Skip to article frontmatterSkip to article content
Site not loading correctly?

This may be due to an incorrect BASE_URL configuration. See the MyST Documentation for reference.

Role Catalogue

This page explains the responsibilities of each role within a FRIDGE deployment, covering both the overall governance and shared responsibility architecture and the operational processes across the FRIDGE lifecycle.

Role Summary

TRE Operator Organisation
Operates the Home TRE and the FRIDGE Satellite TRE, manages technical security controls, and may receive delegated approval authority from the Data Owner. See details.
FRIDGE Hosting Organisation
Provisions and secures resources on the FRIDGE hosting facility to host the Satellite TRE. See details.
Resource Allocator
Approves compute resource requests and monitors resource utilisation of the platform hosting FRIDGE. See details.
FRIDGE Federation Governance
Accountable for risk, determining requirements, and monitoring performance. See details and FRIDGE Governance.
Operational Management Group
Representatives from the technical groups running FRIDGE, information governance experts, and researchers as appropriate to manage risk in day-to-day operations. See details and FRIDGE Governance.
Information Governance Team
The team within the TRE Operator Organisation responsible for information governance and compliance. See details.
TRE Administrator
Deploys FRIDGE components under responsibility of TRE Operator Organisation (blue in the diagrams). See details.
Hosting Administrator
Deploys FRIDGE components under responsibility of FRIDGE Hosting Organisation (green in the diagrams). See details.
Principal Investigator
Leads research projects, submits Safe Project applications, and nominates researchers. See details.
Safe Researcher
Researcher who has completed training, signed attestation, and been approved for data access. Authorised to use the TRE. See details.
Job Submitter
A subset of Safe Researcher who can submit FRIDGE jobs (that is dispatch jobs to a remote resource). See details.
Data Owner
The organisation or individual that owns the sensitive data used in the research project. See details.

Organisational Roles

TRE Operator Organisation

The organisation that runs the Trusted Research Environment used by researchers, which is the “front door” through which researchers access sensitive data. This is typically a university, research institution or data provider that operates a TRE. The TRE Operator Organisation is accountable for researcher accreditation, data governance within the TRE, and the security of the research environment built on top of the FRIDGE infrastructure.

Governance and architecture responsibilities

Lifecycle process responsibilities

FRIDGE Hosting Organisation

The organisation that owns and operates the supercomputing infrastructure on which FRIDGE runs. This is likely to be a national compute facility such as AIRR. This role could also be fulfilled by a public cloud provider or a private cloud hosted by another institution.

Governance and architecture responsibilities

Lifecycle process responsibilities

Resource Allocator

Responsible for managing access to the supercomputing platform. This role controls who can use the platform and how much compute resource they are allocated. On national infrastructure this is likely to be a national body appointed by government. For public cloud the resource allocator will be the bill payer.

Governance and architecture responsibilities

Governance Roles

FRIDGE Federation Governance

The strategic governance body for the FRIDGE federation, bringing together senior representatives from the TRE Operator Organisation, FRIDGE Hosting Organisation, and the Resource Allocator and provides the accountability and oversight layer that sits above day-to-day operations. It also incorporates a PPIE function to ensure public and patient perspectives are reflected in how sensitive data research is conducted.

Governance and architecture responsibilities

Operational Management Group

A cross-organisational working group made up of representatives from the technical, governance, and research teams involved in operating FRIDGE. A standing group that brings together the parties who need to coordinate to keep the platform running safely. Membership includes the Information Governance Team, the Hosting Administrator, the TRE Administrator, and researcher representatives as appropriate.

Governance and architecture responsibilities

Information Governance Team

The team within the TRE Operator Organisation responsible for information governance.

Governance and architecture responsibilities

Technical Roles

TRE Administrator

A technical team within the TRE Operator Organisation with hands-on responsibility for deploying and maintaining the TRE and its FRIDGE components. Typically research computing or platform engineers who understand both the security requirements of TRE operation and the technical implementation of the FRIDGE architecture, including Kubernetes, Satellite TRE deployment, and the connection between the TRE and FRIDGE clusters.

Governance and architecture responsibilities

Lifecycle process responsibilities

Hosting Administrator

A technical team from the FRIDGE Hosting Organisation with hands-on responsibility for the underlying supercomputing infrastructure. Operates at the infrastructure layer by managing physical or virtual hardware, network isolation, and cluster provisioning with no access to the TRE itself. They act on instructions from the TRE Administrator but operate within the security boundary and policies of the FRIDGE Hosting Organisation.

Governance and architecture responsibilities

Process responsibilities

Researcher Roles

Principal Investigator

The academic or research lead responsible for a specific research project using FRIDGE. They are the named individual accountable for how sensitive data is used within their project.

Governance and architecture responsibilities

Process responsibilities

Safe Researcher

A researcher who has been formally accredited to access sensitive data within the TRE. Safe Researchers work within the TRE but do not directly interact with the FRIDGE infrastructure.

Governance and architecture responsibilities

Process responsibilities

Job Submitter

A Safe Researcher who has been granted additional permissions to interact directly with the FRIDGE API. They may use the API to submit compute jobs, manage container images, and retrieve results. Not all Safe Researchers will need or hold this role; it is assigned to those members of the research team who are responsible for the computational aspects of the project, such as running AI models or large-scale data processing workloads on the supercomputer.

Governance and architecture responsibilities

Process responsibilities

External Roles

Data Owner

The organisation or individual that owns the sensitive data being used in the research project. This is typically an NHS organisation, government body, or other institution that holds personal or sensitive data and has the legal authority to permit its use for research purposes. The Data Owner sets the conditions under which data may be used and must receive assurance that those conditions, including data deletion at project end, have been met.

Process responsibilities