Permit-to-work systems: where they break down in practice
5 min read
A permit-to-work system looks simple on the page: identify the hazardous work, get the right people to authorise it, confirm the controls are in place, do the work, close the permit. Most sites have a format that covers all of this correctly. Most sites also have a permit system that, in practice, doesn't function the way the format implies.
The gap rarely shows up in the document design. It shows up in the small, repeated decisions made under time pressure that the format was never built to withstand.
Where it actually breaks
- The permit gets issued before the site conditions are actually verified. The authorising person signs based on a description of the work, not a walkthrough of the specific location — so a permit for hot work near a storage area that was rearranged last week goes out without anyone noticing the new fire risk sitting three metres from where the work will happen.
- Isolation is confirmed verbally, not physically tested. "It's isolated" becomes an assumption passed down a chain of people, none of whom personally verified it with a lockout device and a test, because the person who did the isolation is on a different shift by the time the permit is actually used.
- The permit outlives the conditions it was written for. Work authorised for a specific scope on a specific day continues into a second shift, or a third, under the same permit, while the site conditions around it have changed — different crew, different equipment nearby, different weather if the work is outdoors.
- Closing the permit becomes a formality. The box gets signed to clear the log, without anyone confirming the area was actually left in a safe state — tools removed, isolations reinstated, barriers taken down properly rather than left as a trip hazard.
Why this keeps happening even on well-run sites
None of these failure points are about people being careless. They happen because a permit-to-work system is, in practice, a communication tool operating across shift changes, contractor handovers and time pressure — and the format alone doesn't enforce the verification steps it assumes will happen. A permit that requires a signature for "isolation confirmed" doesn't distinguish between someone who tested it with their own hands and someone who was told it was done by someone else, three hours ago, who has since left site.
What actually closes the gap
The sites where permit-to-work genuinely functions tend to share a few practical disciplines, none of which require redesigning the form itself:
- The person authorising the permit physically visits the location before signing, rather than authorising from a description.
- Isolation is verified by direct test at the point of use, not accepted as a report passed along a chain.
- Permits have a hard validity window tied to a shift, not an open-ended "until the job is done," forcing a fresh review at every handover.
- Closing a permit includes a physical walkthrough of the area, not just a signature.
The document was very likely never the problem. What determines whether a permit-to-work system actually controls risk is whether the people using it treat the verification steps as real actions to be performed, or as boxes that get signed because that's what happens next in the sequence.
Discuss this with us directly
If this raises a question specific to your site, we're glad to talk it through.