Research

Research Ops

Research Ops is the shared operating layer behind customer and user research: recruiting, consent and data rules, repositories and tools, set up once so every study can run faster and safer.

In short

Research Ops (ResearchOps or ReOps) is the set of people, processes and tools that support user and customer research across an organization: recruiting and paying participants, consent and data governance, research repositories, tooling and training. It grew out of practitioner workshops held from 2018 rather than from a single inventor, and it lets a company run more studies without each team rebuilding the same logistics.

Origin
Practitioner work, no single inventor: the ResearchOps Community's #WhatisResearchOps workshops; Nielsen Norman Group's six focus areas, 2018; 2020
Level
401 · Expert
Fits
Scale-up, Enterprise
Time to apply
two to four weeks for a first audit and a minimal setup; then ongoing ownership
What you need
a list of the research done in the last 12 months and who ran it · one person who owns operations, even part time · your privacy or legal lead for an hour on consent and retention · a budget line for incentives and at least one recruiting channel

Research Ops, usually written ResearchOps or ReOps, is the operating layer that sits behind user and customer research. It covers finding and paying participants, consent and data rules, the repository where findings live, the research tool stack, and training for people who run studies without being researchers. The ResearchOps Community defines it as “the people, mechanisms, and strategies that set user research in motion.”

Nobody invented it in a paper. Researchers at companies with growing research teams kept solving the same logistics problems, and eventually they started comparing notes in public.

Where ResearchOps came from

ResearchOps is a practice that practitioners named and mapped together. In 2018 the ResearchOps Community, a Slack group Kate Towsey started that year, ran a global series of volunteer workshops asking one question: what is ResearchOps? Rally’s interview with Towsey puts the count at 32 workshops with hundreds of participants. Vendor write-ups give slightly higher numbers, so treat “more than 30” as the safe figure.

The workshops produced a working definition and a framework. The community’s own page models the field as eight pillars, from environment and scope to recruitment, knowledge management, governance and tools. Nielsen Norman Group published a tighter version in 2020, and Towsey’s 2024 book, Research That Scales, reworked the map again.

Three empty boxes grouped as Studies sit on top of a wide blue bar labelled ResearchOps, with arrows from the bar up to each study. Under the bar, four boxes are connected to it: Participants, Governance, Knowledge and Tools.
Studies draw on one shared layer instead of each rebuilding recruiting, consent, storage and tools.

The logic is the same in every version. Each study needs participants, a consent form, somewhere to keep recordings and a way to share what it found. Without a shared layer, every team rebuilds these pieces, and the researcher’s week fills with scheduling and gift cards. Aaron Fulmer’s account of Microsoft’s research operations started from exactly those pain points: participants, support staff and lab space.

Three maps of the same work

The three best-known models cover the same ground and slice it differently. Use whichever your team finds easiest to explain to a budget holder.

ResearchOps Community, 2018 NN/g, 2020 Kate Towsey, 2024
Recruitment and admin Participants Participant recruitment
Governance Governance Ethics and privacy
Data and knowledge management Knowledge Knowledge management
Tools and infrastructure Tools Tools and vendors
People Competency People and skills; onboarding and support
Organisational context, scope, environment Advocacy Program management; money and metrics

NN/g’s ResearchOps 101, by Kate Kaplan, also gives a cost test for whether operations work: if research volume grows tenfold, cost should grow ninefold or less, with eightfold as the goal. Towsey’s line for the same idea is “Research Does Not Scale–Systems Do.”

Participants: the first bottleneck

Recruiting is where most teams feel the pain first, so fix it first. A working setup has three parts: a source of people, a screener, and rules for paying and contacting them.

For sources, an opt-in customer panel is the cheapest route over time. NN/g’s guide to participant databases recommends recording when each person was last invited and last took part, limiting how often anyone is contacted, making opt-out easy and auditing the panel every year or two. Agencies suit general-public studies, and the GOV.UK Service Manual warns that finding disabled participants can take up to a month.

Incentives work better paid up front. GOV.UK advises giving the incentive at the start of the session, so people do not feel they must say the right thing to get paid. Survey research points the same way: the meta-analysis by Eleanor Singer and colleagues summarises earlier evidence that prepaid incentives beat promised ones.

Online studies now need a fraud check too. A 2023 letter in Health Expectations described “imposter participants” across five studies: replies within minutes of an ad going live, requests for vouchers instead of bank transfers, cameras that stay off. The authors recommend writing an imposter protocol while planning the study, not after the first suspicious call.

Governance is the set of rules for what you may collect, how long you keep it and who sees it. In the EU and the UK, data protection law makes most of these rules mandatory. This section summarises them; it is not legal advice.

Four boxes left to right joined by arrows: Recruit, Consent in blue, Session, Synthesis. From Synthesis one arrow leads up to Repository and another down to Delete.
Consent decides what may happen to the data. Insights go to the repository; raw recordings and contact details get a deletion date.

Four rules cover most research work:

  1. Pick the lawful basis before recruiting. The ICO’s guide to lawful basis says no basis is always better, that many organisations choose between consent and legitimate interests, and that you usually cannot switch away from consent later.
  2. If you rely on consent, make it specific and reversible. GDPR Article 7 says withdrawing must be as easy as giving consent, and the controller must be able to show that consent was given. NN/g’s consent guide suggests separate checkboxes for taking part, audio and video.
  3. Keep only what the study needs, for as long as it needs it. Article 5 sets purpose limitation, data minimisation and storage limitation. Health data is a special category under Article 9 and needs an extra condition.
  4. Keep research apart from marketing. The ICC/ESOMAR Code requires researchers to separate promotional activity from research.

The GOV.UK consent guidance adds a practical detail: name and file data so each recording can be matched to its consent record. Without that link, honouring a withdrawal means searching every drive by hand.

Repositories: why most stall

A research repository is a central place where finished studies, individual insights, recordings and study materials live so others can find them. Most companies that build one struggle to keep it alive.

Maria Rosala’s 2024 NN/g survey of over 400 practitioners, reported in Why Research Repositories Fail, found only 9% described their repository as mature and thriving, and 29% had no owner. The causes were low research maturity, tools that are hard to search or contribute to, no owner, and too much tagging work for contributors. According to Rosala’s data, adoption improves with age: 65% of repositories older than three years had good adoption, against 34% of those under a year.

The fixes are modest. Set a goal and an owner before choosing a tool, start with a few broad tags as Research Repositories 101 advises, import the most used studies first, and keep identifiable recordings out of the shared insight space.

How common is it?

Dedicated roles are still the exception outside large companies. NN/g’s 2021 survey of 353 UX professionals found 46% of organizations had no dedicated ResearchOps person, and only 9% tracked what happened to research findings. User Interviews found in 2025 that 35% of respondents had at least one dedicated ReOps professional, mostly in companies with over 1,000 staff. The surveys use different samples, so read them as direction, not trend lines.

For smaller teams the answer is a part-time owner and the four basics: a panel, a consent template, a retention rule and one searchable place for findings. In our marketing operational system work we treat research the same way as any other recurring process: an owner, a written standard and a metric someone reviews.

How to apply Research Ops, step by step

  1. Audit the last year of research. List every study from the past 12 months: who ran it, how participants were found and paid, where consent forms and recordings now sit, and where the findings went. Ask researchers and product managers which logistics took the most time. Result: a one-page map of the current setup and the three biggest bottlenecks.
  2. Name an owner and set the scope. Give one person ownership of operations, with a written scope covering which teams and which kinds of research they support. According to Nielsen Norman Group's 2024 repository survey, 29% of repositories had no owner at all. Result: a named owner, a scope note and an agreed way for teams to request help.
  3. Fix participants first. Set up one recruiting route per audience: an opt-in customer panel, an agency or a panel tool. Write screener templates, an incentive policy that pays at the start of the session, contact limits per person and a short fraud check for online studies. Result: a team can book qualified participants in days, not weeks.
  4. Write the consent and retention rules. With your privacy lead, choose the lawful basis, write a modular consent form, set where raw recordings live and for how long, and decide who may see identifiable data. Record each person's consent so data can be matched to it. Result: one governance page that every study follows.
  5. Start a small repository. Pick a place for finished studies and individual insights, define a few broad tags, and import the most used recent studies first. Treat it as a product: test it with the people who should search it. Result: anyone can find what the company already knows about a topic in minutes.
  6. Measure and review each quarter. Track time to recruit, studies run, cost per study, repository searches and how many findings led to a decision. Review the bottlenecks list every quarter and retire tools nobody uses. Result: a short quarterly report that shows whether the operation is paying for itself.

Examples

Microsoft's games research team

In a 2019 Microsoft Research article, Aaron Fulmer describes how the research operations group started from pain points: participants, support staff and lab space. The team mapped these onto the ResearchOps Community's framework and drew its own model, with participants, space and staff as the visible top layer and processes and finance as the foundation underneath. His stated aim was that researchers no longer had to handle all the logistical details themselves.

A digital clinic with patient interviews

Illustrative. A telehealth company runs 6 to 8 patient interviews a month across three product teams. Each team recruits on its own, consent forms sit in personal drives, and recordings that mention diagnoses stay in a shared folder for years. One operations owner sets up an opt-in patient panel with contact limits, a consent form with separate checkboxes for taking part, recording and quoting, a 90-day deletion rule for raw recordings, and a repository that holds only de-identified insights. Health data is special category data under GDPR Article 9, so the privacy lead signs off the process once instead of reviewing every study.

A payments startup with two researchers

Illustrative. Two researchers support five squads and spend about a third of their week scheduling merchant calls and chasing gift card payments. They add a merchant panel built from an opt-in question at the end of the support survey, a booking tool with built-in incentive payouts, and a rule that each merchant is contacted at most once a quarter. They keep a screener question that asks merchants to describe their payout schedule in their own words, which filters out people who do not run a business.

When to use it

Use it when research is spread across several teams, when recruiting or paperwork takes longer than the sessions, when legal or privacy staff start asking where recordings live, or when people keep commissioning studies that answer questions the company already answered. Growing and large companies get the most from it, and regulated sectors such as health and finance need the governance part early.

When not to use it

Skip a formal function when one researcher runs a few studies a quarter: a consent template, a retention rule and a shared folder are enough. Do not start with a repository tool when nobody runs research regularly, and do not let operations become a gate that slows down small, low-risk studies such as quick usability checks on public prototypes.

Common mistakes

  • Buying a tool first. Kate Towsey calls this knee-jerk operations: a recruiting or repository platform bought before anyone mapped the workflow it has to serve.
  • Launching a repository with no owner and dozens of tags. According to Nielsen Norman Group, only 9% of repositories are mature and thriving; ownerless ones drift into disuse.
  • One blanket consent form for all future research. Consent has to be specific and easy to withdraw, and NN/g advises against umbrella forms.
  • Keeping raw recordings forever because storage is cheap. GDPR's storage limitation principle means identifiable data goes once it is no longer needed.
  • Mixing research with sales. The ICC/ESOMAR Code requires researchers to separate promotional activity from research, so do not hand panel members to marketing.

FAQ

What does a research ops person do?

A ResearchOps specialist runs the logistics that sit around studies: recruiting, screening, scheduling and paying participants, maintaining consent templates and data rules, running the repository, managing research tools and vendors, and training non-researchers. According to User Interviews' 2025 report, 41% of ReOps teams are one person, so the role often covers all of these.

What is the difference between ResearchOps and DesignOps?

DesignOps supports the whole design function: hiring, workflows, design systems and tools. ResearchOps is the part focused on user research. Nielsen Norman Group describes ResearchOps as a specialized area of DesignOps, and the two often share a team, though large research groups usually have a separate ResearchOps lead.

Do you need consent under GDPR for user research?

You need a lawful basis, which is not always consent. The UK ICO says no basis is always better and that many organisations choose between consent and legitimate interests. Whatever basis you use, participants must be told what you collect, why and for how long. Health and other special category data need extra conditions. Check with your privacy lead.

What should a research repository contain?

NN/g lists research reports, individual insights saved as standalone entries, study materials such as plans and screeners, recordings and transcripts, and raw notes. Store identifiable recordings separately with a deletion date, keep insights de-identified, and start with a few broad tags rather than a detailed taxonomy.

How many companies have a ResearchOps role?

It varies by survey. According to Nielsen Norman Group's 2021 survey of 353 UX professionals, 46% of organizations had no dedicated ResearchOps person. According to User Interviews' 2025 report, 35% of respondents had at least one dedicated ReOps professional, and 76% of those worked at companies with over 1,000 employees.

Sources

  1. ResearchOps Community, home page and working definition
  2. ResearchOps Community, About: 2018 workshops and the eight pillars
  3. Rally UXR, Kate Towsey on Research That Scales
  4. Aaron Fulmer, From pain points to empowerment: A Research Ops evolution, Microsoft Research, 2019
  5. Nielsen Norman Group, Kate Kaplan, ResearchOps 101, 2020
  6. Nielsen Norman Group, Kate Kaplan and Maria Rosala, ResearchOps: Study Guide, 2022
  7. Nielsen Norman Group, Kara Pernice, The State of ResearchOps: Untapped Yet, 2022
  8. User Interviews, The State of User Research Report 2024
  9. User Interviews, The State of Research Operations 2025
  10. Nielsen Norman Group, Therese Fessenden, Recruiting and Screening Candidates for User Research, 2021
  11. Nielsen Norman Group, Kim Flaherty, Best Practices for Building and Maintaining Your Own Research-Participant Database, 2023
  12. GOV.UK Service Manual, Finding participants for user research
  13. Eleanor Singer et al., The Effect of Incentives on Response Rates in Interviewer-Mediated Surveys, Journal of Official Statistics 15(2), 1999
  14. David Ridge et al., 'Imposter participants' in online qualitative research, Health Expectations 26(3), 2023
  15. Pakhi Sharma et al., Navigating the challenges of imposter participants in online qualitative research, BMC Health Services Research 24, 2024
  16. Nielsen Norman Group, Therese Fessenden, Obtaining Consent for User Research, 2022
  17. Nielsen Norman Group, Samhita Tankala, Maintaining the Privacy and Security of Research Participants' Data, 2022
  18. GOV.UK Service Manual, Getting users' consent for research
  19. Information Commissioner's Office, What is valid consent?
  20. Information Commissioner's Office, A guide to lawful basis
  21. Regulation (EU) 2016/679 (GDPR), Article 5, principles relating to processing of personal data
  22. Regulation (EU) 2016/679 (GDPR), Article 7, conditions for consent
  23. Regulation (EU) 2016/679 (GDPR), Article 9, special categories of personal data
  24. European Data Protection Board, Guidelines 05/2020 on consent under Regulation 2016/679
  25. ICC/ESOMAR International Code on Market, Opinion and Social Research and Data Analytics, 2016
  26. Nielsen Norman Group, Maria Rosala, Research Repositories 101, 2024
  27. Nielsen Norman Group, Maria Rosala, Why Research Repositories Fail and How to Get Them Right, 2024

Last updated Oct 9, 2026

Ilia PushinFounder, PUSHERS & COO Fintech ServiceIlia builds operating systems for growing companies in fintech and healthcare. Since 2021 he has run cross-border payments at ARBI Exchange, a licensed currency exchange in Thailand, including KYC and AML and the move into new jurisdictions.About the authorLinkedIn
Related frameworks
More frameworks
Want Research Ops running inside your company?Request an operations audit