Most problems with Control of Work do not start with a major failure. More often, they develop through small gaps in the process.

An isolation certificate is difficult to trace back to the permit it supported. A permit is extended but the associated controls are not reviewed properly. A contractor's competency information is held somewhere separate from the permit process. At shift handover, the incoming team has to work out which permits and isolations are still live.

Individually, these issues can appear relatively minor. Across a busy asset, however, they make it increasingly difficult to maintain a clear picture of work taking place and, just as importantly, to demonstrate afterwards how that work was controlled.

We have seen this particularly on mature assets, where processes have evolved over many years and different systems, spreadsheets and paper records have gradually become part of the same Control of Work process.

When evaluating Permit to Work (PTW) software, the question therefore shouldn't simply be whether the system can create and approve an electronic permit. The more useful test is how well it supports the way work is actually planned, authorised, isolated, handed over and closed out.

Here are some of the areas we believe operators should look at closely.

Start with the complete permit lifecycle

One of the easiest mistakes to make when assessing PTW software is concentrating too heavily on the permit form itself.

The permit is only one part of the process.

Depending on the type of work and the asset, there may also be risk assessments, isolations, certificates, supporting documents, gas tests, toolbox talks, competency requirements, extensions, suspensions and shift handovers.

These records need to remain connected throughout the life of the job.

For example, if an isolation supports several permits, the system should make that relationship immediately visible. Before the isolation is removed, the person responsible should be able to see which permits still depend upon it.

This sounds straightforward, but it is an area where disconnected systems and paper processes can create unnecessary risk and administration.

We have written separately about why isolation can become a weak point in Permit to Work, particularly when the permit and isolation processes are managed separately.

Think about the person taking over the shift

A useful way to assess any Control of Work system is to consider the person coming onto the asset at the start of a shift.

What can they see?

They should be able to establish quickly:

  1. which permits are currently live;
  2. which jobs are suspended;
  3. which isolations remain in place;
  4. which permits share an isolation;
  5. what work is due to continue during their shift;
  6. what has changed since the previous handover; and
  7. whether anything requires their immediate attention.

If answering those questions involves checking several screens, speaking to different departments or referring to a separate spreadsheet, the technology may have digitised the paperwork without necessarily improving operational visibility.

For us, this is an important distinction.

A good PTW system should make the current state of work easier to understand, particularly during handover and periods of high activity.

Auditability should be designed into the process

When an operator is asked to review an event or demonstrate how a particular job was controlled, the information may need to be retrieved months or even years after the work took place.

That is where the quality of the audit trail becomes important.

It should be possible to establish who created a permit, who reviewed it, who authorised it, what isolations were associated with it, when its status changed and who ultimately closed it.

Changes should also be traceable.

If a permit was extended, suspended, reissued or amended, the historical record should make that clear rather than simply showing the latest version.

This is useful during regulatory inspections and internal audits, but it is equally valuable during incident investigation, operational assurance and routine management review.

The objective is straightforward: the organisation should be able to reconstruct what happened without relying on someone's memory or manually piecing together records from several sources.

Contractor competency needs to be part of the workflow

Contractors present a particular challenge because competency and authorisation information is often managed outside the PTW system.

A contractor may have completed the correct training when they first mobilised, for example, but qualifications and authorisations can expire.

The practical question is what happens when that person is subsequently selected to perform or receive work.

Does the system simply allow their name to be selected, or can it identify that a required competency or authorisation is no longer current?

Where competency is relevant to the work being undertaken, bringing that information into the Control of Work process can provide an additional check at the point it matters.

We explore this further in contractor permit management: closing the competency gap on critical equipment.

Don't underestimate isolation management

In our experience, isolation management deserves particular attention during a PTW evaluation.

Permits tend to have an obvious lifecycle. They are created, reviewed, issued and closed.

Isolations can be more complicated.

An isolation may remain in place across several shifts, support multiple permits or continue after an individual job has been suspended. There may also be circumstances where part of an isolation is changed while other work remains dependent upon it.

This is where the relationship between permits and isolations becomes particularly important.

Before an isolation is modified or removed, the system should provide a clear view of the work that relies upon it.

That dependency should be managed by the system rather than being something an operator has to establish manually.

Consider simultaneous operations

Another area worth testing during a demonstration is how the system deals with concurrent work.

On a busy installation, permits cannot always be considered individually. Two perfectly acceptable jobs may create additional risk when carried out at the same time or within the same area.

This becomes particularly relevant during shutdowns, major maintenance campaigns and other periods when permit volumes increase significantly.

Ask the vendor to demonstrate how the system helps the Area Authority, OIM or other responsible personnel understand the overall work picture.

A permit register is useful. A system that helps people understand where work is taking place, what equipment is affected and where potential conflicts exist is considerably more useful operationally.

Integration matters, but it needs a purpose

It is easy for software evaluations to turn into a discussion about how many systems a platform can integrate with.

We would approach this differently.

Start with the operational information that people currently have to enter twice or manually reconcile.

That might include maintenance work orders, equipment information, isolation data, personnel records or competency information.

If a maintenance job originates in an ERP or maintenance management system, for example, operators should consider whether relevant information can flow into the PTW process rather than being re-entered manually.

The same principle applies when information needs to flow back.

The aim should be to remove unnecessary duplication while maintaining appropriate controls over which system is the authoritative source for each piece of information.

This becomes increasingly important on mature assets where maintenance workload, integrity activities and Control of Work are closely connected.

Our article on maintenance backlog and OEUK's KPI guidance looks at some of the wider operational assurance considerations.

Make the vendor demonstrate the difficult scenarios

A standard software demonstration will usually show the cleanest possible workflow: create a permit, approve it, issue it and close it.

That tells you relatively little about how the system will perform in operation.

We recommend asking vendors to demonstrate less convenient situations.

For example:

  1. What happens when a permit crosses a shift?
  2. What happens when work is suspended?
  3. Can several permits share the same isolation?
  4. What happens if someone attempts to remove that isolation while one of those permits remains live?
  5. What happens when an authorisation or competency expires?
  6. How are permit extensions controlled and recorded?
  7. Can you see exactly what changed on a permit after it was issued?
  8. What does the incoming shift see at handover?
  9. How quickly can you reconstruct the complete history of a job six months later?
  10. How does the system behave when permit volumes increase significantly during a shutdown?

These scenarios tend to reveal much more about a PTW system than working through a vendor's standard demonstration.

Multi-asset operators have another consideration

For operators managing several assets, standardisation has obvious benefits, but complete uniformity is not always practical.

Different installations may have different operating arrangements, terminology, work types, approval structures and legacy processes.

A multi-asset Control of Work platform therefore needs to strike a balance.

The organisation should be able to establish common governance and reporting while retaining appropriate configuration at asset level.

This becomes particularly important during acquisitions and asset transitions, where different Control of Work practices may need to be brought gradually into a common framework.

Five questions worth answering before selecting a system

Before starting a procurement exercise, we would ask the operational team:

  1. Can we see every live permit and associated isolation without manually reconciling different records?
  2. Can we reconstruct the complete history of a permit months after the work was completed?
  3. Does the system help prevent an isolation being removed while live work still depends upon it?
  4. Can we identify when personnel authorisations or relevant competencies are no longer current?
  5. At shift handover, can the incoming team quickly understand the current work picture?

If the answer to any of these is "not easily", that is a useful place to start when defining requirements.

What we have learned from implementing Control of Work systems

Technology cannot make Control of Work effective on its own.

The underlying process, responsibilities and operational discipline still matter.

In fact, implementing a digital system often exposes inconsistencies that have existed for years: different terminology between assets, unclear approval responsibilities, duplicate permit types or local processes that everyone follows but nobody has formally documented.

That is not necessarily a bad thing.

A successful implementation provides an opportunity to understand those differences and decide deliberately which should remain and which should be standardised.

For that reason, we believe PTW projects work best when operations personnel are involved from the beginning rather than treating the implementation purely as an IT project.

The people issuing permits, managing isolations and taking over at shift change usually know exactly where the existing process creates friction.

Those are the problems the software should be solving.

Evaluating Permit to Work software

When we discuss PTW with operators, we tend to spend less time talking about electronic forms and more time discussing what happens around them.

How are isolations controlled? What happens at handover? How are concurrent activities understood? What information has to be entered twice? How quickly can the organisation establish what happened after the event?

Those questions provide a much better indication of whether a system will improve Control of Work in practice.

At Elisian, our approach to Permit to Work forms part of a wider operational assurance framework, connecting the records and activities needed to demonstrate how operational controls are being applied.

If you're reviewing your existing PTW process, we're happy to work through your current workflow with your operations team and identify where digital Control of Work could remove gaps, duplication or unnecessary administration.

← Back to Blog