Permits to Work — Overview
Time-bound authorisations for hazardous activities — request, approve, activate, and close, with templates, requirement checklists, and validity windows.
A permit to work is a time-bound authorisation for a hazardous activity — hot work, work at height, excavation, confined space entry, lifting, or electrical isolation. Each permit is requested from a template, gated by a sign-off chain, and only valid within its window. Permits are part of the Safety module, which is in beta.
Requesting a Permit
From Safety → Permits, click Request permit. The capture panel steps through:
- Permit — pick the template (each one carries its own requirement checklist and required documents) and give the work a title
- Validity — set valid from → valid to; the end time is prefilled from the template's default window
- Approvers — you are locked in as the Requester; add at least one Approver and set the order they sign in
Raising a permit does not send it for approval
The new permit opens as yours to prepare. Work through the requirement checklist and upload the required documents on the permit itself, then press Submit for approval — that is what passes it to the first approver. Mandatory items and required documents have to be done before that button becomes available.
What the request panel captures
Those three steps are everything the request panel collects. It does not capture a hazards and controls list or request-time photos, so a permit raised here carries no hazard list and the Hazards & controls section does not appear on its detail page.
The Permit Lifecycle
Permits move through a time-aware state machine that's recomputed whenever you open one:
| Status | Meaning |
|---|---|
| Pending approval | Being prepared by the requester, or waiting on the next sign-off |
| Active | Fully signed off and within its validity window |
| Expiring | Active, but within 24 hours of the end time |
| Expired | The window passed and it wasn't closed |
| Closed | Work finished and closed out |
| Rejected | The requester withdrew the request. A rejection by an approver does not land here — it returns the permit to Pending approval for rework |
The Permit Detail
Opening a permit shows the full picture: a status strip with a live validity countdown, a requirements checklist, any required documents, and the sign-off chain.
Submitting, Approving, Closing
- Submit for approval — the requester's own step, available once every mandatory checklist item is complete and every required document is uploaded
- Approve — the assigned member of the current party signs off. When the last party signs, the permit becomes active as soon as its window opens
- Reject — send it back to the requester with a reason; your policy can auto-create a safety issue for them
- Withdraw — the requester can pull their own permit while it is still pending. This is terminal
- Extend — push the end time out on a live or expiring permit, if your safety policy allows extensions
- Close permit — close a live permit once the work is done
- Confirm close-out — on templates that carry a close-out checklist, the last approver completes it and confirms; the permit cannot be closed until they do
Permits are time-bound
A permit automatically reads as expiring within 24 hours of its end time and expired once the window passes — the status is recomputed whenever the permit is opened or listed. Keep an eye on the Hub: expiring permits appear in the needs-attention feed with their end date and time, and the register shows a live countdown.
Next Steps
- Safety Policies — control extensions and rejection issues
- Safety Hub — where expiring and pending permits surface