A permit to work system can do everything it's designed to do — capture the hazards, get the right signatures, log the isolation, close it out cleanly — and still let two jobs collide in the same space at the same time. The permit itself is fine. What's missing is any mechanism for checking it against everything else happening on the asset that shift.
That's the gap this post is about. Permit to work software has got very good at managing the single task. It's much less consistent at managing simultaneous operations, or SIMOPS — the situation where multiple permits, isolations, and crews are active in overlapping time and space, and where the risk isn't in any one job but in how the jobs interact.
What SIMOPS means for permit to work
SIMOPS — simultaneous operations — refers to two or more activities running concurrently where one could affect the safety of the other, even though each is separately authorised and individually low-risk. A permit to work system manages the single task; SIMOPS is the discipline of checking that task against every other live permit, isolation, and movement sharing the same area, equipment, or access route.
On a site running a handful of permits a day, that checking can happen informally — a supervisor walking the plant, a conversation at handover. On a site running dozens of concurrent permits during a shutdown or turnaround, informal checking starts to miss things, not because anyone's being careless, but because the number of possible interactions grows far faster than the number of permits.
What permit to work systems already do well
Most digital PTW platforms handle the core permit lifecycle competently: hazard identification against the task, competency and authorisation checks against the named individuals, sequenced sign-off, an audit trail that shows who approved what and when. That's the part of HSG250's guidance on permit-to-work systems that vendors have largely absorbed, and it's genuinely useful — a well-run electronic permit register is a clear improvement over a paper board or a spreadsheet passed between shifts.
Where it typically stops is at the edge of the individual permit. The system can tell you the hot work permit is correctly authorised. It usually can't tell you, without someone manually cross-checking, that a confined space entry has just been authorised twenty metres away, or that the isolation supporting one permit is the same isolation another crew is relying on for a different job entirely.
Where siloed permits create blind spots
The interactions that matter tend to fall into a small number of categories, and they recur across sectors — offshore platforms, refineries, construction sites, utilities, mining operations.
- **Spatial proximity** — hot work authorised close enough to a confined space entry, gas testing area, or ongoing excavation that a spark, fume, or dropped object from one job reaches the other.
- **Shared isolations** — two or more permits depending on the same locked valve, isolated circuit, or de-energised system, where removing the isolation to support one job would expose the other. We've written before about why isolation is the weak point in permit to work, and shared isolations are one of the clearest examples of why.
- **Shared access and egress** — a lifting operation positioned over the only walkway serving an area where other crews are working, or scaffold access shared between unrelated jobs.
- **Resource conflicts** — the same fire watch, standby person, or piece of lifting equipment allocated to two permits that overlap in time.
- **Timing overlap that isn't visible at handover** — a permit extended into the next shift without the incoming team being told what else is now running concurrently in the same zone.
Each of these can exist even when every individual permit involved is correctly filled in, correctly assessed, and correctly signed off. The failure isn't in the permit. It's in the absence of anything looking across permits.
A realistic scenario
As a hypothetical: a hot work permit is raised for pipework repair on a platform module. Separately, a confined space entry permit is raised for vessel inspection one level below, sharing part of the same ventilation path. Both permits are assessed correctly against their own task. Neither permit form asks whether anything else nearby could affect gas concentrations in the confined space, because that question sits between the two permits, not inside either one. If the two are managed on separate paper boards, or on a digital system that doesn't surface concurrent activity in the same zone, the interaction only gets caught if someone happens to notice it — an Area Authority doing a walk-round, or a sharp-eyed permit issuer cross-referencing manually.
Closing the gap operationally
There isn't one fix, and most sites use a combination of approaches, matched to how much concurrent activity they actually run.
A permit interaction matrix — a defined set of compatibility rules between work types, agreed in advance and applied at the point permits are raised — is standard practice on many high-hazard sites and gives issuers a documented basis for flagging conflicts rather than relying on individual judgement. Live site or permit dashboards that show every active permit against a zone or asset map make proximity and overlap visible without anyone having to ask. Some sites layer in geofenced or zone-based alerts, so a new permit request in an area with existing live work triggers a review before it's issued rather than after. None of this replaces the shift handover conversation — it supports it, by giving the incoming team something concrete to check against rather than relying on what the outgoing team remembers to mention.
What to look for in a system
If you're assessing how well your current PTW process — paper or digital — handles this, a reasonable test is to ask it to show you every permit and isolation active in a given zone right now, not the status of one permit in isolation. Ask whether extending a permit into the next shift automatically surfaces what else is running in the same area. Ask what happens if a new permit request would put incompatible work types in the same zone at the same time — does anything flag it, or does it depend entirely on the issuer remembering. Our buyer's guide to permit to work software goes into more of the detail worth checking when evaluating a system on this basis.
This is the first piece in a series looking at SIMOPS and permit visibility in more depth — including how to build a SIMOPS risk assessment methodology for multi-activity sites, how shared isolations specifically create blind spots across concurrent permits, and how to construct a permit interaction matrix that issuers can actually use day to day. If your current process relies on people noticing conflicts rather than a system surfacing them, that's usually the right place to start looking.