs it builds its folders on Files.com, grants each vendor its scoped drop-off, and adds the CRO contacts who will work it, often the same people they worked with on the last one. What used to be a request to a central administrator is now simply part of running the study, and when the question comes of who could have seen blinded data, the answer is a report, not a reconstruction.
Delegation and control read as opposites in blinded clinical research. Deciphera's deployment shows they are not. Data owners can run collaborator access themselves, provided the role they hold is structurally unable to reach beyond their own studies and every operation lands in the log. On Files.com, Deciphera did not have to choose between moving fast for its studies and protecting the science they exist to produce.
Related Customer Stories
Health & Life Sciences
Nestlé Health Science Moves 10 TB of Regulated Acquisition Data in One Month with Files.com
A repeatable SFTP staging and verification workflow keeps multi-terabyte GxP data moving without waiting six months to a year for internal infrastructure.
Read story →
Health & Life Sciences
Abcam Retired Its Self-Hosted FTP Servers With Files.com at MuleSoft’s Transfer Edge
A UK-locked landing zone now handles machine traffic from FTP-only counterparties while MuleSoft continues to orchestrate the integrations behind it.
Read story →
Health & Life Sciences
Everly Health Solutions Configures 40 Health Plan SFTP Connections in Files.com, Not Custom Code
Files.com Remote Servers and automations now move regulated clinical reports from AWS to payer-owned endpoints while operations staff handle routine delivery.
Read story →