Govern research ethics
How I work, encoded as skills — 88 portable AI SKILL.md files (research, design, AI-product, motion, code, business). Fork it, make it yours. Inspired by @mattpocock + @emilkowalski, grounded in NN/g.
npx -y skills add dineshrevunuru/SuperSkills --skill govern-research-ethicsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
2 things to look at
- 23 days oldThe repository was created 23 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
- 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
The canonical research-ethics GATE — consent, participant data/PII, retention, and compensation — loaded BEFORE you recruit or hit record, the way name-and-control-bias is loaded before trusting a finding. Sized for a solo/freelance operator, not a corporate legal department: it covers what the RESEARCHER personally owes a participant on top of whatever a client NDA already handles. Use when the ask is 'do I need consent?', 'is it okay to record?', 'how do I handle their data', 'what do I do with the recordings', 'GDPR/CCPA for research', 'how much do I pay participants', 'they told me something really personal', 'this participant seems vulnerable', 'the client wants them to sign an NDA', or before ANY session with a real person. Consent is a process, not a signature; ethics is a gate, not a footnote.
SKILL.md
20.4 KB, as published. Nobody here has run it
Govern Research Ethics
Before a real person gives you their time and their data, you owe them four things: to know what they're in, to be able to leave, to have their data minimized and deleted, and to be paid without strings. This file is the single source of truth for that gate.
The scope line (why this skill is light, not a legal apparatus)
On client freelance work the client's NDA and contract already own the legal layer — IP, confidentiality of the client's business, who owns the findings. This skill does not re-litigate that. It owns the layer the contract doesn't cover: what you, the researcher, personally owe the human in the room — honest purpose, a real exit, control of their own data, and clean compensation. That obligation exists whether or not any contract mentions it, and it is yours, not the client's, to honor.
How to use this reference — two modes
You are almost always here because you are about to recruit or about to record. Pick the mode by stakes:
- Minimum-viable-ethics (scrappy path): run the 6-item gate below. ~5 minutes before you hit record. Use for low-stakes, non-sensitive freelance sessions with ordinary adult participants.
- Full protocol (rigor path): work the six areas (consent content · recording/PII · GDPR/CCPA principles · compensation · duty-of-care · vulnerable-participant escalation). Use for anything health-adjacent, emotionally sensitive, vulnerable-participant, or externally published, and for any client deliverable.
Situational, not a liturgy. Apply the controls the actual study exposes. A 15-minute unrecorded hallway test of a button label does not need a retention schedule; a recorded interview on an emotionally sensitive topic needs the whole protocol. Spend your rigor where a real person is actually exposed — but the 6-item gate is the floor, never skipped.
The one rule that separates this from theater
Consent is a process, not a signature. A signed form at the top of a session is not consent if the person didn't understand what they agreed to, can't remember they may leave, or feels they'll lose their payment by stopping. Consent is live: it is re-offered when the topic turns sensitive, and it holds only as long as the person is still freely in. A form you collected and never honored (kept recording after they hesitated, reused the clip for marketing) is paperwork, not ethics. The test is not "did they sign?" — it's "could they leave right now, understand what leaving costs them (nothing), and would I actually stop?"
The layering rule — client NDA vs. what you still owe the participant
When a client NDA governs, split the two cleanly. They are never the same document and never bundled into one signature:
| The client's NDA/contract owns | What YOU still owe the participant, regardless |
|---|---|
| Confidentiality of the client's business, unreleased product, roadmap | Honest purpose in plain language — what this session is really for |
| Ownership of the findings and deliverable | The right to withdraw mid-session without losing compensation |
| Your obligations to the client | Data minimization + deletion of their recording on request |
| IP in what gets designed | No surprise reuse of their words/face (e.g. as a marketing testimonial) |
The trap to refuse: making the participant sign the client's NDA — or a broad marketing/publicity release — as a condition of being paid or being in the study. The NDA protects the client; it must not be the instrument that strips the participant of their own rights. If the client needs the participant to keep an unreleased product confidential, that is a narrow, separate confidentiality ask, explained on its own, and it still cannot be tied to withholding the incentive. Consent to participate, confidentiality of the client's secret, and any marketing release are three separate yes/no decisions — unbundle them.
Minimum-viable-ethics — the 6-item gate (scrappy path)
Run this out loud before you record. If any item fails, you are not ready to field.
- Said, not assumed: who you are, why you're here, that you're recording, and how the recording will be used. (Spoken counts; see the script below.)
- The exit, spoken: "You can skip any question or stop anytime, and you'll still be paid." Voluntary + withdraw-without-penalty, stated in words they heard.
- A home and a death date for the data: one access-controlled place only you can open, and a deletion date you set right now — not "someday."
- Collect only what the question needs: no legal name, address, or medical detail you won't actually use. Minimize at the point of capture, not later.
- Compensation is clean: amount and terms stated plainly, and not contingent on signing anything or on saying nice things about the product.
- Sensitivity check: if the person is vulnerable, or the topic is health-adjacent/distressing → stop, escalate to the full protocol (no scrappy path here).
If you cannot answer item 3 — "where does this recording live and when is it deleted?" — you are not ready to hit record. That is the gate.
Full protocol
(a) Informed-consent content — what the person must actually understand
Consent is informed only if, before recording, they've heard all six:
- Purpose — what the session is for, in one plain sentence (not "a research study" — what you're trying to learn).
- What's captured — audio, video, screen, notes; and specifically whether their face/voice is recorded.
- Voluntary — they chose to be here and can decline any part.
- Right to withdraw without penalty — they can stop mid-session, skip any question, and still receive full compensation. State it before it's needed, not only if they balk.
- How the data is used — who sees it (just you? the client? in a report?), whether it's quoted, whether their identity is attached or de-identified.
- Retention & deletion — that it's stored securely and deleted on a schedule (and on request).
Copy-ready short consent script (spoken, ~30 seconds — adapt, don't robotically read):
"Before we start — I'm [name], and I'm doing research on [the real topic, e.g. how people book a salon appointment] for [the salon]. I'd like to record audio and screen so I don't have to scribble notes — is that okay? A couple of things: this is completely voluntary, so you can skip any question or stop whenever you want, and either way you still get the [$X] for your time. What you say is used only to improve the design — I'll keep the recording somewhere private and delete it once I've written up my notes, within [N] weeks. I won't put your name or face in anything without asking you separately. Sound good? Any questions before we begin?"
Then wait for an actual "yes." Silence is not consent. If recording, capture the verbal yes on the recording.
(b) Recording & PII handling for a solo operator
You are the whole data-protection department. Keep it small enough that you can actually do it:
- One home. Recordings and transcripts live in one access-controlled location only you can open (a passworded/encrypted drive or a private cloud folder — never a shared link, never the camera roll, never an open Desktop).
- Minimize at capture. Don't collect what you won't use. First name or a participant code beats full legal name. A participant ID (
P1,P2) in your notes instead of names is the cheapest, strongest PII control there is. - Separate the key. Keep the name↔ID mapping in a separate place from the data, and delete the mapping first.
- Retention schedule — set the dates at collection, not later:
- Raw audio/video → delete within [N] days/weeks of writing up notes (define N up front; short is safer).
- Transcripts → de-identify (strip names, employer, anything re-identifying), then keep only as long as the project needs.
- Insights/quotes that outlive the project → carried as de-identified nuggets only (the repository is
build-research-repository's job, not raw-recording storage).
- Access = you. If a recording must go to the client, send a de-identified transcript or a specific clip the participant agreed to, not the raw file — and never on a public link.
- Deletion on request is real. If a participant asks you to delete their data, you must be able to find and delete it. That's only possible if you did the four points above.
(c) GDPR / CCPA as principles (not legalese)
You don't need to be a lawyer; you need to internalize four principles these laws encode. They apply whenever a participant is in the EU/UK (GDPR) or California (CCPA/CPRA), and they're just good practice everywhere:
- Lawful basis / real consent (GDPR Art. 6): you need a legitimate reason to hold someone's data; for research the clean one is freely given, specific, informed, unambiguous consent — which is exactly the process above. Consent that's bundled or coerced isn't valid consent.
- Data minimization (GDPR Art. 5(1)(c)): collect only what's adequate and relevant to the purpose. This is the legal backbone of "don't record what you won't use."
- Right to erasure / right to delete (GDPR Art. 17 · CCPA): a person can ask you to delete their personal data, and you must be able to. Your retention schedule is how you honor this.
- Transparency & purpose limitation: use the data for the purpose you stated, not a new one you invented later (the marketing-clip trap). A new purpose needs a new, separate consent.
Small-operator translation: minimize, secure, tell the truth about use, and be able to delete. Do those four and you're aligned with the spirit of both regimes.
(d) Compensation — stated clearly, kept unbundled
- State the amount, the form, and the trigger before the session ("[$X] gift card, sent within [N] days, whether or not we finish"). No surprises.
- Unbundle it from everything. Payment is for their time, full stop. It is not contingent on: completing the session, signing an NDA or release, giving positive feedback, or agreeing to be quoted. Tying money to any of those turns compensation into coercion and poisons both the ethics and the data.
- Withdrawal doesn't forfeit pay. Someone who stops after five minutes is paid the same. That's what makes the right-to-withdraw real instead of theoretical.
- (Amounts are study-specific — set them per recruit;
write-participant-screenerowns incentive sizing and channels.)
(e) The health-adjacent case — duty of care
Some studies touch a sensitive, health-adjacent topic — say, the booking app for a salon service people feel private about. Participants may disclose real distress — self-image, medical history, shame, relationship strain. That raises the bar:
- Minimize harder. You are researching a booking flow or a chatbot, not their medical history. Don't record or write down clinical/emotional detail you don't need. The most sensitive data is the data you never collected.
- You are a researcher, not a therapist. If someone gets emotional: acknowledge, offer a pause, let them stop — do not counsel, diagnose, or dig for more because it's "rich data." Extracting distress for insight is the violation.
- Emotional safety is a live consent moment. When the topic turns personal, re-offer the exit ("we can skip this — totally fine"). Sensitive disclosure is exactly when consent must be re-confirmed, per the one rule above.
- Sensitive data, sensitive storage. Anything a participant would be mortified to see leaked gets the strictest handling in (b): de-identify immediately, shortest retention, never in a shared or client-visible file.
- Never reuse a vulnerable disclosure as marketing. A sensitive-topic participant's raw words are not a testimonial. That's a separate, explicit, uncoerced release — and usually: just don't.
(f) Vulnerable participants — flag + escalation trigger
Flag (before recruiting): treat as vulnerable if the participant is a minor, has a cognitive/health condition affecting understanding or capacity, is in a dependent or unequal relationship with the study (e.g. the client's own employee, where the client is their boss — power makes "voluntary" questionable), or is in acute distress or a health-vulnerable situation (the health-adjacent case in (e)). Vulnerable → full protocol is mandatory; the scrappy path is off the table. For minors you need a guardian's consent and the child's assent, and generally: reconsider whether you should be running this at all solo.
Escalation trigger (during a session): if a participant becomes distressed, or discloses risk of harm to themselves or someone else — this is not a data-collection moment, it's a duty-of-care moment:
- Stop probing. Stop or pause the recording.
- Attend to the person — acknowledge, offer to pause or end, remind them they're still paid.
- Don't counsel or diagnose. You are not qualified and it's not your role.
- Signpost, don't treat — if appropriate, gently point toward real support (their own doctor, an appropriate resource); for client work, flag to the client's duty-of-care owner. Do not turn it into more research.
- Handle the disclosure as the most sensitive data you hold — or, better, don't retain it at all.
The escalation is away from data and toward the human. If your instinct in a distress moment is "keep the tape rolling, this is gold," that instinct is the failure this section exists to catch.
Worked example — the gate catches a bundled-consent, no-retention sensitive-topic session
Setup as proposed: "Quick one — I'll grab a beta client at the salon this afternoon, ask them about the booking app on my phone. I'll say 'mind if I record?' and hit go. The salon already has them sign the standard client NDA at intake, so consent's covered. I'll keep the clips on my phone in case I need them later."
Run the gate — it catches four failures:
- Consent isn't informed (item 1 + area a). "Mind if I record?" tells them nothing about purpose, use, or deletion, and it's asked after pointing the camera. → Fix: the 30-second script — purpose, what's recorded, voluntary, how it's used, deletion — and wait for a real "yes" on tape.
- Consent is bundled into the client NDA (layering rule). An NDA signed at salon intake protects the salon's business; it is not the participant's research consent, and it may make them feel their payment/service depends on cooperating. → Fix: unbundle. Research consent is its own spoken yes, separate from the NDA, with the exit ("you can stop and still be paid") stated explicitly.
- No home, no death date for the data (item 3 + area b). "Clips on my phone… in case I need them later" is unminimized PII in an unsecured location with unlimited retention — and undeletable-on-request because there's no system. → Fix: record to one access-controlled place, label with a participant ID not a name, set a deletion date now, de-identify the transcript.
- Health-adjacency ignored (area e). Clients of a sensitive service may disclose distress; there's no duty-of-care plan and the clips could become "before/after" marketing. → Fix: minimize what's captured, re-offer the exit if it turns personal, and never route a vulnerable disclosure into marketing.
Verdict: not fieldable as described — it fails the 6-item gate on items 1, 2, 3, and 6. The fix is not "sign more forms." It's the spoken script, three unbundled decisions, one secure home with a deletion date, and a duty-of-care posture. Total added effort: about five minutes and one folder.
Notice what the gate did: it didn't invoke GDPR articles or a corporate IRB. It named the four things that actually exposed this participant and attached a light, real fix to each. That's the solo-operator discipline.
Anti-patterns / red flags
- "They signed the NDA, so consent's covered." An NDA protects the client; it is not the participant's informed consent. Different document, different purpose, never bundled.
- "Mind if I record?" as the whole consent. That's not informed — no purpose, no use, no deletion, no exit. It's a reflex, not consent.
- Payment contingent on finishing / signing / praising. The moment money is tied to compliance, it's coercion and the data is compromised.
- "I'll keep the recording in case it's useful later." Undefined retention is a breach waiting to happen and makes deletion-on-request impossible. Set the death date at capture.
- Mining distress for "rich insight." In a health-adjacent session, digging deeper into someone's pain because it's good data is the core violation — stop, don't extract.
- Reusing a research clip as a marketing testimonial. New purpose = new, separate, uncoerced consent. Usually just don't.
- A signed form as proof of ethics. Consent is a process you honored, not a signature you filed. If you'd have kept recording through their hesitation, the form was theater.
- Running the scrappy gate on a vulnerable participant. Minors, dependent relationships, acute distress → full protocol, no shortcuts.
Boundaries
write-participant-screenerowns the collection point — recruiting channels, incentive sizing, and the screener that first gathers PII. This skill owns what happens to that data after it's collected (consent, storage, retention, deletion) and the ethics of the incentive (unbundled, non-coercive), not its dollar amount.write-research-plancarries the plan's ethics/data-governance section; that section references this skill rather than restating it — this file is the source of truth for consent, PII, retention, and compensation ethics.conduct-user-interviewandrun-contextual-researchown the in-session opening script and field-site consent mechanics; they invoke this skill's consent content and duty-of-care/escalation protocol for the ethics layer.craft-critiqueowns the evidence-discipline protocol — claims are calibrated there, not here. Ethics governs how the data was obtained; craft-critique governs what you're allowed to conclude from it.name-and-control-biasowns validity threats (self-selection, social desirability); a consent violation is an ethics failure, a biased sample is a validity failure — related but distinct. Load both before fielding.build-research-repositoryowns long-lived storage of de-identified nuggets; this skill owns raw-recording handling and deletion before anything reaches a repository.- Design taste and review are handled by
design-taste/craft-critique— not restated here.
Sources
- EU GDPR — Art. 5 (principles incl. data minimization): https://gdpr-info.eu/art-5-gdpr/
- EU GDPR — Art. 6 (lawfulness / consent as a lawful basis): https://gdpr-info.eu/art-6-gdpr/
- EU GDPR — Art. 17 (right to erasure / "right to be forgotten"): https://gdpr-info.eu/art-17-gdpr/
- California CCPA/CPRA — consumer right to delete + overview (California Attorney General): https://oag.ca.gov/privacy/ccpa
- Nielsen Norman Group — ResearchOps 101 (participant management, data governance, tooling): https://www.nngroup.com/articles/research-ops-101/
- Nielsen Norman Group — "How to Recruit Participants for Usability Studies" (incentives, consent, scheduling): https://www.nngroup.com/reports/how-to-recruit-participants-usability-studies/
- Nielsen Norman Group — Recruiting & screening research candidates: https://www.nngroup.com/articles/recruiting-screening-research-candidates/
- Nielsen Norman Group — Context Methods study guide (in-context consent for field/contextual sessions): https://www.nngroup.com/articles/context-methods-study-guide/