UX ResearchOps as Four Operating Systems
UX ResearchOps as four systems: first-party panels, consent ops, repositories, and democratization guardrails. NN/g data and a GitLab SOP.

UX ResearchOps as four systems: first-party panels, consent ops, repositories, and democratization guardrails. NN/g data and a GitLab SOP.

UX ResearchOps is the practice that sets user research in motion: people, mechanisms, and strategies for panels, consent, knowledge, and quality. The ResearchOps Community (2018) and Nielsen Norman Group treat it as orchestration at scale, not a recruiting calendar.
This article is UX ResearchOps, not academic operations research. In NN/g's July 2024 survey of over 400 UX and ReOps people, only 9% of research repositories were mature and thriving.
Ranking pages still sell a 101, a course, or a seat. This hub is the operating manual those pages list as bullets: first-party panels, consent as a multi-point system, repositories as librarianship, and democratization guardrails.
Written for UX and product teams who already run studies. It is not legal advice, not a consent-form template, and not a job listing.
The ResearchOps Community still uses the 2018 workshop line: the people, mechanisms, and strategies that set user research in motion. It exists because research at scale produces work that is not the research itself: ethics and consent, participant data, intake, and the questions of why, when, and how much.
NN/g (Kaplan, 16 August 2020) calls it the orchestration of people, processes, and craft so research scales. The 2022 study guide (last reviewed 27 August 2024) restates the same definition. Six focus areas: participants, governance, knowledge, tools, competency, advocacy.
Recruitment is the obvious pain. It is not the whole job. On r/UXResearch, people who land on ops teams report they expected participant recruiting and found standards, documentation, licenses, and labs.
Kate Towsey coined PWDR ("people who do research"), founded the Community, and stepped back in 2019. She later wrote Research That Scales (Rosenfeld, September 2024). In a February 2025 interview with Maria Rosala, she defined ResearchOps as "the systems that enable people to do research, consume research, and act on research." Civic-design analogy: the city of research.
Google Ads collapses research ops, researchops, research operations, and operations research into one bucket. That bucket is the wrong field (INFORMS, PhD programs, Hillier). Title, H1, and this paragraph exist so the page files under UX.
A research operations manager is a common way to staff the practice. The practice still exists when the title does not.
Do not treat this page as a career listing. Staffing shows up later as a democratization problem: someone has to own consent, the panel, the repository, and the stop-rules.
DesignOps is a sibling. Some NN/g writing nests ResearchOps under DesignOps; the Community and Towsey treat it as its own practice. Keep both readings; do not flatten them.
Kaplan's cost argument still does the business work. If research volume goes 10×, ops overhead should push total cost to 9× or 8×, not 11×. Without ops, every extra study adds its own recruiting, consent, storage, and synthesis tax.
UserTesting acquired User Interviews on 7 January 2026. User Interviews says it remains a standalone, tool-agnostic product.
Great Question announced a $13 million Series A on 12 November 2025, led by Inovia Capital.
NN/g shipped Internal User Panels (23 January 2026) and Why User Panels Fail (24 April 2026). Towsey's March 2026 essay argues that choosing whether to democratize is almost quaint, because AI already did.
The Community about page describes a membership of more than 15,000. Treat that as community scale, not a census of jobs.
You can buy a panel CRM, a consent add-on, a repository seat, and a self-serve study tool and still have no ResearchOps. The operating object is four systems that share a participant, a recording, and a finding.
System | Job | Failure mode if you skip it |
|---|---|---|
Consent and data | Multi-point opt-in, information elements, vendor processing terms | A signed PDF, then recordings in a tool whose terms you never read |
First-party panels | Re-contact opted-in users with a DRI, caps, audit, sunset | A spreadsheet and personal email, with no contact log |
Repositories | Taxonomy, access control, a person who gardens | A seat with no owner |
Democratization guardrails | Who may run which method, who owns consent, stop-rules, what must land in the repo | Unfunded seats. Research-shaped evidence for decisions already made |
Intake and a research roadmap sit underneath all four. They are shorter on purpose. Method choice still lives on the UX research methods hub.
This section is operations guidance for UX teams, not legal advice. Do not copy it into a form and call it counsel.
Do not file an IRB for every usability test. Do not treat product UX as scientific research with a GDPR research carve-out.
Most digital-product UX research is nonclinical and relatively low-risk. Risk is not zero. A casual customer call becomes research-ethics territory as soon as you transcribe quotes or share that person's information without having told them.
UCSF IRB is the clean trigger list for product teams. GDPR can apply if you are established in the EEA, target or monitor people there, or transfer EEA personal data out. Special-category data (health, biometrics, ethnicity) is a higher bar.
GDPR-info on Articles 6 and 7: processing personal data is generally prohibited unless allowed by law or the person has consented. Consent is one of six lawful bases. Valid consent is freely given, specific, informed, and unambiguous.
Withdrawal must be as easy as giving. No implied consent, and no form requirement; written is recommended for accountability.
If you relied on consent, you must stop that processing when consent is withdrawn. You may not switch to legitimate interest after withdrawal.
Hallinan, Boehm, Külpmann, and Elson (2023, AMPPS): when personal data are collected directly, GDPR information obligations (primarily Article 13) are normally delivered inside the informed-consent procedure. Failure is a GDPR breach. Their recommendation is one clearly identifiable subsection, not a second PDF nobody opens.
Cite them for what belongs in the conversation. They studied psychological research; your usability test is not that study.
The U.S. Office of Natural Resources Revenue, writing about federal UX on 3 April 2024, called the consent form the least user-friendly aspect of UX research. They dropped the signed-PDF ritual and rejected implied consent (participating equals consent).
Replacement: a user-research agreement process with three opt-in points:
ONRR also distinguished human-subjects research (the subject is the person) from federal UX (the subject is the website, tool, or service). Do not republish their agreement as your legal form. Steal the ops shape.
NN/g (Fessenden, 3 July 2022) matches the modular half: checkboxes for participate / audio / video; give the participant a copy; "umbrella" consent for an indefinite timeframe of current and future studies is very problematic. Panel opt-in is not study consent.
Element | Primary source | Ops implication |
|---|---|---|
Freely given, specific, informed, unambiguous; easy withdrawal | Opt-in only. Stop that processing on withdrawal | |
Purpose, retention, access, rights, transfers | UCSF GDPR checklist as elements, not a template | Put the elements in one identifiable subsection |
Article 13 delivered inside consent | The conversation carries the information duty | |
Three opt-in points | Participate, start-of-session, use-of-feedback | |
Modular recording; no umbrella consent | Separate panel storage consent from this study |
If you actually run Common Rule or FDA research, HHS OHRP allows electronic consent and keeps IRB authority over the process, not just the file. That guidance is long-standing. It is not a 2026 rewrite, and it is not the default for product usability testing.
Luria 2023 documented a control teams miss: UX research platforms often claim ownership of participant data in their terms. Some will not let the researcher download, so "delete after the study" also deletes your copy. Platforms may argue that signing up for the platform covers any later study.
Ops control next to the consent form: a data-processing agreement, export and deletion rights, and a named owner for recordings. Do not name a live vendor as "sells your data" without that vendor's current terms. The job is to read them.
Maria Rosala's ethical-maturity article (29 December 2019) is the bootstrap: if you have nothing, start by standardizing consent documents and processes for collecting and storing research data. Mature practice adds a code of conduct, ethics training for everyone who runs a study, standardized forms, ethics experts (often ReOps), and a UX-specific data policy.
Consent infrastructure is a product category. Ethnio centralizes consent (DocuSign / Adobe Sign embed) and can give PMs and designers collaborator seats with no Pool or Incentives access.
Rally tracks consent, engagement rules, and access. Those are examples of the system, not the law.
Members already know the product. NN/g (January 2026) still treats a panel as infrastructure you can re-contact: a curated, opted-in group whose distinguishing features are consent and continuity.
They will not always reflect new or unfamiliar users. Use external recruiters for discovery and competitive work. Hybrid is the normal setup.
NN/g's build sequence is the loop you actually run: recruit; organize and segment; contact and schedule; incentivize; reengage and manage (participation history, rotate outreach); govern and improve (ownership, who can access, contact, and update, privacy).
The May 2023 participant-database article adds the consent split that teams skip: ask consent to store data; panel opt-in is not study consent; track last invited, last participated, and studies. Spreadsheet panels need manual governance so researchers do not abuse the file. Internal panels: low cost, medium-to-high bias.
Why User Panels Fail (NN/g, April 2026) names three modes. Static database: attributes go stale; you need explicit ownership and a quarterly audit. Sampling bias: engaged customers positively skew feedback; you need rotation, contact-frequency caps, and occasional off-panel recruiting.
Business drift: the panel still reflects yesterday's audience. The presence of a panel is not what signals maturity. The discipline with which it is managed does.
GitLab's handbook is the best copyable first-party manual in public. It is one company's SOP. It is not a regulation.
Use a panel for hard-to-recruit niches (enterprise, Kubernetes experts, self-managed), not as the default for every study. Research Operations recommends a panel last no longer than 6 months. Historical sizes: 30–500, with a named Panel DRI.
Incentive cap, US-tax-adjacent: 4×60-minute sessions / $600 gratuity per fiscal year, then ineligible. Wave outreach (their example: panel of 1,000, waves of 100). Cons they name: fatigue, pattern-trained respondents, refresh cost, bias.
Do not copy Qualtrics + Calendly + a reimbursement template because GitLab used a stack. Copy the rules: DRI, cap, sunset, niche purpose.
User Interviews says it remains standalone after the 7 January 2026 UserTesting acquisition.
Respondent, Maze, Lyssna (the company reports 690,000+ panelists, access priced separately), and dscout cover genpop and some niche screening. First-party CRMs that productize the GitLab loop include User Interviews Research Hub, Ethnio Pool, and Rally CRM.
Consumer panels are fast for genpop and empty for niche B2B. First-party is lowest time-to-value and a governance tax: access, purge, keep-warm. Screening questions are their own craft; that spoke is not live on UX Crush yet, so keep the logic here: a panel without screens is a mailing list.
NN/g cites a 20% no-show drop after one researcher switched to an internal panel. That is a single-researcher anecdote. Do not promote it to a benchmark.
Typical contents: reports, insights, notes, transcripts, recordings. NN/g (Rosala) defines the object as a central place where those artifacts are stored so others can access them.
If the repo stores session recordings or identifiable data, permissions must match who may see that data. Less than a third of NN/g survey respondents stored participant information and consent forms in the repository.
The Community repositories program frames the same object as librarianship: taxonomy, data gardening, a narrative across studies. A good repo needs a person who does that work. A seat is the lease.
On r/UXResearch, the recurring complaint is that insights go in and never come out. Stakeholders watch three-minute reels; they do not search tagged warehouses.
Why Repositories Fail (Rosala, 26 July 2024) surveyed over 400 UX and ReOps people. Cite it as an NN/g survey, not a census.
Finding | Figure |
|---|---|
Mature and thriving | 9% |
Stagnant or forgotten | 11% |
Poor adoption overall | 19% |
Good-or-better adoption if repo older than 3 years | 65% |
Good-or-better adoption if repo younger than 1 year | 34% |
Dissatisfied with the tool | 23% |
ReOps practitioner owns the repo | 8% |
No owner | 29% |
Collaboration-software satisfaction (median) | 3/5 |
User-research platform / database-tool satisfaction | 4/5 |
Four adoption failures: UX maturity too low; tool frustration (steep curve plus exclusionary pricing); no owner; too much work to contribute. Collaboration software (SharePoint, Confluence) was among the most used types and the least satisfying (median 3/5).
Age is the quiet finding. A repo older than three years shows 65% good-or-better adoption; one younger than a year shows 34%. You do not fix a graveyard by buying a nicer warehouse in month two; you fix contribution cost, ownership, and access boundaries.
Dovetail is the named repository spoke for this cluster, not the definition of ResearchOps. CEO Benjamin Humphrey announced an Accel-led January 2022 Series A from the company's Sydney and San Francisco offices (the firm dates to 2017).
Positioning in 2024–26 is "Customer Intelligence Platform." Official pricing: Free at $0, Enterprise custom, with no public mid-tier dollars.

Do not treat "40 percent of the Fortune 500" as audited research. For the commercial roundup of research platforms, use the live UX research tools list.
Condens (Munich, 100% founder-owned) is the bootstrapped EU contrast. Lite from 15€/month; Business 500€/month billed yearly; Enterprise custom. The ReOps-relevant bit is privacy and anonymization: PII redaction as the share gate, not another AI summary.

A seat still fails without a librarian. Rosala's NN/g writing is the citable version of that claim: creating and maintaining the repository is a job. AI assists tagging; it does not retire the person who decides what is canonical, what is identifiable, and what a PM is allowed to reuse.
The Community about page is still the only authority definition that pairs "making research easier" with operationalizing respect for participants. Vendor SERP celebrates seats. The operating H2 is who may run what.
On r/UXResearch, unfunded democratization shows up as research theater: the org gets efficient at producing research-shaped evidence for decisions it already wanted to make.
Pernice / NN/g (12 June 2022) defines democratization as making it acceptable and possible for anyone, no matter their role, to do user research. Benefit: more research happens.
Dangers, in their framing: "anyone can do research" with no skill and no accountability (microwave versus chef); poor research, then poor design; no one accountable; misuse of resources; halted UX-maturity growth. Good research as V.I.S.E.: Viable, Influential, Sound, Efficient. Sound includes ethical treatment and safe PII.
Five steps: Identify demand; Classify supply (researchers versus PWDR); Fulfill gaps; Sync (who is accountable; who does which research); Revise. Sync is the ReOps object. Without it you have a license count.
Carolyn Morgan (ResearchOps Review, 29 May 2025) puts a spectrum under the slogan. Research anarchy: anyone talks to users and ships decisions. Research autocracy: only "true" researchers; the backlog makes research a blocker.
The need is a research democracy with checks and balances. Without ReOps upskilling, she warns, partners take AI vendors as their research ally. She quotes vendors that promise any teammate can launch a study in 10 minutes.
Kate Towsey (4 March 2026) argues that choosing whether to democratize is almost quaint; AI already did. Counter to "I-Me-Mine AI" (personal copilots that do not compound): build a research operating system of shared agents, templates, workflows, and guardrails for what must not be democratized or handed to AI. The post-2022 fiscal reset flipped the growth trajectory toward ops-then-researchers, not researchers-then-ops.
Great Question is the commercial face of democratization, not the definition. $13 million Series A on 12 November 2025 (Inovia Capital, Y Combinator, January Capital, Character VC). Self-serve at $129/seat/month. Dwyer's line: research democratization, or empowering non-researchers to conduct and engage with high-quality UX research, is the next big shift.

Apply Pernice's dangers, Morgan's checks and balances, and Towsey's operating system to that mission. A funded category can still ship research theater if consent, sampling, and synthesis have no owner.
A written research plan, reviewed before outreach, is the cheapest Sync mechanism. That plan spoke is not live on UX Crush yet; the discipline is the same one qualitative research already uses for sample and method.
Panels, consent, repos, and guardrails fail when anyone can launch a study into the same 40 users with no queue. Intake is the boring fifth system.
A research request form captures the decision, the user group, the date a finding is useful, and the method you will not run. A research roadmap says what is in this quarter so PWDR do not shadow-run a fifth pricing study. NN/g study kits (consent, screening, field-study skeletons) belong here as templates, not as a second 101.
Keep this section short on purpose. Method selection is already on UX research methods. The ReOps job is to make the request expensive enough that people do not skip consent, and cheap enough that they still file it.
This is infrastructure, not a ranking. For feature-by-feature software picks, use UX research tools.
Tool | Best for | Pricing | Free plan |
|---|---|---|---|
Repository / customer intelligence | Yes, $0 | ||
EU-hosted repo, PII redaction | Lite from 15€/mo; Business 500€/mo billed yearly | No public free tier on the pricing page | |
Self-serve studies plus ops wrappers | Check current site | ||
Centralized consent, first-party pool | See Ethnio pricing | Check current site | |
Research CRM, engagement rules | Not published as a self-serve grid in this research pass | Check current site |
Buy the tool that matches the system you are willing to staff. A repository with no owner is the failure cell in the NN/g table.
Recruiting is the pain everyone feels. Towsey's NN/g interview and the Community definition both put systems around doing, consuming, and acting on research. If your ReOps hire only runs a calendar, you staffed a coordinator and named it ops.
ONRR dropped that ritual for a reason. Implied consent ("they showed up") fails GDPR's unambiguous test. Umbrella consent for future studies fails NN/g.
Panel opt-in is not this study. Put three opt-in points in the session and a DPA next to the form.
NN/g's 2026 failure modes are specific: attributes go stale, engaged customers positively skew feedback, the business moves and the panel does not. GitLab publishes a 6-month max, a named DRI, and a $600/year cap because those are the controls. A shared sheet with personal email outreach is how you burn the only 40 enterprise admins you have.
Collaboration software was among the most used types and the least satisfying.
Hire or assign a curator. Make contribution cheaper than skipping, and match permissions to identifiable recordings.
Pernice's microwave-versus-chef problem, Morgan's anarchy, Towsey's personal copilots. More people talking to users is the benefit; research-shaped evidence for a decision already made is the failure.
Sync, consent ownership, stop-rules, and a repository landing rule are the fix. A $129 seat is not.
Most digital-product UX research is not Common Rule research. GDPR can still apply when you target EEA people. Neither fact means every click test needs an IRB, and neither fact hands you scientific-research derogations.
Use UCSF's trigger list, GDPR-info's consent tests, and ONRR's process. Get counsel for your jurisdiction.
Pick the failure you already have. Spreadsheet outreach with no contact log is a panel problem. A signed PDF and recordings in a tool you never read is a consent problem.
A Dovetail seat nobody searches is a librarianship problem. Unfunded seats shipping research-shaped evidence is a Sync problem. Staff that one system this quarter; buy the tool after the owner exists.

A practical decision framework for choosing UX research methods, with cost and time benchmarks per method, the attitudinal-behavioral gap as the organizing prin

A free jobs to be done template covering the Christensen switch-interview method and Ulwick's ODI outcome scoring. Includes a downloadable Google Sheet with six

Every $1 invested in UX returns $100. Here are 42 statistics on UX ROI organized by theme, with inline citations to Forrester, McKinsey, Baymard, and NNG.