Working alone in an industrial environment is not inherently prohibited under UK law — but it carries obligations that many energy sector operators are not fully meeting. When something goes wrong with a lone worker, the question is never whether a policy existed. It is whether the system around that worker actually kept them safe.
In oil and gas, power generation, and process industries, lone working happens constantly — a technician carrying out an inspection in a remote part of the asset, a maintenance operative completing a task between shifts, a contractor working in a plant area while the main crew is elsewhere. These are not exceptional situations. They are part of normal operations. And they require a level of structured oversight that a general lone worker policy, on its own, does not provide.
What the law requires
The Health and Safety at Work Act 1974 and the Management of Health and Safety at Work Regulations 1999 place a duty on employers to assess the risks of lone working and put adequate controls in place. The HSE is explicit that some work should never be carried out alone — tasks where the risk of injury is high and where incapacitation would prevent the worker from summoning help.
In the energy sector, that category is broad. Work in confined spaces, work on or near energised electrical systems, work at height in remote locations, and work involving hazardous substances all carry risks that are significantly elevated when no second person is present. For any of these activities, the risk assessment must address not just the task itself but the specific additional risks created by the absence of another worker.
The question operators must answer is not only "have we assessed the risk of lone working?" but "what controls are in place that would actually protect this person if something went wrong?"
Where lone worker controls typically fall short
The most common approach to lone worker safety in the energy sector is a combination of a written policy, a manual check-in procedure, and a personal safety device. Each of these has value. None of them is sufficient on its own.
A written policy defines what lone working is and when it is permitted. It does not ensure that the person about to work alone has been assessed against those criteria for the specific task they are doing today.
A manual check-in procedure — calling the control room at defined intervals — provides a welfare check. It does not tell the control room what the worker is doing, where exactly they are, what hazards they are working near, or what the rescue plan is if they fail to check in.
A personal safety device — a panic button, a man-down alarm, a GPS tracker — provides a location signal and an alert mechanism. It does not ensure that anyone receiving that alert knows what the worker was doing, where the nearest access point is, or what emergency procedures apply to that location.
The gap in all three approaches is the same: the lone worker is tracked as a presence, not as a worker carrying out a specific task under specific conditions. When something goes wrong, the response is reactive rather than informed.
The permit to work connection
In a well-designed control of work system, lone working is not a separate safety category — it is a dimension of every permit to work that involves a single operative. The permit defines the task, the location, the hazards, the controls, and the boundaries of the work. It also defines the welfare monitoring requirements for that specific job.
A lone worker carrying out a task under a permit to work should have their welfare check-in requirements determined by the risk of the specific task — not by a generic policy that applies the same interval to an office inspection and a confined space entry. A five-minute check-in may be appropriate for entry into a confined space. It is unnecessary and operationally disruptive for a low-risk inspection task in an accessible area.
Connecting lone worker monitoring to the permit to work system means the control room knows — for every lone worker on the asset — what they are doing, where they are, what hazards the permit has identified, and what welfare monitoring has been agreed. If a check-in is missed, the control room has the information they need to mount an informed response, not a search.
Handover and lone worker visibility
Shift handover is the moment at which lone worker risk is most often invisible. A worker who began a task under a permit during the previous shift may still be on site — or may have left without formally closing the permit. An incoming supervisor who does not have a clear, current view of all active permits may not know that a lone worker is still in the field.
This is not a theoretical gap. In incident investigations involving lone workers, the failure of handover to capture lone worker status is a recurring finding. The incoming team assumed the field was clear. It was not.
A permit to work system that provides real-time visibility of all active permits — including who holds each permit, where they are working, and when they last checked in — eliminates this gap at handover. The incoming supervisor can see, immediately, whether any lone workers are still active on the asset and what their status is.
A practical self-assessment
These questions will give you an honest picture of how well your current arrangements protect lone workers:
- For a lone worker currently on the asset, can the control room tell you — without making a phone call — what task they are carrying out, what hazards are present, and when they last checked in?
- Are welfare check-in intervals determined by the risk of the specific task, or by a blanket policy?
- Does your shift handover process explicitly capture the status of any lone workers still active on the asset?
- If a lone worker failed to check in right now, how long would it take to establish their last known location and what they were doing?
- Are permits involving lone workers identifiable as such in your system, or does the control room have to know from memory which jobs involve single operatives?
If any of those questions are difficult to answer confidently, the system is not providing the level of oversight the task requires — or that a regulator would expect to find in place.
How Elisian supports lone worker safety
Elisian's platform connects lone worker oversight directly to the permit to work and operational assurance system. Permits involving lone workers are flagged at the point of issue, with welfare monitoring requirements defined as part of the permit — not as a separate manual process.
Control room teams have a live view of all active permits, including those involving lone workers, with check-in status visible alongside permit details. Missed check-ins generate an alert within the system rather than depending on someone remembering to chase. And at shift handover, lone worker permit status is part of the structured handover record — not an afterthought.
If you want to see how that works in practice for your asset, get in touch.