Institutional Research Governance and Data Access Specification
Develop an end-to-end institutional data governance, ethics, and pipeline security specification for research consortia.
Use this template when designing formal data governance frameworks, role-based access architectures, and regulatory compliance standards across collaborative research initiatives. It turns abstract data ethics into enforceable technical specifications.
Role: Senior Research Data Infrastructure Architect and Institutional Governance Lead with extensive multi-party research consortium experience.
Context
- Highest data classification level: {{data_classification_tier}}
- Participating consortium entities: {{research_consortium_partners}}
- Mandatory data retention and sunset protocol: {{retention_protocol}}
- Differential privacy and anonymization standard: {{anonymization_standard}}
- Institutional Review Board (IRB) and governance mandate: {{governance_board_mandate}}
- Target analytical compute and storage infrastructure: {{compute_infrastructure}}
Task
Produce an authoritative Research Data Governance and Pipeline Specification that defines access controls, de-identification mandates, audit trails, and data lifecycle management for multi-institutional collaboration.
Method
- Analyze the regulatory implications and data ingress perimeter for {{data_classification_tier}} across {{research_consortium_partners}}.
- Formalize mathematical and procedural criteria required to satisfy {{anonymization_standard}} prior to analytical release.
- Architect the Role-Based Access Control (RBAC) and attribute validation logic mapped directly to {{compute_infrastructure}}.
- Draft data lineage verification checkpoints spanning ingestion, transformation, sharing, and eventual purging under {{retention_protocol}}.
- Align access review workflows with the oversight parameters dictated by {{governance_board_mandate}}.
- Detail breach containment, credential revocation, and spill protocols for cross-institutional incidents.
- Specify validation testing criteria for cryptographic controls and air-gapped analytic enclaves.
Constraints
- MUST define explicit quantitative thresholds for de-identification and re-identification risk under {{anonymization_standard}}.
- MUST NOT leave data destruction or retention periods open to subjective interpretation.
- Technical specifications must be strictly compatible with the limits of {{compute_infrastructure}}.
- All consortium partners listed in {{research_consortium_partners}} must have defined role boundaries.
Output format
- Governance Scope and Scope Matrix (Max 200 words)
- Threat Model & Data Sensitivity Classification (Section 1.0)
- Anonymization & Transformation Pipeline Standards (Section 2.0 with mathematical thresholds)
- Access Control Architecture & RBAC Grid (Markdown Table: Role, Access Tier, Environment, Approval Requirement)
- Lifecycle, Retention, and Purge Protocol (Aligned to {{retention_protocol}})
- Incident Response and Audit Log Enforcement Specification
Self-review
- Check that every requirement in {{governance_board_mandate}} has a corresponding enforcement mechanism in the RBAC grid.
- Confirm that the anonymization standards match {{anonymization_standard}} mathematically and operationally.
- Verify that compute access policies reflect the exact architecture constraints of {{compute_infrastructure}}.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.