The problem

Many Permit to Work processes still depend on paper forms, spreadsheets or a mix of both. The form may be well designed, but its use varies from one supervisor to the next. Fields are skipped, hazards are described in free text, the same work is assessed differently on different days, and the approval history is spread across signatures, emails and phone calls.

Replacing paper with an app does not fix this by itself. A digital form that accepts anything is still an inconsistent form, only faster. The useful question is not "how do we digitise the permit?" but "what should the system control so that each permit is complete, reviewed by the right people and traceable afterwards?"

Why it matters

A permit is a decision record. It states what work will be done, where, by whom, which hazards were identified, which precautions were agreed and who accepted the remaining risk. If any of these elements is missing or unclear, the permit loses its value as a control and as evidence.

Paper processes make some failures hard to see: which permits are currently active at a site, whether a performer's certificate had expired, whether a step was approved by someone with the authority to approve it, or what changed between submission and issue. These are exactly the questions asked after something goes wrong.

A practical approach

Before choosing or configuring a system, list the controls your permit process is supposed to provide. For most organisations they fall into a small number of groups:

  • Required information. Work type, location, time window, description, people involved. The system should not let a permit move forward without them.

  • Hazards and precautions. Hazards should come from a maintained library linked to work types, so that common hazards are not forgotten and precautions are described consistently. Free text should add to the library, not replace it.

  • Risk visibility. Approvers need to see the assessed risk for each hazard, not only an overall "yes". Rating consequences separately for people, assets, the environment and reputation shows where the risk actually sits.

  • Approval authority. Each step should be actionable only by the groups authorised for it, with clear rules on who can refuse, cancel or act on their own request.

  • Competence visibility. Approvers should be able to see the certificates and expiry dates of the people who will perform the work.

  • Simultaneous work. People should be able to see when several permits are active at the same site, so that interactions can be considered.

  • History. Every action should be time-stamped and attributable, from creation to closure.

  • Field access. A printed permit at the work location should lead quickly to the current digital record.

What a good system should provide

A good digital Permit to Work system enforces structure without removing judgement. It guides the requester through the form, loads relevant hazards and precautions, prevents incomplete submissions and routes the permit through a workflow that reflects real authority levels in the organisation.

It should make information visible rather than claim to make decisions. Showing an expired certificate to an approver is useful. Showing which permits are active at the same site is useful. Neither replaces the approver's responsibility to decide whether the work can proceed safely.

It should also keep an honest history. A record that shows who submitted, reviewed, approved, refused or closed each permit, and when, is more valuable than any dashboard figure.

If the system includes AI, its role should be clearly limited. An AI review can act as a second opinion, pointing out things worth checking. It should never approve a permit or declare that work is safe.

How Sospita SafeGuard addresses it

Sospita SafeGuard is a Permit to Work and observation application available on the web, iOS and Android. Its permit process reflects the controls described above:

  • A four-step guided permit form with validation and workflow-specific fields, so permits reach submission with the required information completed.

  • A hazard and precaution library managed by administrators and linked to work types. Each permit requires at least one hazard, followed by precautions and recovery elements.

  • Residual risk rated on a 5×5 likelihood and severity matrix, with separate severities for People, Asset, Environment and Reputation. Residual ratings cannot be set below the defaults defined in the library. The reasoning behind that floor is covered in Why Risk Ratings Shouldn't Be Lowered to Speed Up Approval.

  • A visual workflow editor in which each step is assigned to user groups, with options for whether a step can be refused, cancelled or acted on by its requester.

  • Performer certificates with issue and expiry dates, viewable from the permit, so approvers can see expired or missing certificates.

  • A SIMOPS view that groups active permits by site when two or more are open, giving visibility of simultaneous work at the same location.

  • A time-stamped action timeline for each permit, comments and attachments at any stage, and PDF download.

  • QR scanning on mobile to open the digital record of a printed permit.

  • An AI review of permit content that offers advisory recommendations before approval.

Limitations and human responsibility

Some limits are deliberate and worth stating clearly.

The SIMOPS view shows that several permits are active at a site. It does not check time overlaps or detect conflicts between hazards automatically. Deciding whether simultaneous work can proceed remains a human assessment.

Certificate information is visible to approvers, but an expired certificate does not block a permit automatically. The approver remains responsible for the competence check.

The AI review is advisory. It does not approve permits, it does not decide whether work is safe, and it should not replace professional judgement. Approval stays with the authorised workflow user groups.

Finally, no software makes work safe on its own. A digital permit system supports a good process; it cannot replace site supervision, toolbox talks, isolation practice or the people who know the work.