Hot work in a data centre is not like hot work anywhere else. When you isolate a smoke detector to carry out welding or grinding, you are simultaneously removing the early warning system for a fire in a building full of energised equipment, combustible cabling, and raised floor voids that can carry a fire invisibly from one zone to the next.
That combination — ignition risk, concealed fire pathways, and a suppressed detection system — is why hot work permits in data centres demand more rigour than almost any other work category. And it is why the consequences of getting the permit process wrong are so much harder to recover from.
What counts as hot work
Hot work is any activity that produces heat, sparks, flame, or the risk of ignition. In a data centre context that includes welding and cutting, grinding, soldering, brazing, use of heat guns, and any open-flame work associated with mechanical or structural modifications.
It also includes activities that are not immediately obvious — disc cutting through metal cable trays, drilling into concrete near energised busbar, or using a blowtorch to sweat pipework in a plant room adjacent to an active hall. The test is not the tool being used. It is whether the activity could produce an ignition source in an environment where combustible materials are present.
In a data centre, combustible materials are always present — cable insulation, cable management trays, floor tiles, acoustic panels, and in older facilities, legacy wiring with degraded insulation that may not be visible.
Why detection and suppression isolation is the highest-risk step
Most data centre fire suppression systems use clean agent or inert gas — FM-200, Novec 1230, or CO2 in older installations. These systems are designed to discharge automatically when detectors trigger. Before hot work begins, the detection zone covering the work area must be isolated to prevent a spurious discharge triggered by welding smoke or grinding sparks.
That isolation step is the point at which the facility becomes most vulnerable.
A suppressed detection zone means that a real fire developing during the work period will not trigger an automatic response. The fire watch — typically a requirement of the hot work permit — becomes the only real-time detection mechanism for the duration of the work. If the fire watch is inadequate, distracted, or absent, the window between ignition and intervention closes very quickly in an environment with the fuel load of a typical data centre.
The permit must therefore control not just the isolation of detection, but the conditions under which that isolation can exist: time limits, fire watch requirements, the precise boundaries of the suppressed zone, and the reinstatement process when the work is complete.
Where hot work permits fail in practice
The failure modes for hot work in data centres follow a consistent pattern across incident investigations:
Detection systems isolated but not reinstated at the end of the working day — because the permit was not formally closed out before the contractor left site, or because reinstatement was treated as a formality rather than a controlled step.
The suppressed zone was larger than necessary — because it was easier to isolate a full detection loop than to identify precisely which heads needed to be covered. A larger suppressed zone means a larger area with no automatic detection if something goes wrong.
The fire watch was not maintained continuously — because the person assigned to fire watch was also expected to assist with the job, or left the area briefly while the work was paused but the isolation remained in place.
Work scope crept beyond the area covered by the permit — because the job turned out to be more complex than planned and the contractor extended the work without stopping to amend or reissue the permit.
Each of these failures is individually manageable. In combination, in a live data centre, they create the conditions for a fire that takes hold before anyone knows it has started.
The regulatory framework
In the UK, hot work in a data centre sits under several overlapping regulatory requirements. The Regulatory Reform (Fire Safety) Order 2005 places a duty on the responsible person to manage fire risk, which includes controlling ignition sources introduced by maintenance and construction activity. Where contractors are carrying out hot work, the principal duty holder remains responsible for ensuring adequate controls are in place.
HSE guidance on permit to work systems identifies hot work as one of the primary categories where a formal permit is required — not because a permit eliminates the risk, but because it imposes the structured sequence of checks — authorisation, isolation, fire watch, reinstatement — that experience has shown to be necessary.
For data centre operators, this means the hot work permit cannot be treated as a contractor formality. It is a site-level control document, issued by a competent person with knowledge of the building's detection and suppression systems, and closed out only when reinstatement has been physically confirmed.
What a robust hot work permit must cover
A hot work permit for a UK data centre should, at minimum, address:
- Precise location of the work, referenced to a building management system or floor plan — not just "level 2 plant room"
- Identification of the detection zones affected and the suppression system serving those zones
- The authority responsible for isolating detection — this should be the facility's own competent person, not the contractor
- Time limits on the isolation, with a requirement to reinstate if work pauses for more than a defined period
- Fire watch requirements — who, where, and for how long after the hot work stops
- Combustible material clearance distances and confirmation that adjacent cable runs have been assessed
- Reinstatement sign-off, confirmed by the facility's authorised person before the permit is closed
If any of those elements are missing from your current hot work permit template, the permit is not providing the level of control the environment requires.
A practical self-assessment
If you want to test the robustness of your hot work controls quickly, these questions will tell you where the gaps are:
- Who on your team holds the authority to issue a hot work permit, and can they identify the detection zones affected by a job without consulting the contractor?
- Is there a maximum duration for detection isolation, and what happens if the job overruns?
- Can you demonstrate, from your permit records, that every hot work permit issued in the last twelve months was formally closed out with reinstatement confirmed?
- Does your permit system alert anyone if a detection isolation is still active at the end of a working day?
- Are your contractors required to use your permit system, or their own?
If any of those questions are difficult to answer, that is where the risk is sitting — and where an investigation will look if something goes wrong.
Hot work in a data centre requires a permit process that is proportionate to the environment. If you are reviewing your hot work controls or building a permit to work framework for a new facility, get in touch to see how Elisian supports permit issuers and facility managers in maintaining control of the highest-risk work categories.