The All of Us Research Program, run by the National Institutes of Health (NIH), gives researchers cloud-based access to health record, survey, physical measurement, wearable, and genomic data from more than a million participants through an environment called the Researcher Workbench. What makes All of Us different from an open dataset isn’t the volume of data — it’s the access model wrapped around it: a two-tier structure, backed by an institutional agreement and individual researcher requirements, that determines exactly what any given researcher can see and what they’re permitted to do with it. For a research administrator negotiating institutional participation, or a principal investigator trying to work out why a collaborator can query genomic fields they can’t, the access model — not the dataset’s contents — is the actual point of friction.
This guide covers how that tiered-access model works mechanically: the difference between the Registered and Controlled Tiers, what the Data Use and Registration Agreement (DURA) actually obligates an institution and an individual researcher to do, and — directly relevant to anyone using the platform in 2026 — the Researcher Workbench 2.0 migration that decommissioned the legacy analysis environment this year.
What “tiered access” means inside All of Us
All of Us does not publish participant-level data openly, and it does not let approved researchers download raw extracts. Analysis happens inside the Researcher Workbench itself — a cloud workspace built on Jupyter notebooks and SQL/R/Python tooling — and no participant-level record leaves that environment. Within it, access is tiered: which fields and record types a researcher’s workspace can query depends on which tier that workspace is authorized for. This is a data governance control, distinct from de-identification alone (see CASRAI’s De-identification entry) — tiering restricts who can query which fields at all, on top of whatever privacy transformation has already been applied to the underlying data.
Registered Tier vs. Controlled Tier
All of Us organizes its participant data into two access tiers, both of which require an approved researcher account — there is no fully public, ungated tier for individual-level records.
Registered Tier
The Registered Tier is the baseline for approved researchers. It includes individual-level data from electronic health records, participant survey responses, physical measurements, and wearable data (e.g., Fitbit), transformed to reduce re-identification risk — for example, certain dates and demographic fields are generalized or shifted rather than shown exactly as recorded.
Controlled Tier
The Controlled Tier adds materially more sensitive data on top of everything in the Registered Tier: whole-genome sequencing and genotyping array data, demographic fields that are suppressed in the Registered Tier because they carry higher re-identification risk in combination with other fields, and event dates that are not generalized or shifted. Because genomic and unshifted-date data raise re-identification risk substantially, Controlled Tier access carries additional program-level scrutiny beyond standard registration, and researchers should expect closer review of workspace use and publication reporting than under the Registered Tier alone.
Getting access: the Data Use and Registration Agreement (DURA)
Access is gated in two layers, and a research administrator typically owns the first one:
- Institutional layer. A researcher’s institution must sign a Data Use and Registration Agreement (DURA) directly with the All of Us Research Program before any of its researchers can be authorized. Per All of Us program guidance, once the DURA is executed the institution’s access is typically activated within a short window (on the order of a couple of business days) — but the negotiation and signature step itself is an institutional research-administration function, similar in kind to negotiating a standalone Data Sharing Agreement (DSA) for a single study, except the DURA covers the institution’s entire relationship with the program rather than one dataset.
- Individual researcher layer. Once their institution is covered by an active DURA, an individual researcher must separately register with All of Us, verify their identity, complete Responsible Conduct of Research (RCR) training (or an equivalent the program accepts), and agree to a program-specific code of conduct governing responsible data use before their account is activated on the Workbench.
Neither layer alone is sufficient: an individual at an institution without an executed DURA cannot register into an active workspace, and an executed institutional DURA does not itself grant any individual researcher access until they complete their own registration steps. This two-layer structure is functionally similar to how many NIH-designated controlled-access repositories operate — compare CASRAI’s entry on dbGaP (Database of Genotypes and Phenotypes), another NIH-governed controlled-access genomic resource with its own separate data access committee review.
Researcher Workbench 2.0: the 2026 migration
Research administrators supporting All of Us users should be aware of a platform transition that played out through 2026. According to All of Us program support documentation, a new version of the analysis environment — Researcher Workbench 2.0 — began a beta rollout to registered users in January 2026, with features including JupyterLab-based notebooks, a redesigned Data Explorer, and Git repository integration. The program set a migration deadline of June 30, 2026 for existing workspaces to move from the legacy Workbench to the new environment; per that same documentation, the legacy Workbench was decommissioned after that date, and workspaces that were not migrated by the deadline were archived rather than left active for analysis. Archived-workspace retrieval was expected to become available later in July 2026.
The practical implication for anyone administering or relying on an All of Us-funded project: confirm any workspace tied to your institution’s grants or IRB protocols was actually migrated before the deadline, rather than assuming it carried over automatically, and if a workspace was archived, budget time for the retrieval process rather than assuming immediate access to prior analyses. Because this transition is recent, verify current status directly against All of Us’s own support documentation (support.researchallofus.org) before making representations to a funder, IRB, or collaborator about a specific workspace’s state.
What research administrators and data stewards should track
- DURA scope and renewal. Confirm which institutional office owns the signed DURA, its effective dates, and whether new PIs at your institution are correctly routed through it rather than attempting to register independently.
- Tier-appropriate use. Controlled Tier access should map to an actual analytic need for genomic or unshifted-date data, not be requested by default — this is both a program expectation and generally sound practice under the minimum-necessary principle common to human-subjects data governance.
- Publication and results reporting. All of Us requires researchers to report publications and, in some cases, submit results back to the program; confirm your researchers know this obligation exists before they publish, since it is a condition of continued access rather than an optional courtesy.
- IRB and consent alignment. Confirm your institution’s IRB determination for secondary use of All of Us data (exempt, expedited, or full review, depending on your institution’s policy) is documented alongside the DURA, not treated as automatically satisfied by the participant-level consent All of Us itself already obtained from participants.
- Workbench 2.0 migration status. As above — verify active workspaces migrated before the June 30, 2026 deadline and don’t assume continuity.
How this fits with other controlled-access data models
All of Us’s tiered structure sits alongside a family of related controlled-access mechanisms research administrators encounter elsewhere: NIH’s dbGaP uses a data access committee review model for genomic data (see the dbGaP entry); biobanks commonly layer broad, tiered, or dynamic consent models that determine what a specimen can later be used for (see Biobank Specimen Consent Models); and clinical trial data-sharing platforms like Vivli run their own independent data-request and access-review process (see Vivli: How the Data Request and Access-Review Process Works). For the general mechanics of managing individual participant-level data once it’s in hand, see Managing Participant-Level Research Data, and for the underlying agreement type behind most of these programs, see Data Sharing Agreement (DSA) and the related Data Sharing Policy guide.
Frequently asked questions
Is the All of Us Researcher Workbench free to use?
There is no fee to register as an individual researcher, but a researcher can only register once their institution has an executed Data Use and Registration Agreement (DURA) with the program.
Can I download All of Us participant-level data to my own institutional servers?
No. Analysis takes place inside the cloud-based Researcher Workbench itself; participant-level data is not released as a downloadable extract under either tier.
Who needs to sign the Data Use and Registration Agreement — me or my institution?
The institution signs the DURA. Individual researchers then register separately under an institution that already has an active DURA; an institutional signature does not by itself grant any one researcher access.
What happened to workspaces that weren’t migrated to Researcher Workbench 2.0 by the deadline?
Per All of Us program support documentation, workspaces not migrated by the June 30, 2026 deadline were archived when the legacy Workbench was decommissioned, with a separate retrieval process rather than continued active access.
Does Registered Tier access include genomic data?
No. Whole-genome sequencing and genotyping array data are part of the Controlled Tier only, along with certain demographic fields and unshifted dates that the Registered Tier suppresses or generalizes.
Is Controlled Tier access harder to get than Registered Tier access?
Both tiers require the same underlying registration steps (institutional DURA, identity verification, RCR training, code of conduct), but because Controlled Tier data carries materially higher re-identification risk, expect closer program-level scrutiny of use and publication reporting.







