What is a Permit to Work?
A practical guide to permit to work systems: the four permit types, why a single generic form is the most common point of failure, and what turns a permit from paperwork into an actual control.
A permit to work is a formal, documented authorisation to carry out a specific hazardous task, in a specific place, during a specific window, under conditions agreed in advance. It exists because some jobs are dangerous enough that starting them should require a deliberate act of permission rather than a supervisor saying go ahead.
Almost every industrial organisation has one. Far fewer have one that works, and the failure is remarkably consistent: the permit becomes a form to complete rather than a control that stops work. This guide covers the four types most sites need, why collapsing them into one document is the most common design mistake in the whole discipline, and what separates a permit system that prevents incidents from one that merely documents them.
One form cannot cover four different hazards
Most sites need four permit types, and they have almost nothing in common with each other. What makes each one useful is precisely the part that does not generalise.
Energy isolation
Every energy source identified and isolated, locks and tags applied by the people at risk, stored energy released, and isolation verified by attempting to start the equipment. The verification step is the one that gets skipped, and it is the one that matters.
Confined space entry
Atmosphere tested before entry and monitored during it, ventilation running, a named attendant stationed outside who does not enter under any circumstances, and a rescue plan that does not consist of shouting for help.
Hot work
Combustible material removed or protected, ignition sources controlled, extinguishing equipment present, a fire watch during the work — and, critically, a fire watch that continues after the work stops, because that is when most hot-work fires actually start.
Work at height
Anchor points verified rather than assumed, fall arrest equipment inspected and in date, the area below controlled, and a rescue plan for a suspended worker — because suspension trauma makes a successful arrest a time-limited situation, not a resolved one.
Now consider what happens when those four are merged into a single permit form with a generic checklist. The specific prompts disappear. A box labelled safety checks complete does not ask anyone whether the atmosphere was tested, whether the anchor point was verified, or whether the fire watch is still there. The signature is collected, the record exists, and the control that would have prevented the incident was never actually performed.
This is not negligence. It is a predictable consequence of designing for administrative convenience. One form is easier to manage and easier to audit as a count. It is also the reason a permit system can show ninety-eight percent compliance while the specific checks that make each permit type meaningful go unperformed.
A permit that cannot stop the job is a record, not a control
Here is the test that separates the two. If the permit is refused, or expires, or has an outstanding condition — does the work stop?
In most organisations the honest answer is that it depends on whether anyone notices. The permit lives in a safety system. The job lives in a maintenance system. Nothing connects them except a person, and people under schedule pressure are exactly the wrong place to put a safety interlock.
A permit becomes a control when it is attached to the work order it governs, so the job cannot be started or closed while the permit is missing, expired or unapproved. That single structural change converts the permit from documentation into authorisation. It also removes the most uncomfortable conversation in safety management — the one where a supervisor has to physically stop a crew who are already standing there with tools in hand.
Where permit to work systems break
| Failure | What it looks like in practice |
|---|---|
| The generic form | One checklist for four hazard types, so no permit prompts the check that matters for its own hazard. |
| The rolling permit | A permit issued Monday and still in use Thursday, covering conditions that changed on Tuesday. |
| The absent issuer | Approval signed by someone who never went to the location and is relying on a description. |
| The uncontrolled handover | Shift changes and the incoming crew inherits a permit whose conditions nobody re-verified. |
| The unclosed permit | Work finished, isolation still in place, equipment unavailable and nobody sure whether it is safe to restore. |
| The invisible contractor | A permit issued to someone whose certification lapsed, because the certificate is filed rather than checked. |
Notice that only the first is a design problem. The other five are lifecycle problems — issue, validity, handover, closure and competency — and they are what a paper or spreadsheet system handles worst, because none of those states has an owner once the form leaves the office.
What a digital permit to work should actually change
Digitising a permit system is often sold as faster approval. That is the least interesting benefit. The changes worth paying for are structural.
Each permit type carries its own signed checklist, so the confined-space form asks about atmosphere and the hot-work form asks about the fire watch after the job. Validity is a property of the permit rather than a date somebody reads, so expiry is enforced instead of noticed. Competency is checked at issue against live certificate status, which catches the contractor whose licence lapsed last month. Closure is a required step with its own verification, so isolation cannot be left in place by omission. And the permit is attached to the work order, so authorisation gates execution.
The audit benefit follows automatically. Instead of retrieving a folder and hoping the right form is in it, the question show me every hot-work permit issued in that area last quarter and who approved each one becomes a query. That is the seventh stage of the safety lifecycle — proving it happened — arriving as a by-product rather than a project.
How SmartX HUB handles permits
Permits live alongside the maintenance work they govern rather than in a separate safety application, which is what allows a permit to block the work order it covers until it is approved and open. Four permit types each carry their own signed checklist, competency is validated at issue against live certificate status, and closure is an explicit step. Because it runs on the same record as tracking and training, the person named on the permit is the same person in the training register and the same person counted during an evacuation.
The seven stages of the safety lifecycle and where each one breaks.
Where hazardous work is planned, and where the permit has to reach.
Competency checked at issue rather than filed and forgotten.
Make the permit stop the work, not just record it
See how SmartX HUB attaches permits to the work orders they govern, with a dedicated checklist per permit type and competency validated at issue.
Explore our blog for insightful articles, personal reflections and ideas that inspire action on the topics you care about.
Explore more information about cases and news.
Stay informed with the latest updates and in-depth insights.
RFID Tool Tracking & MRO — Common Questions
Answers to the questions we hear most from teams evaluating RFID tool tracking for maintenance and MRO operations. Have another question? Reach out through our support center.
What are the main challenges of MRO tool control?
How does RFID compare to barcodes, NFC, BLE or GPS for tools?
How do you set up an RFID tool tracking system?
How does RFID integrate with our existing MRO and ERP systems?
What if some tools are too small or the wrong shape to tag?
How does RFID ensure calibration and maintenance compliance?
How does RFID support predictive and preventive maintenance?
What keeps tools accessible during downtime or power loss?
Still have questions about bringing RFID tool tracking to your operation?
Talk to Our Team
