UX ResearchOps as Four Operating Systems

UX ResearchOps as four systems: first-party panels, consent ops, repositories, and democratization guardrails. NN/g data and a GitLab SOP.

Updated 19 min read
UX researcher holding a sticky note that says run a usability test

UX ResearchOps is the practice that sets user research in motion: people, mechanisms, and strategies for panels, consent, knowledge, and quality. The ResearchOps Community (2018) and Nielsen Norman Group treat it as orchestration at scale, not a recruiting calendar.

This article is UX ResearchOps, not academic operations research. In NN/g's July 2024 survey of over 400 UX and ReOps people, only 9% of research repositories were mature and thriving.

Ranking pages still sell a 101, a course, or a seat. This hub is the operating manual those pages list as bullets: first-party panels, consent as a multi-point system, repositories as librarianship, and democratization guardrails.

Written for UX and product teams who already run studies. It is not legal advice, not a consent-form template, and not a job listing.

Key Takeaways

  • ResearchOps is a practice (Community / NN/g / Towsey), not a synonym for recruiting and not operations research.
  • Consent is an operations loop: GDPR elements, a three-point opt-in, vendor data-processing terms, and a separate panel opt-in from per-study consent.
  • A first-party panel is infrastructure with a named owner, frequency caps, and a sunset. GitLab's public handbook is one SOP, not industry law.
  • A repository seat is not a repository. NN/g found 29% of surveyed repos had no owner.
  • Democratization without who-may-run-what, consent ownership, stop-rules, and a repository landing rule produces research-shaped evidence, not research.

What Is UX ResearchOps?

The ResearchOps Community still uses the 2018 workshop line: the people, mechanisms, and strategies that set user research in motion. It exists because research at scale produces work that is not the research itself: ethics and consent, participant data, intake, and the questions of why, when, and how much.

NN/g (Kaplan, 16 August 2020) calls it the orchestration of people, processes, and craft so research scales. The 2022 study guide (last reviewed 27 August 2024) restates the same definition. Six focus areas: participants, governance, knowledge, tools, competency, advocacy.

Recruitment is the obvious pain. It is not the whole job. On r/UXResearch, people who land on ops teams report they expected participant recruiting and found standards, documentation, licenses, and labs.

Kate Towsey coined PWDR ("people who do research"), founded the Community, and stepped back in 2019. She later wrote Research That Scales (Rosenfeld, September 2024). In a February 2025 interview with Maria Rosala, she defined ResearchOps as "the systems that enable people to do research, consume research, and act on research." Civic-design analogy: the city of research.

Google Ads collapses research ops, researchops, research operations, and operations research into one bucket. That bucket is the wrong field (INFORMS, PhD programs, Hillier). Title, H1, and this paragraph exist so the page files under UX.

Role Versus Practice

A research operations manager is a common way to staff the practice. The practice still exists when the title does not.

Do not treat this page as a career listing. Staffing shows up later as a democratization problem: someone has to own consent, the panel, the repository, and the stop-rules.

DesignOps is a sibling. Some NN/g writing nests ResearchOps under DesignOps; the Community and Towsey treat it as its own practice. Keep both readings; do not flatten them.

Why UX ResearchOps Matters in 2026

Kaplan's cost argument still does the business work. If research volume goes 10×, ops overhead should push total cost to 9× or 8×, not 11×. Without ops, every extra study adds its own recruiting, consent, storage, and synthesis tax.

UserTesting acquired User Interviews on 7 January 2026. User Interviews says it remains a standalone, tool-agnostic product.

Great Question announced a $13 million Series A on 12 November 2025, led by Inovia Capital.

NN/g shipped Internal User Panels (23 January 2026) and Why User Panels Fail (24 April 2026). Towsey's March 2026 essay argues that choosing whether to democratize is almost quaint, because AI already did.

The Community about page describes a membership of more than 15,000. Treat that as community scale, not a census of jobs.

How UX ResearchOps Works: Four Operating Systems

You can buy a panel CRM, a consent add-on, a repository seat, and a self-serve study tool and still have no ResearchOps. The operating object is four systems that share a participant, a recording, and a finding.

System

Job

Failure mode if you skip it

Consent and data

Multi-point opt-in, information elements, vendor processing terms

A signed PDF, then recordings in a tool whose terms you never read

First-party panels

Re-contact opted-in users with a DRI, caps, audit, sunset

A spreadsheet and personal email, with no contact log

Repositories

Taxonomy, access control, a person who gardens

A seat with no owner

Democratization guardrails

Who may run which method, who owns consent, stop-rules, what must land in the repo

Unfunded seats. Research-shaped evidence for decisions already made

Intake and a research roadmap sit underneath all four. They are shorter on purpose. Method choice still lives on the UX research methods hub.

This section is operations guidance for UX teams, not legal advice. Do not copy it into a form and call it counsel.

Do not file an IRB for every usability test. Do not treat product UX as scientific research with a GDPR research carve-out.

Most digital-product UX research is nonclinical and relatively low-risk. Risk is not zero. A casual customer call becomes research-ethics territory as soon as you transcribe quotes or share that person's information without having told them.

When GDPR Actually Applies

UCSF IRB is the clean trigger list for product teams. GDPR can apply if you are established in the EEA, target or monitor people there, or transfer EEA personal data out. Special-category data (health, biometrics, ethnicity) is a higher bar.

GDPR-info on Articles 6 and 7: processing personal data is generally prohibited unless allowed by law or the person has consented. Consent is one of six lawful bases. Valid consent is freely given, specific, informed, and unambiguous.

Withdrawal must be as easy as giving. No implied consent, and no form requirement; written is recommended for accountability.

If you relied on consent, you must stop that processing when consent is withdrawn. You may not switch to legitimate interest after withdrawal.

Hallinan, Boehm, Külpmann, and Elson (2023, AMPPS): when personal data are collected directly, GDPR information obligations (primarily Article 13) are normally delivered inside the informed-consent procedure. Failure is a GDPR breach. Their recommendation is one clearly identifiable subsection, not a second PDF nobody opens.

Cite them for what belongs in the conversation. They studied psychological research; your usability test is not that study.

Three Opt-In Points Beats One Signature

The U.S. Office of Natural Resources Revenue, writing about federal UX on 3 April 2024, called the consent form the least user-friendly aspect of UX research. They dropped the signed-PDF ritual and rejected implied consent (participating equals consent).

Replacement: a user-research agreement process with three opt-in points:

  • Agreeing to participate.
  • Start of the interview: confirm they read the agreement, ask questions, opt in.
  • End of the interview: opt in to feedback being used in the summary.

ONRR also distinguished human-subjects research (the subject is the person) from federal UX (the subject is the website, tool, or service). Do not republish their agreement as your legal form. Steal the ops shape.

NN/g (Fessenden, 3 July 2022) matches the modular half: checkboxes for participate / audio / video; give the participant a copy; "umbrella" consent for an indefinite timeframe of current and future studies is very problematic. Panel opt-in is not study consent.

Element

Primary source

Ops implication

Freely given, specific, informed, unambiguous; easy withdrawal

GDPR-info, Art. 6/7

Opt-in only. Stop that processing on withdrawal

Purpose, retention, access, rights, transfers

UCSF GDPR checklist as elements, not a template

Put the elements in one identifiable subsection

Article 13 delivered inside consent

Hallinan et al., 2023

The conversation carries the information duty

Three opt-in points

ONRR, 2024

Participate, start-of-session, use-of-feedback

Modular recording; no umbrella consent

NN/g informed consent

Separate panel storage consent from this study

If you actually run Common Rule or FDA research, HHS OHRP allows electronic consent and keeps IRB authority over the process, not just the file. That guidance is long-standing. It is not a 2026 rewrite, and it is not the default for product usability testing.

The Vendor Contract Sits Next to the Form

Luria 2023 documented a control teams miss: UX research platforms often claim ownership of participant data in their terms. Some will not let the researcher download, so "delete after the study" also deletes your copy. Platforms may argue that signing up for the platform covers any later study.

Ops control next to the consent form: a data-processing agreement, export and deletion rights, and a named owner for recordings. Do not name a live vendor as "sells your data" without that vendor's current terms. The job is to read them.

Maria Rosala's ethical-maturity article (29 December 2019) is the bootstrap: if you have nothing, start by standardizing consent documents and processes for collecting and storing research data. Mature practice adds a code of conduct, ethics training for everyone who runs a study, standardized forms, ethics experts (often ReOps), and a UX-specific data policy.

Consent infrastructure is a product category. Ethnio centralizes consent (DocuSign / Adobe Sign embed) and can give PMs and designers collaborator seats with no Pool or Incentives access.

Rally tracks consent, engagement rules, and access. Those are examples of the system, not the law.

First-Party Participant Panels

Members already know the product. NN/g (January 2026) still treats a panel as infrastructure you can re-contact: a curated, opted-in group whose distinguishing features are consent and continuity.

They will not always reflect new or unfamiliar users. Use external recruiters for discovery and competitive work. Hybrid is the normal setup.

The Operating Loop

NN/g's build sequence is the loop you actually run: recruit; organize and segment; contact and schedule; incentivize; reengage and manage (participation history, rotate outreach); govern and improve (ownership, who can access, contact, and update, privacy).

The May 2023 participant-database article adds the consent split that teams skip: ask consent to store data; panel opt-in is not study consent; track last invited, last participated, and studies. Spreadsheet panels need manual governance so researchers do not abuse the file. Internal panels: low cost, medium-to-high bias.

Why User Panels Fail (NN/g, April 2026) names three modes. Static database: attributes go stale; you need explicit ownership and a quarterly audit. Sampling bias: engaged customers positively skew feedback; you need rotation, contact-frequency caps, and occasional off-panel recruiting.

Business drift: the panel still reflects yesterday's audience. The presence of a panel is not what signals maturity. The discipline with which it is managed does.

One Public SOP: GitLab

GitLab's handbook is the best copyable first-party manual in public. It is one company's SOP. It is not a regulation.

Use a panel for hard-to-recruit niches (enterprise, Kubernetes experts, self-managed), not as the default for every study. Research Operations recommends a panel last no longer than 6 months. Historical sizes: 30–500, with a named Panel DRI.

Incentive cap, US-tax-adjacent: 4×60-minute sessions / $600 gratuity per fiscal year, then ineligible. Wave outreach (their example: panel of 1,000, waves of 100). Cons they name: fatigue, pattern-trained respondents, refresh cost, bias.

Do not copy Qualtrics + Calendly + a reimbursement template because GitLab used a stack. Copy the rules: DRI, cap, sunset, niche purpose.

Buy a Sample Versus Be the Panel

User Interviews says it remains standalone after the 7 January 2026 UserTesting acquisition.

Respondent, Maze, Lyssna (the company reports 690,000+ panelists, access priced separately), and dscout cover genpop and some niche screening. First-party CRMs that productize the GitLab loop include User Interviews Research Hub, Ethnio Pool, and Rally CRM.

Consumer panels are fast for genpop and empty for niche B2B. First-party is lowest time-to-value and a governance tax: access, purge, keep-warm. Screening questions are their own craft; that spoke is not live on UX Crush yet, so keep the logic here: a panel without screens is a mailing list.

NN/g cites a 20% no-show drop after one researcher switched to an internal panel. That is a single-researcher anecdote. Do not promote it to a benchmark.

Research Repositories as Librarianship

Typical contents: reports, insights, notes, transcripts, recordings. NN/g (Rosala) defines the object as a central place where those artifacts are stored so others can access them.

If the repo stores session recordings or identifiable data, permissions must match who may see that data. Less than a third of NN/g survey respondents stored participant information and consent forms in the repository.

The Community repositories program frames the same object as librarianship: taxonomy, data gardening, a narrative across studies. A good repo needs a person who does that work. A seat is the lease.

On r/UXResearch, the recurring complaint is that insights go in and never come out. Stakeholders watch three-minute reels; they do not search tagged warehouses.

Why Repositories Fail

Why Repositories Fail (Rosala, 26 July 2024) surveyed over 400 UX and ReOps people. Cite it as an NN/g survey, not a census.

Finding

Figure

Mature and thriving

9%

Stagnant or forgotten

11%

Poor adoption overall

19%

Good-or-better adoption if repo older than 3 years

65%

Good-or-better adoption if repo younger than 1 year

34%

Dissatisfied with the tool

23%

ReOps practitioner owns the repo

8%

No owner

29%

Collaboration-software satisfaction (median)

3/5

User-research platform / database-tool satisfaction

4/5

Four adoption failures: UX maturity too low; tool frustration (steep curve plus exclusionary pricing); no owner; too much work to contribute. Collaboration software (SharePoint, Confluence) was among the most used types and the least satisfying (median 3/5).

Age is the quiet finding. A repo older than three years shows 65% good-or-better adoption; one younger than a year shows 34%. You do not fix a graveyard by buying a nicer warehouse in month two; you fix contribution cost, ownership, and access boundaries.

Dovetail Is a Spoke, Not the Hub

Dovetail is the named repository spoke for this cluster, not the definition of ResearchOps. CEO Benjamin Humphrey announced an Accel-led January 2022 Series A from the company's Sydney and San Francisco offices (the firm dates to 2017).

Positioning in 2024–26 is "Customer Intelligence Platform." Official pricing: Free at $0, Enterprise custom, with no public mid-tier dollars.

Dovetail homepage
Dovetail homepage.

Do not treat "40 percent of the Fortune 500" as audited research. For the commercial roundup of research platforms, use the live UX research tools list.

Condens (Munich, 100% founder-owned) is the bootstrapped EU contrast. Lite from 15€/month; Business 500€/month billed yearly; Enterprise custom. The ReOps-relevant bit is privacy and anonymization: PII redaction as the share gate, not another AI summary.

Condens homepage
Condens homepage.

A seat still fails without a librarian. Rosala's NN/g writing is the citable version of that claim: creating and maintaining the repository is a job. AI assists tagging; it does not retire the person who decides what is canonical, what is identifiable, and what a PM is allowed to reuse.

Democratization Guardrails, Not a Slogan

The Community about page is still the only authority definition that pairs "making research easier" with operationalizing respect for participants. Vendor SERP celebrates seats. The operating H2 is who may run what.

On r/UXResearch, unfunded democratization shows up as research theater: the org gets efficient at producing research-shaped evidence for decisions it already wanted to make.

The Guardrail Spec the SERP Skipped

Pernice / NN/g (12 June 2022) defines democratization as making it acceptable and possible for anyone, no matter their role, to do user research. Benefit: more research happens.

Dangers, in their framing: "anyone can do research" with no skill and no accountability (microwave versus chef); poor research, then poor design; no one accountable; misuse of resources; halted UX-maturity growth. Good research as V.I.S.E.: Viable, Influential, Sound, Efficient. Sound includes ethical treatment and safe PII.

Five steps: Identify demand; Classify supply (researchers versus PWDR); Fulfill gaps; Sync (who is accountable; who does which research); Revise. Sync is the ReOps object. Without it you have a license count.

Anarchy, Autocracy, Democracy

Carolyn Morgan (ResearchOps Review, 29 May 2025) puts a spectrum under the slogan. Research anarchy: anyone talks to users and ships decisions. Research autocracy: only "true" researchers; the backlog makes research a blocker.

The need is a research democracy with checks and balances. Without ReOps upskilling, she warns, partners take AI vendors as their research ally. She quotes vendors that promise any teammate can launch a study in 10 minutes.

Kate Towsey (4 March 2026) argues that choosing whether to democratize is almost quaint; AI already did. Counter to "I-Me-Mine AI" (personal copilots that do not compound): build a research operating system of shared agents, templates, workflows, and guardrails for what must not be democratized or handed to AI. The post-2022 fiscal reset flipped the growth trajectory toward ops-then-researchers, not researchers-then-ops.

The Commercial Face Is Not the Thesis

Great Question is the commercial face of democratization, not the definition. $13 million Series A on 12 November 2025 (Inovia Capital, Y Combinator, January Capital, Character VC). Self-serve at $129/seat/month. Dwyer's line: research democratization, or empowering non-researchers to conduct and engage with high-quality UX research, is the next big shift.

Great Question homepage
Great Question homepage.

Apply Pernice's dangers, Morgan's checks and balances, and Towsey's operating system to that mission. A funded category can still ship research theater if consent, sampling, and synthesis have no owner.

Seven Guardrails You Can Staff

  • Who is accountable (NN/g Sync).
  • Who may run which method given current skill.
  • Consent ownership stays with the research / ReOps system, not whoever launched the tool.
  • Quality bar: ethical treatment plus safe PII, not "a study launched."
  • Stop-rules: ReOps can say no (Morgan's democracy, not anarchy).
  • What must land in the repository before a finding is done.
  • AI: shared OS and standards, not personal copilots (Towsey). Teach partners to verify, not to validate (Morgan).

A written research plan, reviewed before outreach, is the cheapest Sync mechanism. That plan spoke is not live on UX Crush yet; the discipline is the same one qualitative research already uses for sample and method.

Intake, Roadmaps, and the Rest of the Queue

Panels, consent, repos, and guardrails fail when anyone can launch a study into the same 40 users with no queue. Intake is the boring fifth system.

A research request form captures the decision, the user group, the date a finding is useful, and the method you will not run. A research roadmap says what is in this quarter so PWDR do not shadow-run a fifth pricing study. NN/g study kits (consent, screening, field-study skeletons) belong here as templates, not as a second 101.

Keep this section short on purpose. Method selection is already on UX research methods. The ReOps job is to make the request expensive enough that people do not skip consent, and cheap enough that they still file it.

Tools That Productize the Four Systems

This is infrastructure, not a ranking. For feature-by-feature software picks, use UX research tools.

Tool

Best for

Pricing

Free plan

Dovetail

Repository / customer intelligence

Enterprise custom

Yes, $0

Condens

EU-hosted repo, PII redaction

Lite from 15€/mo; Business 500€/mo billed yearly

No public free tier on the pricing page

Great Question

Self-serve studies plus ops wrappers

$129/seat/month

Check current site

Ethnio

Centralized consent, first-party pool

See Ethnio pricing

Check current site

Rally

Research CRM, engagement rules

Not published as a self-serve grid in this research pass

Check current site

Buy the tool that matches the system you are willing to staff. A repository with no owner is the failure cell in the NN/g table.

Common ResearchOps Mistakes to Avoid

Treating ResearchOps as Recruiting

Recruiting is the pain everyone feels. Towsey's NN/g interview and the Community definition both put systems around doing, consuming, and acting on research. If your ReOps hire only runs a calendar, you staffed a coordinator and named it ops.

ONRR dropped that ritual for a reason. Implied consent ("they showed up") fails GDPR's unambiguous test. Umbrella consent for future studies fails NN/g.

Panel opt-in is not this study. Put three opt-in points in the session and a DPA next to the form.

A Spreadsheet Panel With No DRI

NN/g's 2026 failure modes are specific: attributes go stale, engaged customers positively skew feedback, the business moves and the panel does not. GitLab publishes a 6-month max, a named DRI, and a $600/year cap because those are the controls. A shared sheet with personal email outreach is how you burn the only 40 enterprise admins you have.

Buying a Repository Seat and Calling It Knowledge

Collaboration software was among the most used types and the least satisfying.

Hire or assign a curator. Make contribution cheaper than skipping, and match permissions to identifiable recordings.

Democratization as Unfunded Seats

Pernice's microwave-versus-chef problem, Morgan's anarchy, Towsey's personal copilots. More people talking to users is the benefit; research-shaped evidence for a decision already made is the failure.

Sync, consent ownership, stop-rules, and a repository landing rule are the fix. A $129 seat is not.

Filing an IRB (or Claiming a Scientific-Research GDPR Carve-Out) for Ordinary Product UX

Most digital-product UX research is not Common Rule research. GDPR can still apply when you target EEA people. Neither fact means every click test needs an IRB, and neither fact hands you scientific-research derogations.

Use UCSF's trigger list, GDPR-info's consent tests, and ONRR's process. Get counsel for your jurisdiction.

Start With the System You Already Broke

Pick the failure you already have. Spreadsheet outreach with no contact log is a panel problem. A signed PDF and recordings in a tool you never read is a consent problem.

A Dovetail seat nobody searches is a librarianship problem. Unfunded seats shipping research-shaped evidence is a Sync problem. Staff that one system this quarter; buy the tool after the owner exists.

Frequently Asked Questions

Related Articles