Home · Newsletter

The site permission letter for a Purdue Global study: who signs it, what it must name, why it stalls files

Purdue Global's IRB does not use the phrase most people type into a search box. On its published submission guidelines the item is called agency approval, and the university sets out four things about it in one short list: the permission must be in writing, it must sit on letterhead and carry an official's signature, and it must arrive from an agency email address rather than a personal Gmail account. Agency approval is one of five documents on Purdue Global's own IRB submission checklist. It is also the only one of the five whose signature belongs to somebody who is not you — which is why a file that is otherwise finished can sit still, waiting on a page nobody outside the study has any reason to hurry.

Victoria Halloran, PhD · 2026-08-23

Short answer

Purdue Global calls it agency approval. It must be written permission on the organisation's letterhead, signed by an official, arriving from an agency email address rather than a personal account, and naming the same site and activities your application names.

Does a Purdue Global study need agency approval at all?

The test is not geography and not formality. It is whether some organisation other than you controls the people, the premises, the channel or the records your study intends to touch. If the answer is yes for any one of those four, written permission belongs in the file.

Purdue Global's guidelines make the reach of that rule concrete with three worked examples. The first is a Dean's approval, where the people you want to reach are the faculty or the enrolled population of a school. The second is website approval to post a recruitment notice, which may come back as a standard template the website itself issues. The third is an outside agency's approval to use its site, its personnel or its data. Together those reach further than the phrase "research site" suggests: a survey that never puts you in a building still needs permission if it travels down an employer's distribution list, and a records study that never meets a participant still needs permission because somebody owns the records.

What must the approval actually contain?

Four requirements are published. The rest are what stops a reviewer asking a follow-up question — treat the published four as the floor and the remainder as the difference between a page that passes and one that comes back.

The published requirements, and the additions that stop a return
The elementSourceWhat a usable page does
In writingPublishedA letter — not a remembered conversation, not a verbal yes relayed by a manager.
On letterheadPublishedThe organisation's own letterhead, so the page shows who is granting permission without anyone inferring it.
Signed by an officialPublishedA signature from someone whose role carries authority over those people, that place or those records.
From an agency addressPublishedSent from the organisation's domain. Purdue Global names the failure directly: not a personal Gmail account.
The site and the activitiesReads against the applicationThe same organisation or unit the research plan names, spelled the same way, permitting the things the study will actually do there.
The records and the researcherReads against the data planWhich records, whether identifiers travel with them, and you named under the study title the application uses.

Notice what is absent from that list: enthusiasm. A page saying the organisation is excited about the project, values the partnership or looks forward to the findings has granted nothing. Permission is a verb applied to named activities. Support is a sentiment, and a reviewer cannot approve a sentiment.

Who counts as "an official," and how do you find them?

The signature question sinks more approvals than the wording does, because the helpful person and the authorised person are usually two different people. A unit manager glad to have the work done rarely holds authority to commit the organisation to research on its own personnel or its own data. Nothing about such a letter looks wrong; it simply is not permission, and the reviewer reads authority, not warmth.

Work backwards from what you are asking for. Access to people means whoever can commit those people's time. Access to premises means whoever controls the premises. Access to records means whoever is accountable for them — often a privacy or compliance role in health settings, and a Dean rather than a course lead in a school. Where a setting layers approvals, with a district above a building or a health system above a unit, more than one signature is normal. And some sites will not sign a letter at all, offering a data-use agreement instead; if that document names the university as a party, an individual cannot bind the institution, so it goes to the university before anyone signs.

What about recruiting inside a Facebook group or on a website?

This is the case candidates most often assume needs no permission, and Purdue Global addresses it directly. Where recruitment happens through a site such as a Facebook group, the guidelines require you to reference that site's Terms of Use, naming Facebook's own terms page as the example. The logic matches the employer case: somebody else owns the channel, and their rules govern what may be posted in it.

An online recruitment plan therefore produces two documents rather than one — the permission itself, from the group owner, moderator or site administrator, and the reference to the platform's terms, showing the board that the posting is allowed by the platform as well as by the person holding the keys. The website example adds a small mercy: for a public posting board, the approval may simply be the standard template the website issues, which makes asking a routine request rather than a negotiation.

What must the approval agree with, line by line?

The board never reads agency approval on its own. It reads it beside the research plan summary, the recruitment plan and the consent, and it notices when the four disagree. This is where most returns are made, and none of them concern the quality of the study.

  • The organisation's name. One spelling. A file saying "Riverside Health" in the plan and "Riverside Regional Health System" on the letterhead has invited a question it need not have invited.
  • The unit or campus. If the plan names one clinic, school or department, the approval names that one — not the parent organisation, which grants either too much or nothing recognisable.
  • The activities. If the methodology describes interviews and a chart pull, an approval covering only interviews leaves half the study unauthorised.
  • The population. Faculty, staff, patients, clients, members — the approval permits access to the group the recruitment plan intends to approach.
  • The identifiers. If the data plan says records arrive de-identified, the approval should not read as though a named list is being handed over.

That is this practice's whole discipline in one document: the same dimension, measured in four places, reading identically each time. The step-by-step route sets out the full sequence, and the application checklist shows where agency approval sits among the other four submission items.

Why is this the document that stalls files?

Because it is the only one you cannot finish alone. A consent form can be rewritten tonight. A methodology section can be tightened this afternoon. An approval waits on an organisation's internal routing — a compliance reading, an authority who is travelling, a committee with its own agenda — and none of that begins to move because your file is ready.

Purdue Global's own guidance sharpens the cost: its instructions for completing the submission form state that any items missing from a submission will delay its review. An incomplete file is not held in a queue while the missing page is chased; it is simply not yet something the board can act on. So the request goes out early, while the research plan is still settling — and it goes out with the requirements attached, because an official asked to compose a permission letter from scratch will produce less, later, than an official asked to review one and sign it.

How we carry the agency approval

This is the document we most often find missing when a file first reaches us, so it is the one we start on first. We list every organisation, channel and record set the study touches and decide which genuinely need permission — sometimes fewer than feared. We identify who can sign, draft each approval for signature with the site, activities, population and identifiers already matched to the plan, reference platform terms where recruitment runs through someone else's channel, and follow the signatures until they arrive. Our how-it-works sheet places this among the three moves, and the questions page covers what candidates ask first. The study and the findings stay yours; the determination belongs to the board.

What to do next

If your study touches an organisation you do not control and no signed page exists yet, that is the thread to pull today — before the methodology is final, not after. Ask for the free application review and say which organisations, channels and record sets your study reaches. A consultant will tell you which need written permission, who is likely to hold the authority to grant it, and whether any will want an agreement rather than a letter. If your study needs no permission at all, we will say so, and nothing goes to the board until you decide it should.

Sources

Give us the entire IRB process. Keep the study.

The free application review is where it starts. From there we carry everything — the determination and the plan, every document drawn to the same dimensions, the submission itself, and every reply to the board until the approval letter exists. The study, the data and the findings remain yours; the board's decision is its own.

Request the free application review Send whatever exists — drafts count.
Has the board measured your file yet?