Seven roles
| Role | Function |
|---|---|
| Senior management | Allocates resources |
| Employer representative | Appoints and publishes the approvers |
| Safety and environment function | Filters the work plan, decides whether a permit is needed |
| Approver | Assesses the risks and approves the permit — a specific training requirement applies |
| Permit holder | The party having the work done; completes the form |
| Area supervisor | Prioritises clashing jobs |
| Working party leader | Delivers the toolbox talk |
Additional roles
The system also defined an attendant, a gas tester, a contractor site supervisor, a worker representative and a support person. These roles attach to the permit conditionally: an attendant becomes mandatory where there is confined space work or hot work in a hazardous area.
Where separation broke
During measurement two lines of the same procedure were found to contradict each other: one line said the permit holder and the approver can never be the same person, and a few lines below, at certain plants on night shifts, both roles fell to the same post. A rule refuted by its own exception, and refuted on the riskiest shift.
What software can do here
On paper the separation is a sentence; in a system it can be a gate — the same user cannot be selected as both holder and approver, not even at night. That is the difference between writing a rule and running it.
Where the authority comes from
The list of approvers has to be published and current. In the set we measured, the template for that list was empty: the source of the answer to "who may approve" was an unfilled table. If the source of authority is blank, so is the validity of the signature.