Zenith · Safety

“No hazards recorded” is not the same as safe.

When a machine's hazard panel is empty, Zenith says so plainly: silence rather than a reassuring tick — nobody has assessed it. That refusal to show a comfortable green check is the instinct behind everything else here: a permit that dies at an instant rather than at midnight, an issuer who cannot be the holder, and an isolation that counts only once somebody has walked to the panel.

Bilingual EN / FR · Multi-site · WCAG 2.2 AA
Instants, not dates
A permit issued at 08:00 for eight hours is dead at 16:00, not at midnight
Issuer ≠ holder
A refusal, not a warning — a permit somebody wrote for themselves is a signature on a piece of paper
7 named refusals
Every reason a permit cannot be issued, each naming the person, the ticket or the clash
EN · FR
Every label, hint, empty state and refusal, in both languages
The model

Six things the safety layer holds

A hazard is a standing fact about a machine or a place — this panel is live, this room is confined. A permit is a decision made about one job in front of one of those facts, this afternoon, by a named person who is not the person doing the work. Reading them apart is how somebody ends up looking at a register of hazards with no idea whether anything is authorized against them right now.

01

Hazards

A library of what can hurt somebody — six categories, four severities ordered worst-first, and the harm written in the words somebody would use out loud.

02

Where they are

Attached to a machine, a place or a model. Recorded on a model once — every chiller of that model carries a refrigerant charge — rather than typed onto every unit.

03

PPE

Derived from the hazards actually present, as one union: a person puts on one set of equipment before walking in, and two hazards each wanting a hard hat do not want two hard hats.

04

Permit types

The template: how long one may run, whether it demands isolation, whether it excludes others, and which tickets the issuer and the holder each need — two lists, because they are two questions.

05

Permits

The instance: a window in time on one subject, held by one person and issued by another, with a hard end it cannot be created without.

06

Isolation

A fact about this job, not a property of the type. Confirmed at the equipment by somebody who walked there — or the permit authorizes nothing.

A window in time

A permit that “expires today” covers the night shift

Every other expiry in a maintenance system is a date: a certification lapses on a day, a calibration runs out on a day. A permit does not. Hot work issued at eight for eight hours is dead at four — so permits carry instants, and every question about them is asked at an instant. It is the one place where the extra precision is the safety property rather than pedantry.

  • Dead at the instant, not at the end of the day — in force at 15:59, not in force at 16:00, and the tests say so in exactly those terms.
  • A permit is never open-ended — leave the end blank and it takes the type's maximum, because a permit with no end is the thing the whole idea exists to prevent.
  • The maximum is a cap, not a suggestion — one shift for hot work. A permit good for a week is a sign on a door: the value of the thing is that somebody reassesses the job.
  • Expired-but-open is its own list — an expired permit still on the board is how a crew comes back from lunch and carries on under a piece of paper that stopped meaning anything at four o'clock.
Two people, not one

A second pair of eyes, or a signature on a piece of paper

The person who issues a confined-space permit is not the person who climbs into the vessel. That separation is the entire mechanism — so it is a refusal rather than a warning, and the two roles carry separate ticket lists, because a type may reasonably demand more of the person signing than of the person entering.

  • Same person in both roles: refused — not flagged, not warned, not permitted with a note.
  • Each side is checked against your workforce records — asked rather than restated, so a lapsed ticket is lapsed everywhere at once.
  • Judged at the instant it was issued — a permit written in February under a ticket valid in February stays explicable in August, instead of turning retroactively into a violation.
  • The refusal names the ticket — “issuer not certified — FIRSTAID” is a person and a certificate, which is a fixable thing.
  • Exclusivity is by overlap, not by simultaneity — two hot work permits whose windows merely touch still mean two crews with a flame on the same vessel.
Isolation

Somebody has to walk to the panel

A type saying isolation is required and a permit recording that isolation happened are two different facts. Confirming it is a separate act from issuing it, deliberately — folding it into the paperwork would mean the paperwork could claim it happened.

  • Until it is confirmed, the permit is not in force — however current its window, however properly signed.
  • The points are recorded in words — “supply fan breaker locked off”, “damper actuator air bled” — beside the permit they belong to.
  • The panel says what is waiting — “issued and waiting on isolation”, because “no permit is in force” is true and hides the most relevant thing on the page.
  • A cancellation says why — the reason is appended to the permit rather than lost with it.
Hazards

Asbestos is in a building, not in one room of it

A hazard recorded against a facility applies to everything inside it. Recording it once per room would mean that the day somebody adds a room, the asbestos is not in it — so hazards roll down the location tree, and an inherited one always says where it came from.

The tab before the job

Worst first, because that is what somebody is looking for

Somebody reading this before walking to a job wants the thing that can kill them at the top, not the alphabetically first thing. So the list sorts by severity, the harm is a sentence rather than a category, and an inherited hazard names the building it came from.

  • An inherited hazard names its source — “inherited from Science & Engineering Building”. Asbestos with no explanation on a room whose record never mentions it reads like a data error; named, it reads like the truth.
  • Four severities, deliberately — a five-point scale invites debate about the middle three, and the debate is never about the ones that matter.
  • The harm is written to be read — “permanent hearing loss above 85 dBA over a shift”, because a hazard register written in categories is one nobody opens before a job.
  • An empty panel admits it is empty — “silence rather than a reassuring tick: nobody has assessed it”, which is the one sentence a safety tab must never replace with a green check.
  • The same tab on three kinds of record — a machine, a place and a model each gain it, without any of those modules knowing this one exists.
Where the line is

What this is, and what it is not

This is the safety layer inside a maintenance system — the part that makes sure a job knows what can hurt somebody and whether it is authorized. It is not a safety management system, and that difference is worth saying on a web page rather than discovering in a procurement meeting.

Said plainly

The parts we do not have, named

Safety is the module where over-claiming does the most damage, because the person who finds out is the one it was meant to protect. So the absences get the same treatment as the features.

  • No incident or near-miss reporting — none, and we will not imply otherwise. It is a different product category, and a maintenance system that pretends to it gets one incident logged and never a second.
  • No risk matrix — one severity on the hazard, four levels, described as “how bad it is if the controls fail”. There is no likelihood axis and no score, so if your process needs a scored assessment per job, this is not that.
  • Not a full lockout/tagout programme — isolation is a rule, a confirmed fact and a list of points in words. There is no padlock register, no per-point lock-tag-verify state and no group lockbox.
  • Certifications live with your people records — safety asks whether a ticket is valid on a date rather than keeping a second copy to drift out of step with the first.
And the rest of it

Everything around the permit

Your word for a permit

A refinery says Work Permit, a hospital says Authorization to Work, a utility says Clearance. The tab, the heading and the type all follow your vocabulary — including the word people click.

PPE standards are never renamed

“Gloves” is not a specification: class 0 insulating gloves and general-purpose gloves are both gloves, and one of them is what stops an electrician dying. So the standard rides on the item — CSA Z94.1 stays CSA Z94.1.

One moment, every row

The board reads as of a single instant, stamped at the top — so two rows can never disagree about what time it is, and “in force” means in force right then.

Filter by in force, not by status

Because Active and authorizing are different facts, and the filter that matters is the one that tells them apart.

It refuses to start broken

A hazard pointing at a PPE code or permit type that does not exist would be a requirement nobody could satisfy — discovered by whoever it was meant to protect. So the register refuses to load rather than open with a hole in it.

Exclusive where it matters

Two crews can work at height on the same building without endangering each other; two cannot have a flame on the same vessel. Exclusivity is set per type rather than imposed on all of them.

Four figures on one page

In force, expired-and-still-open, the hazard library, and how many hazards are attached to something — because a hazard nobody has attached to anything is a definition, and a definition hurts nobody.

Who holds it, who signed it

Both are on the permit, and either can be searched — “what is this person holding, and what have they signed for?” is a question with one answer.

Two languages, all the way down

Every label, hint, empty state and refusal exists in English and French — including the sentence that says nobody has assessed this machine.

Enterprise foundations

Refusals, not warnings

A warning is something a busy person clicks past. Everywhere the safety rules matter, they are refusals — and everywhere a list could drift out of step with another, it is derived instead of typed twice.

Refusals, not warnings

Issuer-is-holder, an uncertified signer, a permit longer than its type allows, a clash on the same equipment — each is a refusal that names its own reason.

Derived, never hand-kept

Hazards are the one list kept by hand; PPE, permits and certifications derive from them — because four hand-kept lists are four lists that drift apart, with the safety one drifting silently.

Bilingual by birth

Full en-CA / fr-CA parity on every screen, hint, empty state and refusal — plurals handled properly, not by concatenation.

Accessible to everyone

WCAG 2.2 AA as a build rule: real table semantics, states announced in words, and focus that moves to the field an error refers to.

Built on Instants, not dates Issuer ≠ holder Isolation confirmed at the equipment WCAG 2.2 AA
Questions people actually ask

Before you book the demo

Can we report incidents and near misses?
No. There is no incident register, no near-miss form, no injury log, no investigation and no corrective-action tracking — none of it, and none of it is hidden behind a module you would buy later. Incident management is a different product category, and a maintenance system that pretends to it gets one incident logged and never a second. Keep the system you have; we will make the hazard and permit record line up with it.
What can we actually do on screen today?
Read, thoroughly: the permit board with its in-force column, its isolation state and its expired-but-still-open alert; every machine, place and model's hazards with the PPE, permits and tickets they demand; and the four figures on the safety page. The issuing screens are the next piece of work. The rules behind them are built and tested — seven named refusals — but a person cannot yet issue, close or cancel a permit from a screen, and we would rather write that here than demo a button that is not there.
Is there a JSA, or a risk matrix?
No. There is one severity on a hazard — Critical, High, Moderate, Low — described as “how bad it is if the controls fail”, plus one free-text line for the engineering or procedural controls that come before PPE. There is no likelihood axis, no score and no residual-risk calculation. The four levels are deliberately few: a five-point scale invites debate about the middle three, and that debate is never about the ones that matter.
Is this a full lockout/tagout programme?
No, and the distinction is worth drawing precisely. What exists is real: a permit type can require isolation, a permit records whether it was confirmed, the points are written down in words, and an unconfirmed isolation means the permit authorizes nothing. What does not exist: a padlock register, per-point lock-tag-verify states, a group lockbox, per-person locks, or a de-isolation step. It is meaningfully more than a checkbox and meaningfully less than a LOTO programme.
Does a missing permit stop somebody starting work?
No, and this is the honest shape of it. The safety engine refuses exactly one action: issuing a permit, for seven named reasons. It does not block starting a job, logging hours against it, or completing it. What it does instead is put what can hurt you, what to put on, what must be signed and what is already signed on the record before somebody walks up to the machine — which is where that information changes a decision.
What does block a work order from closing?
Four things, and they are work-order rules rather than safety rules: nobody has put hours on it; the equipment is still recorded as off; there is no failure coding on a job that requires it; and the person who did the work cannot be the person who checks it. That last one is the same instinct as issuer-is-not-holder — a second pair of eyes, enforced rather than encouraged.
Where do certifications live?
With your workforce records, which own what a certification is and when it lapses. Safety asks rather than keeping a copy — so a ticket that expires expires everywhere at once, and the answer a permit gets is the same answer a job plan gets. Validity is judged at the moment the permit was issued, not at today, so a permit written under a then-valid ticket stays explicable afterwards.
Do hazards on a building apply to the equipment inside it?
Hazards roll down the location tree — a hazard on a building is on every room within it, and the room's panel says which building it came from. An asset does not automatically inherit from the room it sits in: record it on the asset, or on its model where every unit carries it. That is worth knowing when you set the register up, and it is the kind of detail we would rather you heard now than found later.
What happens when a machine has nothing recorded?
It says so: “No hazards are recorded here. Silence rather than a reassuring tick: nobody has assessed it.” An empty safety tab that looks clean is worse than one that admits it is empty — because a green check on an unassessed machine is a claim nobody made and everybody reads.
Can we use our own words and our own hazards?
The vocabulary, yes — permit, hazard, clearance, authorization to work — and it follows through headings, tabs and type names. The registers ship with a starting library: seven hazards, eleven PPE items with their standards, and five permit types with real caps and ticket requirements. Editing that library is not yet a screen; today it is set up with you rather than by you.
Is there an audit trail?
Not yet, and on a safety page that deserves a straight answer rather than a soft one. The registers are session state until the persistence layer lands, which means there is no durable history of who issued what and when. For a permit system that is the thing that has to arrive before it is relied on in a regulated environment, and it belongs to the same server phase as sign-in and identity.
How would we start?
With one machine and one permit type. Tell us what can hurt somebody on it, who is allowed to sign, what ticket each side has to hold, how long the permit may run and whether it needs isolation — and we will model it in front of you, then try to issue one badly and watch it refuse for the right reason.
See it on equipment you already work on

Bring the permit nobody closed.

Every site has one — the piece of paper still on the board from a job that finished on Tuesday. Show us the equipment, the permit type and who is allowed to sign it, and we'll model it: the window, the tickets each side needs, and the isolation that has to be confirmed before it authorizes anything at all.

Zenith · Safety Part of the Zenith maintenance & asset operations platform