Access Management
A guide to requesting, receiving and using access to BAPa's licensed analysis application.
The steps below describe the system as it is implemented today.
1. Why access is controlled
Most of this site is open to anyone: the research chat, the publication library, the interview and the background pages. The analysis application is not. It is licensed, and access to it is granted individually.
The control serves two purposes. It limits the analysis application to people the project has approved, and it establishes which named account is using it, since Clerk records each sign-in.
It is worth being clear about what the gate does not do, so nobody plans around a protection that is not there:
- It does not change where laboratory data goes. Analysis runs entirely inside your browser whether you are signed in or not, and your file is never uploaded. See the Security and Privacy document.
- It does not record what you do once you are in. Sign-in times are recorded; analyses are not.
2. Requesting access
Step 1. Sign in once. Go to the site and press Get Started!, or open the App tab. You will see a notice explaining that the application requires access from an administrator. Press Continue to sign in and complete sign-in with your Google account.
Step 2. You will land on a pending screen. It reads "Your access is pending approval" and shows the email address you signed in with. Signing in is what creates your account; there is no separate registration form.
Step 3. Write to the project administrator. This step is manual, and it matters: creating the account does not notify anyone. Your account appears in the administrator's user list, but no message is sent and no alert is raised. If you sign in and then wait quietly, nothing will happen.
That is deliberate. BAPa sends no email at all, and has no mail service behind it. Access to a licensed application is a considered, individual decision, so it is made by a person reading your request rather than by an automated queue.
Who to write to
Dr. George Cembrowski, at cembr001@gmail.com.
Please treat this as a formal request. Each one is read and assessed individually, so include enough for that assessment to be possible:
- The exact email address you signed in with. This is what the administrator searches for, and someone with more than one Google account cannot always tell afterwards which one they used. The pending screen shows it to you for exactly this reason.
- Who you are: your name, your role, and the institution or organisation you are with.
- What you intend to use the application for: the clinical or research purpose, and the kind of laboratory data you expect to analyse.
- Anything relevant to the licence, such as whether this is for individual use, a department, or an evaluation ahead of wider adoption.
Requests without this information are difficult to act on and may simply go unanswered. If you are evaluating BAPa on behalf of an institution rather than to use it yourself, say so, and send the Security and Privacy document to your IT and privacy teams first.
3. Onboarding, and how access is activated
There are no credentials to issue, and nothing arrives by email.
You already have an account from the moment you first sign in. Approval simply attaches a role to it. An administrator sets that role in the Clerk dashboard, by hand.
Two roles exist:
| Role | Grants |
|---|---|
| User | The analysis application |
| Admin | The analysis application, plus management of the publication library |
Most people need User.
Once approved, reload the page. You do not need to sign in again, and you will not be sent anything. Your existing session picks up the new permission within about a minute. If the pending screen is still showing, wait a moment and reload once more.
Access can be withdrawn the same way, and takes effect within about a minute.
4. Signing in and reaching the analysis application
Once you have been approved:
- Go to the site.
- Press Get Started! on the home page, or the App tab in the navigation bar.
- If your session has lapsed, press Continue to sign in and sign in with Google. Otherwise you go straight through.
- The analysis application loads. Allow around a minute the first time on a new machine or browser, while it downloads the analysis engine. Later visits are much faster.
- Step 1 is Load Dataset. Drop a CSV or Excel file onto the panel, or click to browse.
The application then walks you through six steps: Load Dataset, Inspect Data, Column Mapping, Dataset Checks, Analysis Settings, and Results. Each step has a Help button in its top-right corner, and an Overview button in its top-left explaining the whole sequence.
Sign-in uses your Google account. There is no BAPa password to choose, store or reset, and this application never sees your Google credentials. Whatever protections your Google account carries, including two-factor authentication, apply to your access here.
5. Troubleshooting
"This app requires access from an administrator"
You are not signed in. Press Continue to sign in. If you have never used the application before, this is expected. See §2.
"Your access is pending approval"
You are signed in, but no role has been attached to your account yet. Three possibilities, in order of likelihood:
- Nobody has been asked yet. Signing in does not notify anyone (§2). Email cembr001@gmail.com with the details listed in §2.
- It has just been granted, and you have not reloaded. Reload the page.
- Something is misconfigured on our side. If the administrator has confirmed they granted your access and a reload still shows this screen after a few minutes, it is not your account, so report it. Two configuration faults produce this exact screen for everyone, administrators included: a typo in the role value, and a missing session-token setting in the Clerk dashboard. Both look identical to "not yet approved" from the outside.
"Failed to load analysis engine"
The application could not download the components it runs on. Usually a network problem rather than an account problem.
- Check that you are online, and reload.
- On a hospital or corporate network, the likely cause is a filter blocking
cdn.jsdelivr.net, which the analysis engine is fetched from. Your IT department may need to permit it. This is covered in §5 and §7 of the Security and Privacy document, which is the right thing to send them.
"The analysis tool hit an error"
The application itself failed, not your access. Your file never left your browser, and an anonymous crash report, containing no part of your data, was sent so the fault can be diagnosed. Press Start the tool over to try again or load a different file.
The application stops responding partway through
If your session expires while you are working, nothing interrupts you: the analysis runs entirely in your browser and does not check back with the server. You would only meet the sign-in screen again on your next reload.
Note that reloading discards work in progress. Nothing is saved between visits. A loaded file and the steps completed on it exist only for as long as the tab is open.
Signing out
There is currently no sign-out button once your access has been approved. On a shared or public workstation, close the browser entirely, or clear the site's cookies, when you have finished.
Anything else
Write to cembr001@gmail.com, as for an access request. Include what you were doing, what you expected, and what happened instead. If the analysis tool showed an error, note whether it offered Start the tool over, since that distinguishes a fault inside the tool from a problem reaching it at all.
Quick reference
| Situation | What to do |
|---|---|
| First time using the application | Sign in, then email cembr001@gmail.com with who you are and what you intend to use it for. Signing in alone notifies nobody |
| Pending screen, already asked | Reload. If it persists for more than a few minutes, report it |
| Just been approved | Reload the page. No new sign-in needed |
| Analysis engine will not load | Check the network, and ask IT about cdn.jsdelivr.net |
| Finished on a shared machine | Close the browser, since there is no sign-out button |
| Access no longer needed | The administrator removes the role, effective within about a minute |