Submind YouTube summaries
Thumbnail for Unlock: SATRE and Federation

Unlock: SATRE and Federation

Watch on YouTube

Video summary

The session co-hosted by ARDC and Data Connect Australia introduced SATRE version 2, a community-co-designed specification that defines capabilities for Trusted Research Environments to ensure safety through five overlapping principles: safe people, projects, settings, data, and outputs. While the initial version published in 2023 established four pillars covering information governance, computing technology, data management, and supporting capabilities with numerous mandatory statements, SATRE v2 adds a fifth pillar focused on Federation due to higher risks associated with federated analysis. This new addition introduces seven mandatory capabilities regarding study management, financial oversight, and accreditation without prescribing specific technical tools like Python or R, instead setting observable standards for transparency, auditability, and equivalence across different environments. A central theme of the discussion is that federation serves as a practical tool to foster dialogue on governance standards rather than an exclusionary measure, allowing communities to define their own inclusion requirements within agreed safety boundaries. This approach supports flexible collaboration models such as hub-and-spoke or peer-to-peer networks while addressing critical challenges like sustainability and funding instability which often drive complaints regarding cost recovery for security expenses. The architecture aims to prevent the creation of unsustainable silos caused by fragmented TRE proliferation, encouraging organizations facing uncertainty about long-term data storage to avoid building independent structures in favor of fostering trusted relationships with existing providers across regions like Scotland and internationally. Public engagement remains integral to this evolution, utilizing biweekly "collaboration cafes" involving diverse participants including NEETs and older adults to inform updates alongside documentation hosted on GitHub for open discussion. As the UK TRE community becomes more cohesive, the focus has shifted from rapid technical infrastructure development during short sprints to robust governance processes that require continuous effort in engaging data controllers to demonstrate trustworthiness when accessing new datasets. The control alignment table further highlights gaps left by existing accreditations like ISO 27001 or NHS standards regarding specific TRE needs, reinforcing the necessity of shared responsibility frameworks with clear role documentation for both university-run platforms and provider-led environments. In conclusion, SATRE v2 represents a strategic move toward reducing redundancy while maintaining security through governance-focused collaboration rather than dictating technical implementations. By emphasizing that adoption was easier because many members were already engaged with specifications despite initial time constraints, the initiative underscores the importance of formal data-sharing agreements to support studies like the Rain Study which cannot sustain independent operations alone. Ultimately, the Federation pillar enables communities to define their own federated patterns within safety boundaries, ensuring that as research environments scale and evolve, they remain secure, transparent, and capable of supporting diverse health registers, bio-banks, and national datasets without falling victim to resource limitations or fragmented governance structures.
Read the full video transcript
It's co-hosted by ARDC and Data Connect Australia. Um, and with me today I've got my colleague Kylie who's uh helping facilitate this. Uh, I'd just like to do um I'd like to do an acknowledgement of country. We acknowledge and celebrate the first Australians on whose lands we meet and we pay our respect to their elders past and present. And today I'm speaking to you uh from the traditional lands of the Woodundry Wandery people of the Cooland Nation in Melbourne. Uh and just to let you know uh we are recording this session uh and if if Chris is happy we'll uh uh we'll put it up on the website afterwards so people can uh view it uh afterwards. Okay. So um welcome to Chris Cole. Uh Chris is the principal investigator and lead of the standardized architecture for trusted research environment satra. Um uh he serves as a reader in health informatics uh and AC and he's the academic co-director of the health informatics center at the University of Dundee. Um, and I I've asked Chris to talk about uh SATRA today and uh preferably SATRA v2 because I know it's very topical at the moment, Chris. Uh, and maybe even the new fifth pillar which is Federation of TRES. Um, so Chris will speak for about 35 minutes and we'll leave about um 15 20 minutes at the end for uh questions. So without further ado, uh over to you Chris. I'll stop sharing. >> That's great Roger. Thanks very much. Um, hi everyone. Uh, thanks a lot for coming along and many thanks for the invitation to speak to you today um about Satra, a topic that's very much um, uh, close to my heart. It's something that we've been working on for quite a while. Uh, just a minute. My bar is right in the middle of the screen. Right. Okay. So, uh, thanks so much for the intro, Roger. Yes, as you say, um, I'm Chris Cole. Um I'm reading health of thematics at the University of Inde and I'm also one of the co-directors of the Trevolution program which is funded by day UK which I'll I'll be giving a bit of an intro to um to give context of of the funding landscape of of TRE and and secure environments um across the UK. I'd also like to shout out Tim Tim manin who um was one of the the the lead people in in the in the s development um from the start and in particular in in version [clears throat] two in the federation part and also I noticed Anthony >> I noticed that Anthony tutor is also here um who's one of our public participants who's been involved with such right from the start. So I'll be talking a little bit about um our public involvement around this work as well which has been really influential. So um just to give a bit background of where I come from. So the health informatics center is um a a multi-entered group of different expertise around data linkage, engineering, uh software development, infrastructure, information governance, all the types of things that are important in providing support for sensitive data for research. Um and we've been around 20 years, so we've been doing this for for quite a while and have a lot of experience in this space. Um we're professionally accredited. Um we ISO 27,0001 accredited and then we have a a bunch of UK specific accredititations like the NHS, DSP and the digital economy act um which has been audited by the UK statistics authority. Um we work very closely with our local data providers which is primarily the the NHS. Um we work with with Scottish and UK um large ecosystems of of health and non-health and governmental information and data. Um and we we collaborate widely uh particularly across Europe through various European initiatives like uh European open source cloud and uh the Eden project. Um we sit within the Scottish safe network. So health is a devolved um power in Scot in the UK and because we work primarily with health data that is also devolved. So England, Scotland, Wales and Northern Ireland have different health services and they they're managed independently. So the health data management is also managed differently. So we've had the Scottish safe haven running since about 20145. Um the charter was updated just this year, sorry, last year. And we're all um accredited to do ISO 7,01. Um but you know, we have some additional accredititations and we we cover so Scotland split into four regions and we cover the east of Scotland region and have access to around 2.2 million pounds uh pounds million people's worth of data. Um and have managed the TR for over 10 years now. Um we have a significant data capability uh as that has been our bread and butter since since day one really. So we have um yeah hundreds of millions of records. We standardize our data. We have many many different types of data sets um that's longitudinally collected over the last 20 years. Um we also support um health registers and bio banks. Um and we've um we manage national data sets of chronic pain and and other other areas as well. Um as I say we we we um we have a lot of skills in other areas. So we run software services so disease registries or clinical trial support data management um and software development for particular research projects as well. And we're heavily involved in research. I'm I'm an academic so uh TRE and safe havens in the UK don't usually have um research groups embedded with them within them. So we're somewhat unusual in that and we can we can run this kind of R&D loop of being heavily involved in the research that then delivers change in our kind of service offering that we do through through our TR. So these are examples of projects that we've been involved with over the the many years. So focusing on on imaging or pain cohorts or um uh diagnosis and machine learning predictors in clinic for hypertension and the the dare program which I'll talk about a bit more detail. I probably don't need this slide in here but just to kind of explain you know the concept of a TR is a is a safe computational environment and is an embodiment of the five safe. So that's this long-standing principle certainly in the UK and in other countries um around safe people, safe projects, safe settings, safe data and safe outputs which are five overlapping principles that ensure uh data privacy and data safety. So if any one of those things fails, the others should um should compensate and and minimize the risk of of exposure of data. So onto day UK. So day UK's data analytics and research environments UK. So it's a specialist area of funding from UKRI and um the the DRRI program to um enhance the capability of working with sensitive data in in in the UK. So although my background and the background of many many organizations in the UK around safe data is health, there is explicitly not just about health. We're trying to equalize the the the the the community across across the piece. So that's why we we're [clears throat] co-managed through Health Data Research UK and Administrative Data UK. So we we have these these um common needs across across the piece. Um and uh I think I've said this in in this slide is it's about managing sensor data and to improve access with pace and efficiency and and in scale and uh and I think Dar is is being really successful in that so far. Uh and also mentioned this as well. So we're right in the middle of phase two of of the day UK program. Um phase one ran for two to three years uh in between 21 and 24 and now we're we're running to kind of near the end of phase two although there's potential we might get some extensions into that and we're planning into the phase three program of of DAR and like I say it's it's about enabling TR capability and capacity across across the piece and um if in talking of technology readiness levels. This is where we DARE is is sitting. It's about taking things that are proof of concept or being formulated and getting them into really close to to operational use um and showing that they are relevant to the to the appropriate communities and to the appropriate work. So the the phase two of the of DAR has focused on these um four areas of um standards, output checking, federated analysis and AI and ML. And this is where the core director groups and core funding um of the trevolution program of which I'm one of the directors um is is focusing on on and and the and the satra specification um kind of fits all these these areas which I'll get into in a bit more detail. [snorts] So we have our our core part part in in revolution and then we have um TRRES that that work with us and have been working with us um as part of the early adopter program um and there are these uh seven early adopters and as you'll see you know we we're building up an ecosystem across the UK in terms of of different types of um uh stakeholders that are are critical to to the adoption of of what dare is trying to deliver. Um and then we have the researchers themselves who um we can't ignore, we can't forget, you know, they're the ones that will be using these these facilities and these capabilities and we need to make sure that they are suitable for the research that needs to be done um in in this area with sensitive data. So we have this collection of research exemplar projects which are currently running. They've been uh running for five or six no four or five months currently. Um and uh these these are they so there are currently eight running on this uh so they're taking some of the early things that we've built in in Travolution um and testing them in real world environments um around uh dermatology or um dealing with epilepsy or dealing with um other types of um environmental data for for dealing with uh people's envir environments and people's well-being um in the society and so this work is tightly scoped and tightly coupled between the researchers and TRE and and the core Trevolution program and then we have um more more testing of proof and concept and pilots through innovation and um we have another series of of short-term projects to try and test uh different aspects of um kind of the edges of where we are. So things like um unstructured textual data um and and you know this is being done in in different ways and also security um testings of of different um capabilities across the UK. Um, and we can't forget the wider community that we have uh in the UK that are interested in in what we're doing, although it may not necessarily be researchers, but certainly interested parties. Uh, and this will be people looking at imaging or the safe data access professionals group, which has been around a long time. Um, looking at uh uh uh statistical disclosure control or public involvement or or things like that. So there's um there's a wide group of people looking at the risks or looks looking at the benefits of of what we're doing in here and and they're all they're all funded and involved um through wider funding capability of of of DAR and these are kind of lightly scoped and loosely coupled with with the um with the core work that's being done in other in other projects and you know the latest thing that initiative we've we've we've set up through through DARE is the R data R a kind of community involvement and engagement activity with the public um and to try and and get um more direct input from from public and involve them um more although throughout the whole of the DA phase phases we've been doing a lot of this already um and has been a core part of every project that's been running and so then that that that gets us here into where we are in in the development of driving technological change. So yeah, and the the key issue in in the UK particularly and I think this is a little bit different in Australia um in that the the growth of TRE is is really uh uncontrolled at the moment. Um this this slide is a little out of date now. Um there was a survey run or published just recently that was run last year that had um 63 respondents of TR operators and this this table this graph is around 40 odd um so it's still growing and um you know there there is there is an issue with that um and we don't think we think this is not everyone obviously not everyone answers surveys so the number could easily be uh 100 or more in the UK. Okay, but what's key is that the the shift TRE and data and data access model rather than a data sharing model is a good thing. Um, we don't want to have the situation where data ends up in the wrong place. Um, but TRA are expensive. It can be complicated and and take long to get access. There's lack of interoperability. Um, they don't necessarily meet need meet the needs of all researchers. um and federation and multi-ter projects are still not not routine at the moment. So these are the things that the DA program is trying to deal with long term. So looking more into the the Satcha program, you know, why does this matter? You know we we the the the issue is is that TR have evolved over these last couple of decades and in no with no common mechanism no common way and so we have a really fragmented landscape which makes life difficult not only for for TR operators but their um data providers and also particularly for researchers um and people want consistency people want equivalence so if you're working in one TR one day or for one project or another TR for another project. You don't want to be learning a completely different skill set. And a data controller needs to know that if they're working with TR1 or TR 2 that they um they provide the same thing. Um but it's just it's just not a name. Um and we need we need access to to more complex and and larger data sets. And so that by default requires access to more sources of that data which which will be sitting in TRE and obviously we need to improve security. We don't we don't want to reduce security at the risk of uh for the benefit of getting more access to data and I think as we as we all know that the growth and the desire for access to data is is never ending and is not going to change. um and lots of certainly UK based um initiatives have highlighted highlighted this and across Europe with the the the initiation of the European health data space um and European open source clouds are looking all at this in great detail. So what is Sartra? It is an architecture and specification. It's not a product. It defines the capabilities that a TR must should or could have. Um and most importantly is that this was a co-designed activity. We did this um through extensive engagement and activities with researchers with TR operators and importantly the public uh through a mechanism called collaboration cafes and I can I can talk about that a bit more um because that is something that is uh lots of people have been shown interested in that in that in a way of of getting good effective and rapid um feedback from from the community. It's really easy. It's really consistent with uh existing credit accredititations which I'll I'll demonstrate um uh later on. Um and it supports it's importantly it's to support TRE to improve themselves and to you know show continuous improvement. it shouldn't be an additional burden and I think given given the involvement of everyone I think it it it's clear that it isn't a burden and it's actually useful um and you can get access to it I mean a quick Google Google find it nowadays and um it's quite an extensive piece of work it's it includes 185 statements broken down into 35 capabilities and uh five pillars and during the the initial ual phase of of version one of Satcha. We we engaged with over 60 groups and since then we've engaged with even more um for version two. So um like I say it's more than a specification and it's built around these three um parts. So we quickly established four principles around uh building Sartra. It had to be usable. It had to be it had to include public trust and be invol and and demonstrate that. It's not something you can enforce on on people. You have to you have to earn it. Um it has to be observable. You need to show what happens in a TR and have that be transparent and auditable. And we need to have some form of standardization. It's not a standard yet. I mean there I think there's talks of of this in the UK or what what a TR standard should look like and Sartra is very much in that conversation. Um but we're on we're on that direction. Um and the architecture had u has to have these four layers. It has to have a spoke a scope. It has to be cap has to have a list of capabilities and what are those components within those capabilities and then within that what does that specification actually look like and I mentioned the the overall structure of the specification so the five pillars uh and with these capabilities and statements which I will describe in a bit more detail now um so the initial version one only had the first four um I say only it had the four first four uh pillars around IG G uh computing tech, data management, and supporting capabilities. And you can see there's lots of management in here going on. So, it's about managing the processes and managing the the the activities that a TR needs to do. Um and then in version two which was published in June um now uh we included the federation pillar which was a core activity requirement for for Trevolution and also something that the community wanted as well in terms of trying to understand what federation actually means and what it does. And so out of the 185 total statements, we have 89 mandatory statements um across all the four the five pillars. Um and in in many ways if you have a TR that complies with all the mandatory statements that is a TR by UK definitions by the community definition you have met the requirements of a TR. Anything less than that probably is missing some some core needs that probably isn't suitable for a TR. So the structure itself um has uh these statements um and you can download it. It's it's uh there's a kind of self- assessment spreadsheet you can look at um on the website and you know has this statement that you you can read and understand and they're intentionally brief so that you can you can uh uh inspect it and it's not a it's not a requirement. It doesn't tell you how to do things. And then there's some guidance to explain it a bit more and then that can give you an idea of of maybe how to implement that that that uh that statement and that requirement. Um but we were very it was very clear right from the start of of version one of Satcha was that um a technical solution wasn't what the community needed at that time. We needed something that sat underneath the five safes. Um but didn't but didn't tell the community this is this is the single way or this is the the best way to do things. It was about you know what does the ecosystem look like and what is it that we need to do to make it consistent across all all all environments. And so that's and so that's what we did. That's why we're kind of in this middle ground of not being prescriptive of you need to have Python or R or you need to use um you know oorthth for authentication. We're telling you everyone well this is the sort of things you need to consider and then deliver it yourselves. And then um it was really important to have these these different levels of importance. So um things that need to be mandatory recommended activities and the things which are good practice but generally are optional. um in in the grand scheme of things. And so just to talk through one of these examples um in the data life cycle management pillar in pillar three um you know we have this statement so where a project intends to train or fine-tune machine learning models on sensitive data you should ensure that data management plan for ML artifacts is agreed prior to project commencement. [snorts] So that's pretty clear you know it it covers um you know the kind of the key things that we we we need to cover in terms of you [snorts] know what what TR can do and how they manage the projects to be safe um and and uh compliant with regulatory requirements. So then the guidance gives you a bit I won't read this one out but this the guidance gives you a bit more um uh detail as to what what kind of things you should consider um and things like that and then um and then ano an importance level for this was defined as as recommended. So although this is a really important thing to do it's probably not something that all TRE can do and we know that is a fact. You know not all TRE currently can manage all all types of machine learning um capabilities. So this is a recommended thing but as I guess AI and ML gets um more and more embedded in what we do then you know these things can change and that's the thing satra is a um is a community activity and so things you know can and will be updated over time as as we have done already. Um so how is it useful for for the community and for individuals uh uh currently? Um and so Satchra was first published in 2023. So we're we're kind of two and a half years into this into this journey. So we have some examples of what what what that could look like. Um you can use it to demonstrate equivalence between um different TRE. So we did this piece of work um what is it now? two years ago nearly nearly two years ago um amongst us in the Scottish safe haven network. So we have uh four regional uh TRES and so we we did a a self self assessment individually and then we came together and did a a peer a one-toone peer review and then we came together and did a a a global review of our interpretations and our implementations of the SAR specification. And so you can see that um we could mark all our evaluations and we generate this this heat map of how we align to each other and you can see that broadly there are some areas which are very very similar and there are other areas which which show quite a lot of variability in that and that highlights I guess two things one is that there are certain areas where we don't need to worry too much about um about the cons about um whether that part of the specification is it needs more effort or whatever. Um whereas the others which show more variability either that's the specification highlighting genuine differences in the community or it could also mean that specification is not necessarily tied down enough to be able to demonstrate to show um to to to show complete uh understandability across that. Um but we found this really really useful as a community because we were trying to develop um a federated governance mechanism across Scotland to work with our data controllers to show that um a relationship with one safe haven in Scotland was equivalent to a relationship to any other safe haven in Scotland. And we were able to do this through Sartra and um demonstrate that um and so this addresses the fragmentation of TRE because then we can show that we are equivalent and um identify what is the UK's and I guess international view of what a TR needs to do. So the fragmentation should naturally reduce um and I'll go into this uh in a bit more detail but allows a name alignment to ex existing creditations. So, like I said, the point is isn't for this to be more effort and and a more a bigger burden on TRE. It's about trying to bring these together and and and identify what actually a TR needs to do and what it can do and and how that that can be demonstrated because all of these different accredititations in the UK have different strengths or internationally like ISO. So either they're health specific or non-health specific or they focus on particular things like cyber um and so they don't necessarily help in designing and supporting a TR. So we we did this work um and we've we created a what we're calling a control alignment table and again that's that's available freely on online. Um the link will come up in a sec. Um and I'm happy [clears throat] to share these slides uh to to whoever and so this should help TRE on their um accredititation journey and also their improvement you know continuous improvement activities. Um so like I say version one was was published uh two and a bit years ago and in a recent survey uh which I I mentioned earlier is that now in the UK uh over 80% of TRE are aware of Satra and nearly half of them have evaluated themselves against it um and it's been widely adopted. I've mentioned the safe network but the NHS secure data environments um industry and and and various um health or not or maybe not health but technically specific uh research institutes running their own uh secure environments have also widely adopted it and its adoption is is growing. Um I think that's quite clear. So in view of that in terms of the the transparency and and the the visibility that we we we highlight as an important part of aspect is we've now developed this this public evaluations catalog um which uh all organizations can self-submit their evaluations uh through the website and then you can this is kind of a way of demonstrating your your equivalence and um and evidencing your transparency to uh your stakeholders particularly I guess your data controllers at national regional level and as well as um industrial partnerships. So what's new in in version two and the federation pillar? So um we've added seven extra capabilities uh which are highlighted here um around governance um accreditation uh study management information security infrastructure data management and financial management. Um so these are all kind of really critical things have c cropped up in the various workshops that we've run and collaboration cafes that we've worked in in in this space. Um and more most of these are are actually mandatory because um I think that the level of risk is is higher and the the need to mitigate them is is stronger when you're talking about federation. And so that's why this is perhaps a higher bar to meet for than the other four pillars. Um and I've mentioned the real world exemplars and so they're you know they're now um all going to be involved in in assessing their TRE within with with the SRA specifications. So again adoption is is growing in this space and one of the key things that we we wanted to encourage through SAR right from day one was transparency and open openness. So everything is is online and open. So everything that we did was was done on GitHub. So the specification is on GitHub. you can see all the all the issues all our discussions that we we did u both internally and externally around all the different changes that we needed to make. Uh the documentation is freely available. We wrote a blog at the time of version one and we developed uh two videos for for researchers and for um the public to understand a bit better what what the the point of Sartra was. And um I mentioned this already and I think it's to it's important to reiterate how how much the community were involved in. We were a small team originally and still are you know maybe six or seven of us in total um but we got input from dozens and dozens of people um from across across the country and across the stakeholders. At the start of Satcha project, we thought we might we might get into contact about 12 organizations, but actually the the community was significantly larger than than we thought. And so the public was also crucial in what we do. You know, we we we have a social contract uh with the public, especially when it comes to using uh sensitive data and personal data for research. Um and so we've throughout we've had uh public members on our team. So Anthony here was is is one of them. Um though we've had access to public advisory groups through Trevolution and other organizations and um these collaboration cafes which essentially were a a a meeting every Fortnite or roughly tw uh twice a month online for an hour, an hour and a half and we we talked either about a specific topic or we allowed people to bring in a specific topic that they wanted to talk about. We broke out into rooms with scribes, took notes on everything that was discussed, and then came back and and reported back on that. And then we we collected that information and used that to inform any any future changes. And then uh through Trevolution, we've run some in-person workshops with with organizations and and groups of the public that don't normally engage or we don't normally engage with. So the young, the old, the unemployed um and and other different um uh disadvantaged groups. Um and so for example for for the city's lab work, we we worked with what's called neats in the UK. So not in education, employment or training um people from areas of multiple deprivation and and older people. And um they self uh describe themselves like this. And so we were able to get some really good uh feedback from them. Um recently we've run uh five cafes with um over 300 participants with a large numbers of of self-described public individuals as well. So we feel we've we've had a lot of reach in the into the public and into the the wider views and that's highlighted the needs for transparency and clarity of what what we're doing and what TRE are doing and for them to report on that. Um and so one of the key things that we've been asked as well is that how do you deal with um public activities which perhaps are are challenging or revisiting the same issues again and again. So then you you it's really clear to make to highlight the scope of what you're doing and and be clear that today we're going to be talking about this um these we know these are these other topics that people want to talk about not devaluing them but we want to talk about these things today um and so that's been really helpful in being able to do that and [clears throat] also having someone like Anthony um in these discussions who is a public member himself a very very good uh speaker and uh can tell people to shut up in a very very nice way and you don't feel offended about it at all and it's it's great to have that. Um uh so that's that's really good and you know the impact on on version two uh and Simon specifically is having you know mandatory statements on transparency. Um there's a public engagement group uh funded by HDR UK called Pedri and we we've taken guidance from them on on how to do that um and encourage TRE to have stronger public involvement individually and and also to demonstrate that public data is a public good um generally and and highlight that throughout and so you know the wider context of SAT is that we have a community interest group that's looking the the the longer term view which has input but from a wide range of stakeholders. Um and through this group, this is where we did this capability mapping between these these different um standards. um which was run by uh Jenny Johnston at Hick and we we published a report and like I say the the control alignment table that that that I mentioned earlier and just to I've been looking at this in a bit more detail so this is the first look at this you know publicly I guess [clears throat] is looking just at the mandrit statements in the first four pillars of of Satra not the federation pillar um and this is the the level of um missingness in the different accredititations in terms of alignment with SATRA. So even um so security controls and kind of the more uh you know data specific things have really high levels of missingness compared to Sartra. So I think that highlights that SAR is definitely filling a gap that these specifications don't have. these well recognized long-running specifications in some cases um and even ISO 27,0001 which is a very common and well well seen uh specification in in TRRES and secure environments is missing quite a lot of things that we deemed as a community in the UK as an important aspect of running a TR. So, you know, this this I think this is where I think the real strength comes in of of what we're doing and I think will, you know, change what we do going forward, I think. Um, and uh the the closest one is the newest specification that's coming out from from the NHS, which is isn't finalized and could still change. Um, we've worked uh we're growing our our impact across the the world as well. also through Europe specifically um but you know South and Central America we've got a Spanish translation now of Satra and uh discussion with different organizations like yourselves um across across across the globe. So I think just to wrap up um I think there is SART is very much the first UK definition of a TR and built on this capability framework um and provides a mechanism for transparency and equivalence um and clearly fills a gap that that doesn't that what that that that is there and it's clearly there now and we can evidence that and which is being adopted through different domains, industries and across borders and version two is an exciting um framework that's only just out to try and push how federations should work and and and and affect that discussion in in that space. And I don't think we'll get it right first time, but I think we need something to to kind of almost as a straw man to attack and see right when we need to do this differently. And because federations are a relatively new thing, um I think we'll take it'll take a few rounds of getting getting that right. So please get engaged uh with with Sartra download it have a look at it um self-evaluate yourself against it if you have her TR um and happy to get any and all feedback and that just leads me to thank the amazing team that's been involved in SART from from the day day one for version one and version two and of course day for funding and thank you for listening. >> [snorts] >> You're muted, Roger. >> Oh, sorry. Um, thanks very much, Chris. Um, and really topical, uh, as Satra, uh, Satra, uh, these two have just been released, so, uh, it's it's it's really timely. Um, I I've got a I've got a question to start with. So, you've got this equivalence tool where we can self-write our TRA. Can we submit them to your website and uh for equivalence? >> Yes, absolutely. There's a form that you can you can fill in and you just submit your spreadsheet and then we'll uh we'll have a just a quick scan over it just to make sure it it looks all right and then and then publish it like that. So yeah, it's it's completely open for for everyone to submit. >> Yeah. And just another comment, it's great to see the social license work that you've been doing, you know, the the our data, R say and the cafes because it's really important to get the public along the journey with u uh TRA and you know I I'm also interested as you know in the OOP common data model and secondary use of data. So um yeah, great. Um Kylie, have we got some questions from the chat? Um, there was a question in the chat, but actually Tim has answered it. Um, Tim or Amir, would you like to go into any further details about that? Or if you don't, I've got a question. >> So, yeah, I can just So, there's a question about So, we often get this um where someone's got a very specific question saying, you know, how what's advice on this? It's so broad that if we went into too much detail, it would be, you know, hundreds of pages long. So they're much more based around principles that people have to agree and pro you say a process has to be in place. I think that the as we develop it and more kind of widely accepted tools and processes and techniques are in place, then we can point directly to those. It's like you could do it like this. somebody's already um uh you know someone's already solved this problem. So about the export of of trained models for example if we have if if there's a really good set of uh things that the community thinks is is is now a stand you know a reasonably standard way of doing it then we can put that into the um into the guidance section. So that's that's kind of the approach to keep it high level. Yeah, I I was uh looking at that link that you have pasted and u yeah uh it is kind of uh useful regarding my question. So yeah, thank you. >> I see that Andrew's got a a question. So Andrew, >> hi. Thanks for talking us really really good. Um so I come from a a many many years ago health informatics background you know 20 years ago and we obviously were all afraid of silos of data. So there was, you know, everyone had their own little EMRs and everything was siloed. And [snorts] my reflection on TRE in Australia at the moment seems to be that everyone is now wanting to build a TR essentially to build a silo around their data. Um, and I wonder as a country that has gone down the path, you guys have many, many more TREs than we have. And I I'm kind of like wanting to kind of say, can we put the brakes on everyone having a TR? Can you reflect on on that from a UK perspective the kind of many versus a few TREs? Um yeah certainly I can give a perspective I mean it's it's difficult to you know um to dictate anything in this space really you know uh universities and organizations will will do will do they what they want ultimately but I think I think some of the the things to highlight are to try and address um uh maybe outdated views around TRE um that and and raise awareness of of the strengths of TRRES and what benefits they bring um because I I'm relatively new in this space as well and you know when when I first was aware of of of HICK and and joining this space you know the the view was that oh it's difficult to work with with them it's difficult to work with data in a in a secure environment um and so I think there there are some kind of social or or cultural views that need to be addressed to make sure that um that more people work with existing infrastructure rather than say oh it's rubbish I can do it better myself so I'll get some money from somewhere and build my TR to my specification or to my needs um and then you know 3 years down the line when they still don't really have a functioning TR and no one wants to use it you know then they go oh well actually maybe I should have gone and spoken to people who've got the experience of doing this. Um, so I think, you know, there's there's uh there's kind of a an an advertising and and kind of exposure bit of of what this space can can look like. I think there's perhaps there's a there's a bit of a stick I think needs to be used to to try and to ensure that the right governance models are clearly front and center of of all these these TRE. um because in my experience of a couple I've seen re re recent ones that I've seen um is that it's kind of been an afterthought um they've focused on the the the technical aspects and not um the the governance aspects and then they go you know oh we'd like to you to to to access this data is like well who are you and why should we give it to you so um so I think um there will be there there will be that needs to be dealt with and I think the Last point to make is is sustainability. Um it's one thing building a TR with some grant money or some institutional money that's been made available to you, but to make that sustainable long term is really difficult. Um and it gets even harder when there's, you know, 60, 80 or 100 of you across the country doing very similar things. Um so I think that's our future in the UK. I think my my personal view is that I think there will be a contraction in this space because it they just won't be it won't be sustainable long term. Um so so yeah I would certainly uh not recommend going down to that size. Maybe some more maybe may be good you know having maybe some special specialisms in certain technical areas but data themselves shouldn't just be sat in the same place and just oh I'll just stick a TR around it and then I'm I'm fine. I think there needs to be uh more around data sharing and making sure that's that's that's embedded in in the culture. Do just as a quick followup, do you [clears throat] and I think I'm unc unfairly characterizing our data custodians, but do you ever find institutes who seem to be like, well, it's the data governance of sharing things out to other places is hard and so therefore we'll just build a TR because it feels like the data governance is easy and and how do you get people over that? >> Yeah, that's exactly it. No, no, it's exactly the same here. Um if I if I knew the answer then then uh we wouldn't we wouldn't be here I don't think. Um >> yeah I think I think it's it's it's it comes down to people right the governance is always around one or two people who who who have different risk appetites and then just just that just brings up barriers. Um so it's yeah it's it's it's dealing with people and building that that relationship of trust. Um that's the key bit. >> Yeah. Thank you. I I think Dom's got the next question. >> Yeah, thank you very much Chris for this quite presentation. Um I was wondering if the specifications for federation cure for all kind of federation like peer-to-peer or hub and spoke kind of federation is it all of type of federation or just a specific one? >> Yeah, it's it's like uh so thanks very much for the question. It's like Tim was saying earlier, um, you know, if if we if we became too specific and too technical, then we'd we'd have Yeah. you'd have a Bible size specification because you would have to deal with all the different types. And, you know, early on through well, throughout Federation, um, sorry, Trevolution, we've kind of agonized over, you know, what is a um, what is a federation? What does federation mean? Can we define it? And beyond you know very general high level views um you can't really have a single definition you can have you know what we're working on you know patterns of uh federation that meet certain needs whether it's federated analytics whether it's federated cohort discovery or whether it's yeah like you say a peer-to-peer uh uh data sharing uh type. So the key thing that we've done in the in pillar two sorry pillar five in version two is that the the first statements are you need to define yourselves within your your group what type of federation you are and then agree the the criteria that you need within your federation for uh inclusion within that federation and things like that. So I it it may feel like a copout in that we've said it's not up to us to define it but I think even with that it's been it is it's become really helpful in in people to frame it's like oh are we in a federation do we want to be in a federation okay well if we do then okay we need to do these things so um so yeah it may feel a little bit standoffish but actually I feel it's been it's it's it's making the right discussions happen. >> I think Kylie's got some questions from the chat now. Uh FA. >> Yes. >> Yes, I do. So, um I vet has put in a question. Um what has been the hardest and conversely easiest parts of the Satcha development and also the assessments groups have done? >> Huh. Uh that's a really good question. Um >> it's easy, isn't it? Yeah. [laughter] >> Yeah. I think probably certainly in version one, I think the hardest thing was time because it was it was a 9-month sprint project from start to finish and we had like a month's notice to start the project. So I think we were funded in February for a March start um and then end in October. Um so so we had to work very rapidly and closely um and efficiently and that's where kind of the collaboration came cafes came to their to their four um easiest part um actually I think adoption has been somewhat the easiest haven't really had to do a lot of kind of evangelizing because everyone in the community well not everyone but certainly a large proportion of the community was already working with us on the specification. Um it kind of almost naturally happened that organizations like okay yeah we'll probably start adopting it um and and and say that we're adopting it. So I don't know Tim I don't know if you have any thoughts on what easiest and hardest things that we've done are. So yeah, I think um like time for the first part was was interesting because I joined the project a bit late and and and we did change the direction of it about halfway through as well which uh just because it originally I think there was a view that this would be quite a technical standard of like what does the AR what does the infrastructure look like? how does the data flow and then actually it turned into you know to feedback from the community kind of redirected us towards what does good look like for governance what processes do you need how do you how do you control stuff so I think that that that made the time even shorter um and the easiest thing I think I mean one thing because I was I sort of led the development on on V2 the as the community has become more cohesive across the UK actually getting them involved in writing the stuff has been great like really really good engagement from across that community and that community didn't really exist with V1. So you know the one thing that DARE has done that isn't you know strictly a a research output has been bringing the UK TR community together and giving it direction and and and everybody kind of knows each other. The organizations understand basically what we all do. So I think that that's been really good. >> That's fantastic. Hopefully we can get a similar thing happening here. Um so Martin also has put in a question in the chat and he said you mentioned that standing up a TR is straightforward relatively speaking but sustaining them is difficult from your experience what are the challenges in sustaining TRE and Martin's noted asked by a group member who have just opened the door to an S sur at a uni in New Zealand. So it sounds very topical for Martin. >> Um like like I mentioned uh to to previous to Andrew's question uh sustainability is the hardest thing. So funding and maintaining funding for for your uh for what you do. um because you'll get um you'll get compl constant complaints if you're charging to for access like we do in in in Dundee and and other organizations do uh on a cost recovery basis on a per project basis you will constantly be being told you're too expensive regardless of how how expensive it actually is to pay for the expertise to manage data to manage the security you know everything. So, um sustaining it and I guess um engaging with with data controllers when you're trying to get access to a new data set um and and trying to uh persuade or uh demonstrate to data controllers that you are a safe pair of hands and can be trustworthy custodian of of that data for research. So, you know, yeah, I think those probably the two hardest things is trying to work with with different organizations to to provide access to your data to their data securely. Um, and then making sure that you're here for the long term. Um, and it it's a constant it's a constant effort to to do both those things. Um uh so you you just need to have diversity in in your in your team and in your capabilities to keep that the the I guess the the lights on. And good luck with your sur in New Zealand. Um happy to help where where you where you if you if you'd like. >> You can fly out to New Zealand Chris and advise. >> I'd honestly I'd love to. [laughter] >> Um >> beautiful part of the world over there. Um we have one more question from Jake. Um and Jake asks, "Can Satra scale to smaller TRE like university level um as well as larger ones?" Do you want you want me to Chris? >> Oh, go ahead. Yeah. Yeah. Go ahead, too. Yeah. [laughter] >> So, so uh yeah, so Chris obviously is is part of HICK which um whereas I work for UCL. our um we've got two TRE uh at UCL and and there is a fundamental difference um between the way that universities often run TRE and the way that um more kind of data provider type TRES like HICK do >> in that we really we're we're a platform as a service right you bring your own data you can build your own stuff within our environment um but you you understand your data we don't as a platform provider provider. Um, so will still work in that way, but you do have to um, so one of the things that we're very clear on and if this is something you're interested in, like um, UCL has published all of its kind of all of its documentation, all its ISO documentation. So it's things like understanding that shared responsibility model of you know when I tell Chris that our our uh researchers are responsible for their own outputs is sort of horrified right which is understandable because they control their data whereas we have a very strict um uh shared responsibility model that says you know what people should and shouldn't do and where our responsibilities stop and where where theirs begin. So it is universal in that respect. You just have to make sure that you've got um uh the documentation and how it's presented and there are good examples from other UK universities and and world universities that um that can help with some of that stuff. >> Fantastic. Um one more question has just popped up in the chat. I might ask you Bika um to um maybe verbalize your question um because you might just need to explain what the rain study is um for our presenters. >> Okay. Uh so my name is Bleitza and I'm the scientific manager at the rain study. Let me just um um just have my face as well. So um we have uh like a multigenerational cohort study that um has been running since 1989 and currently we have been work we have been inviting participants coming through for their 18th follow-up. Uh it's a multigenerational study where we've got generation one, two and three which is like uh parents, grandparents but also now the babies of the gen 2 participants and um we have an ample amount of data um available and the major issue it's always sharing that data and how to share it whether sending um via I don't know this transfer file files that are secure and not secure. But we always are faced with um that little bit of uncertainty. What happens to the data after the project finishes because we have no idea whether it is destroyed, how like properly um and all of that has come to now like we need to start being more um involved with these trusted research environments where we can give the researchers access to that data where they can run the analysis and and essentially um kill the um [clears throat] access after a completed project. Is that something that Sarta can um be used for or are we truly looking because of the nature of the study that we will have to have that um siloed data um TR for the brain study. >> So that is a really really good in a good question. Uh thank you. And and al also you know as as a data controller you know the kind of thing I was mentioning before in other questions I think it's really good that you're you're asking these questions and and you know challenging yourselves around this. Um so I think obviously my my argument would be is don't build your own um because it will take you a long time to do it and and uh and we don't have the funds. and and you you don't have the funds. So, you know, work on building trusted relationships with with existing TRE and and and a good solid uh data sharing model with those data with those TRE so that um researchers can get access to to the data through mechanisms that that they're already familiar with. >> Yeah. Um, and I know I know some so for example in Scotland we have Share um, which is which is a bio bank and and uh, a long-term population cohort that we we run a TR for in Dundee. We also have Generation Scotland which kind of works more like like yourself um >> in terms up to now in in sharing the data but now they're working with with um uh with a TR provider in Edinburgh and building and building a TR for them under kind of similar spec as as other TR in Scotland. So >> um and you know I'm sure you're you're you're familiar with UK B. Uh so we're we're talking to them at the moment in terms of how to >> develop a TR to suit their their needs, you know, they're their somewhat substantial needs. Uh so they're they're looking very closely at at this space as well. Um >> and I can't really talk for them, but you know, >> Yeah. Yeah. Um but I would certainly encourage you not to build your own um but to work with with others and and build those kind of data data sharing agreements and trusted agree uh relationships with >> Yeah. Um >> thank you. >> I I I just noticed we're we're past the hour and that's a very good question. Uh come to the ARDC um uh and talk to us as well because maybe we can help uh with that question. >> Okay. Um, Chris and Tim, I'd just like to thank you very much for presenting. I know it was very early in the morning. It was uh it was an 8 am start for you in Dundee. So, and it's really informative and um and I I think the community's got quite a lot out of this. So, thank you very much for your presentation. Uh it was great. Um so, uh we'll wrap at that and um yeah, thanks everybody for attending. >> Thank you. >> Thanks. Thanks again for the invitation, Roger, and thanks all for the really, really interesting questions. So, um, yeah, hope to see you soon again soon. Thank you. >> Thanks, Chris. Bye. Thanks, Tim.