gcuirb Free application review

HomeNewsletterSite authorization

The GCU site authorization letter: who signs it, what it must name, and why files stall on it

Grand Canyon University publishes a sample site authorization letter and expects you to draft it, not download it. The site's official signs a page you wrote, on the site's letterhead, and that page must say in plain words what the organisation is permitting — which activities, in which rooms, with which people, on which terms. When a file waits, it is usually waiting here: not on a paragraph that is hard to write, but on a signature that belongs to someone whose calendar you do not control.

Caroline Strauss, PhD · 2026-08-23

The short answer

GCU expects a letter on the site's letterhead, signed by an official with authority to grant access, naming your study, its purpose in plain language, every research activity the site permits, and the exact participant criteria used everywhere else in the file.

What does GCU mean by site authorization?

Authorization is permission from whoever controls the place, the people or the records your procedures touch. GCU's Office of Academic Research treats it as a precondition rather than an attachment: its own checklist opens by saying that site authorization is required before applying to the board. Recruit through an employer's distribution list, sit in a school library with a voice recorder, ask an administrator for a file of test scores — each of those is an activity at somebody's site, and each needs that somebody's written yes before the board will read the rest of your file.

Two routes run under the same name, and confusing them is expensive. The first is the one most candidates need: an external organisation — a district, a clinic, a company, a non-profit — grants permission by letter, and that letter travels with the IRB application. The second applies when the site is Grand Canyon University itself. That request goes to the Office of Academic Research on its own checklist, which asks for written approval from the deans concerned, the chair-approved proposal, the instruments, and a data use agreement where archival records are involved. The same checklist records a moratorium on sampling the university's own enrolled population and expects an affiliation with GCU beyond enrolment. Any design that quietly assumes access to GCU's own people should meet that page early.

Who has the authority to sign the letter?

The board is not checking for enthusiasm. It is checking that the signature belongs to someone who can bind the organisation, and the most willing helper is frequently not that person. A charge nurse, a department manager, a friendly principal — each may be delighted by your project and still lack the standing to authorise research on the organisation's behalf. GCU's template answers the commonest procedural worry directly: a wet signature is preferred, an electronic signature is sufficient. It also asks for the signer's printed name, title and signature date, which is how a board tests authority without an interrogation — a title tells the reader whether this person can grant what the page grants.

Layered settings need layered permission. GCU's template says plainly that data collected in a school requires permission from the district office and from each school, because individual schools set their own conditions on what may be collected and how staff may help. The same logic runs through health systems, correctional settings and any site that operates a review body of its own: one letter per authority, each naming what that authority actually controls. If a site runs its own IRB, expect its review to sit alongside GCU's rather than replace it.

What must the letter name, line by line?

GCU's sample is written as scaffolding in coloured instructional text, with a hard rule attached: every instruction is deleted, and the letter reaches both the site and the board in black type. What survives that deletion has to carry the following.

  1. The addressee and the study. The letter is written to the board, names your study by its title, and names you as the researcher. GCU's template blocks in the university's Office of Academic Research and College of Doctoral Studies address so that the site's official can see who is being written to.
  2. The purpose, in lay terms. A short statement of what the study is about, written the way you would explain it to the person signing — not the purpose statement lifted out of chapter one.
  3. Every activity the site permits. This is the load-bearing paragraph. GCU's examples are unusually concrete: interviews of a named group in a named room during non-contact hours, a research presentation at a monthly staff meeting, flyers handed out at that meeting, a focus group before opening, de-identified records released by an administrator. Bullets are encouraged, and so is naming the restrictions, limitations and responsibilities the site is taking on.
  4. The exact participant criteria. The template asks the site to authorise a specific population, bulleted, and states that this must align exactly with the inclusion and exclusion criteria in the consent document, the recruitment material and the application.
  5. The protection undertakings. GCU's wording has the official acknowledge that the researcher will supply the approved consent document and recruitment material before recruiting anyone at the site, that the site's name will not appear in publications or presentations, and that the researcher will protect the data.
  6. The workplace paragraph, when it applies. If the research runs where you work, GCU supplies a statement that complete confidentiality cannot be guaranteed, because colleagues may infer participation from your role or professional relationships. That sentence belongs in the letter and in the consent document, worded the same way in both. The template also offers an aggregate-results clause for sites that want the findings, and expects it deleted rather than softened where they do not, plus an invitation for the board to raise any concern about the permission directly with the signer.

Two mechanics decide whether a good letter survives its own formatting. The date must cover the whole period of data collection, and GCU treats authorization as something that goes stale: its checklist for doctoral files asks outright whether the site authorization or the permission to use an instrument is outdated, and expects a visible date. Ask too early and the page expires under you; ask too late and everything else sits finished, waiting.

What the letter says, and where the board checks it
Line in the letterRead againstWhat a mismatch looks like
The permitted activitiesThe procedures in the application and the activity list in the consent documentThe letter permits interviews; the procedures also pull records
The participant criteriaInclusion and exclusion in the application, consent and recruitmentThe letter authorises staff; the recruitment reaches contractors too
The location and conditionsWhere and when the procedures say data is collectedAuthorised for non-contact hours; the schedule runs during class
The signature and titleThe authority the organisation actually delegatesSigned by someone who cannot grant access to those records
The dateThe data-collection window in the approved proposalThe window runs past the period the letter covers
The named siteThe sites named in the proposal AQR approvedA second campus appears in the file with no letter behind it

Why does this one page stall so many files?

Every other exhibit is yours to finish tonight. This one is a page you draft and someone else adopts, and adoption runs on their governance, not your submission plan. A compliance officer wants to read it. The signer is travelling. The district routes research requests through a committee that meets on its own cycle. A health system attaches an affiliation agreement or a data use agreement before anyone signs anything, and those documents carry conditions that have to be checked against what the file already promises.

None of that is unreasonable; it is simply outside your control. Which makes the useful advice unglamorous: open the conversation before the letter exists, tell the official precisely what the page has to contain, and hand over a clean draft to approve rather than a blank task to compose. GCU's template recommends speaking with the site first for exactly that reason — so the page you write describes what they truly agreed to.

The second stall is quieter and costs more. A warm, signed letter arrives that authorises something a little narrower than the application describes. The board has no duty to reconcile the two; it treats the narrower page as the outer edge of what the site permitted, and the file goes back. That is drift, the same failure traced at every other desk in the step-by-step walk through GCU's route, and it is why this page is drafted from the approved proposal rather than from the memory of a phone call.

Which documents must this letter match?

GCU's instruction is unusually blunt for a template: the site authorization, the consent document, the application and the recruitment material must align, down to the participant criteria and to exactly what the site has agreed to do. Treat that as a test, not a suggestion. Any two of those documents, read side by side, have to describe one study — one population, one set of activities, one set of places and limits. The whole manifest that travels with an application is laid out in the exhibits checklist; the participant-facing pages this letter has to agree with are covered in recruitment materials as filed.

How this desk handles it

Authorization arrives missing more often than any other exhibit, so it moves to the front of the plan. We map which permissions a design genuinely requires, one authority and one activity at a time; establish who can grant each; write the pages for signature so every official is approving prose rather than composing it; follow the signatures; and file the letters with the finished application. Where a site requires a contract, that enters the plan as work rather than as a late surprise. Your study and your relationship with the site stay yours, the decision stays the board's, and the docket is ours — set out in full on how it works.

What to do next

If your design touches an organisation you do not control, this page already sits on the critical path, whether anyone has asked for it yet or not. Send the sites your study involves through the free application review. You will hear which of them need a letter, who inside each organisation can grant it, and what the page must contain before a board will read it as permission — and where none is needed, you will hear that too. Nothing is filed in your name without your sign-off, and the FAQ covers what follows.

Sources

GCU revises its templates, checklists and portal instructions. Where anything on this page departs from GCU's current doctoral handbook or IRB portal, GCU's own material is what counts. This practice is independent of Grand Canyon University.