Most contractor management systems are built around onboarding: induction records, site passes, insurance checks, generic safety briefings. That work matters, but it answers a narrower question than the one that actually determines whether an incident happens. The question that matters on process-safety-critical assets is not "has this contractor been inducted?" It is "is this specific contractor competent to isolate or work on this specific piece of equipment, today, under these conditions?"

That distinction is where a lot of contractor management content, and a lot of contractor management software, stops short. Generic onboarding tells you a contractor is allowed on site. It does not tell you they are qualified to break containment on a high-pressure line, isolate a switchboard feeding critical load, or work inside a zone where a joint failure could have safety or environmental consequences. Closing that gap is a permit-to-work problem, not an induction problem.

Why induction records aren't enough

A valid site pass and a completed induction confirm that a contractor understands general site rules. They say nothing about whether that individual holds the specific competency, training, or authorisation needed for the task in front of them. On critical equipment, that's the check that actually prevents harm.

Think about the assets typically classified as process-safety-critical: pressure systems, electrical infrastructure feeding essential services, structural joints, isolation valves on hydrocarbon or chemical lines. Work on these assets carries a different risk profile to routine maintenance, and the competency bar for whoever picks up the tools should reflect that. A contractor with an expired certification, or one who has never been assessed against a particular isolation procedure, is a different risk category to one who has. Paper-based systems and generic contractor databases rarely make that distinction visible at the point the permit is raised, which is exactly when it needs to be caught.

What digital permit systems can enforce that paper can't

A digital permit-to-work system can tie the permit itself to the competency record, not just to the contractor's name. Before a permit for isolation or intrusive work is issued, the system checks that the named individual holds current, verified competency for that task and that equipment class. If the record has lapsed, or was never issued, the permit simply cannot be authorised. That's a structural control, not a reminder someone has to remember to act on.

This matters most on electrical work, where the consequences of an unqualified person isolating the wrong circuit are immediate and severe. Our guide to electrical permit to work sets out how a permit system should verify authorisation before isolation work begins, rather than trusting that the right checks happened somewhere upstream. The same logic extends to any asset carrying a process-safety classification, whether that's a data centre's critical power infrastructure, as covered in critical equipment integrity for data centres, or offshore plant subject to formal control-of-work regimes.

Assurance, not just compliance

The regulatory direction of travel, particularly offshore, has been toward stronger evidence that competency verification actually happened, not just that a policy exists requiring it. The expectations set out in guidance on OIM security and control of work offshore reflect that shift: operators are expected to demonstrate assurance, with an audit trail, not simply assert it after the fact.

A digital permit record that links every authorisation to a verified, current competency check gives you exactly that trail. When an auditor or investigator asks who was authorised to isolate a specific asset on a specific date, and on what basis, the answer should take seconds to produce, not an afternoon of cross-referencing spreadsheets against training folders.

Building this into your contractor management approach

If your current contractor management process treats induction and permit authorisation as separate systems, it's worth asking where the join happens, and whether that join is enforced automatically or relies on someone remembering to check. Sites with clearly classified critical equipment are the ones with the most to gain from closing that gap, because the cost of missing it is highest there. Anyone reviewing their permit-to-work approach should start by mapping which assets on site carry a process-safety classification, then confirming that the permit system genuinely blocks authorisation when contractor competency for that asset class isn't current.

If you'd like to discuss how a digital permit-to-work system could enforce competency checks on your critical equipment before work is authorised, get in touch with Elisian.

← Back to Blog