Work permits — the guarded chain and the validity window

2 minHSE officerfacility_managerCompliance manager

A work permit is not a form to fill in — it is a temporary, guarded authorisation: submitted, approved by someone other than its submitter, activated within a defined time window, and closed. What confuses new users most is the guards themselves — here is why each exists.

Why you cannot approve your own permit

The submitter is not the approver. The HSE officer submits the permit, activates, closes and extends it — but approval and rejection belong to the area owner (the facility manager). This is not administrative friction: a permit is a declaration that a specific area is safe for hazardous work, and whoever owns the area owns that declaration. Auditors ask about this separation by name.

The validity window — the source of three refusals

A permit carries a window: from a date to a date. Three guards are built on it:

  1. No approval without a window: the system refuses approval until the window is set — because an authorisation without a duration is a permanent one, and no such thing exists in safety.
  2. No activation of an expired permit: a permit whose end date has passed cannot be activated — extend it to a future date or submit it again.
  3. A warning on early activation: activating before the window starts is allowed, but only after an explicit warning, so departing from the plan is a conscious decision rather than a slip.

The hazardous-task gate — the behaviour you most need to know

Tasks marked as requiring a permit do not move without an active one. Therefore:

  • Activating the permit pushes those tasks forward so they become executable.
  • Closing the permit pulls whatever is unfinished back to waiting — and the system warns you before closing if anything is about to be pulled.
  • The nightly sweep does the same when an active permit's window expires: whatever was running under it returns to waiting on its own.

If you see a task "go back" to waiting with nobody touching it, look for its permit: it was most likely closed or its window expired. That is the system working, not failing.

Extending and reopening

Extending requires a future date — a permit is never extended into the past. Reopening returns the permit to active and clears its closure date after a warning, so pulled tasks move forward again.

Read next

More in this collection