Create and Publish a Trusted Research Environment
Step-by-step guide for TRE Admins to create, configure, and publish a new Trusted Research Environment on the DNAnexus Platform.
Apollo and Trusted Research Environments licenses are required to use Trusted Research Environments on the DNAnexus Platform. Contact DNAnexus Sales for more information.
Learn how to make your data discoverable using a Trusted Research Environment (TRE) on the DNAnexus Platform.
Before You Begin
Make sure you've done the preparatory work described in planning a TRE.
Confirm the following before you start creating your TRE:
Your File Inventory TSV and Data Collections JSON are uploaded to DNAnexus.
If your TRE includes a Tabular Data Inventory, your Apollo Dataset is ingested and accessible.
If your TRE includes a Data Showcase, your Apollo Dataset is in a separate project from your other inventory resources.
All inventory assets are in the same region as the TRE you are creating.
You know how many review steps your pipeline needs and who to assign as reviewers.
Step 1: Create the Research Environment
In the platform navigation menu, go to Orgs > Your Org.
Click the TRE tab.
Click + New Research Environment in the top right corner.
Complete the following fields in the New Research Environment modal:
TRE ID — A unique, lowercase, alphanumeric handle for the environment.
Name — The display name shown to researchers browsing Data Resources > Resource Center.
Description — A detailed description of the data offering.
Region — The cloud region where the data is hosted.
Customized Rate Card — Controls how compute costs are billed to researchers. Select Yes to have the platform create a dedicated billing org (wallet) for each approved data access request, with pricing inherited from the organization hosting the TRE. Leave as No to have researchers bill to their own org wallet. This setting cannot be changed after creation. For details and prerequisites, see planning your billing configuration.
Click Create Research Environment.
The TRE ID is permanent and cannot be changed after the TRE is created. In the TRE UI, the Region and Customized Rate Card fields are also locked after creation, even while the TRE is in the draft lifecycle state. The Name and Description can be updated at any time.
Step 2: Configure Membership
Open the newly created TRE and navigate to the Membership section. Add TRE Admins and the initial Authorized Users who you want to be able to discover and access the environment. If your TRE includes a Data Showcase, you must be an Admin in the Data Showcase project to add Authorized Users.
For more details, see how to manage TRE membership. Membership can be updated at any time regardless of lifecycle state.
Step 3: Configure the Resource Inventory
The Resource Inventory links your prepared inventory assets to the TRE. Contact DNAnexus Professional Services for assistance preparing these files before continuing.
Navigate to the Resource Inventory section.
Provide a semantic Version string for this inventory release, for example
1.0.0.Enter the project ID and object ID for each required inventory asset:
File Inventory — The file ID of your File Inventory TSV.
Data Collections — The file ID of your Data Collections JSON file.
If your TRE includes tabular phenotypic or clinical data, enable Tabular Data Inventory and enter the record ID of your tabular Apollo Dataset.
If your TRE includes pre-request data browsing or cohort selection, enable Data Showcase and enter the record ID of your showcase Apollo Dataset. This dataset must be in a separate project from your File Inventory and Tabular Data Inventory.
If your TRE includes assay data, add one entry per assay with the entity name, project ID, dataset record ID, and assay database name. Assays can only be configured when Tabular Data Inventory is enabled. Contact DNAnexus Professional Services for guidance on configuring assays.
Resource Inventory settings can only be configured or updated when the TRE is in the Draft or Maintenance state. You cannot modify the inventory while the TRE is Active.
Step 4: Configure Data Access Policies
Navigate to the Features & Policies section.
Click Configure Policies.
For each policy, select one of three options:
Enforce on — The restriction is enforced on all projects in this TRE, regardless of individual project settings.
Enforce off — The restriction is explicitly disabled for all projects in this TRE.
Defer to project settings — Individual project owners control this setting.
Click Save.
Step 5: Configure Data Showcase and Selection
Navigate to the Data Showcase and Selection section. If your governance policy requires all researchers to access data for all participants without cohort filtering, enable Enforce Full Set Selection. When enabled, researchers' data access requests always include all participants in the dataset.
If you do not configure a Data Showcase, the TRE must use Enforce Full Set Selection. Researchers cannot select cohorts, but they can still select data collections and submit access requests.
This setting can only be configured in Draft state and cannot be changed or disabled after the TRE is published.
Step 6: Configure the Review Workflow
Navigate to the Review Settings section and add the review steps you planned. Assign at least one reviewer to each step.
For details, see how to manage review steps and reviewers. The TRE must have at least one review step with at least one reviewer assigned before you can publish it.
Step 7: Publish the Research Environment
Once your membership, inventory, policies, and review pipeline are configured, you can publish the TRE to make it visible to Authorized Users. You can also publish with no Authorized Users configured and add them later.
When published, the TRE enters the Active state. Authorized Users can immediately discover the environment in Data Resources > Resource Center, explore the Data Showcase (if one exists), and submit access requests.
Click Administrative Actions (gear icon) at the top right.
Select Publish Environment.
Review the confirmation checklist:
Your review steps are finalized. After publishing, you cannot add, remove, or reorder steps, but you can update step names and descriptions.
Your Resource Inventory is correctly linked with valid file and record IDs.
Your data access policies reflect the appropriate restrictions for your data.
Click Confirm and Publish.
To update the resource inventory after publishing, or to deactivate or delete the TRE, see Manage TRE Lifecycle.
Last updated
Was this helpful?