A permit that never reaches the gate authorises work it cannot prevent.
A permit to work is signed, filed and forgotten. The welder it authorises walks through the gate the following week on a badge that knows nothing about it, into an area the permit never covered.
The paperwork was correct. The control was absent — because a permit that does not reach the gate authorises work it cannot prevent.
Different hazards require different verifications and different approvers. The common types:
| Permit type | Core verification |
|---|---|
| Hot work | Fire watch, area clearance, gas testing where applicable |
| Confined space | Atmosphere testing, rescue plan, standby person |
| Work at height | Fall protection, access equipment, exclusion zone |
| Electrical | Isolation, lockout, verification of dead state |
| Excavation | Buried services survey, shoring, edge protection |
The approval chain is the part software most often gets wrong. A permit needs the area owner and the safety function, not one general approver — because the area owner knows what else is happening in that space, and safety knows whether the controls are adequate. Collapsing both into one signature removes the check that matters.
Through a direct link between permit validity and badge validity. In practice:
Step three is the one that changes outcomes: a worker authorised for a confined space entry in Unit 3 should not have access to Unit 7 that afternoon. Site-wide access with a task-specific permit is the arrangement that produces incidents nobody predicted.
Permits expire — that is their purpose. What matters is whether expiry does anything.
Three triggers worth enforcing:
The third is what connects permits to the wider contractor record: a valid permit held by a worker whose certification expired yesterday should not open a gate. Systems that treat permits and credentials as separate silos cannot make that connection.
This is the practical question that reveals whether a system was designed by someone who has stood at a gate. A hard cut-off that strands workers inside a hazardous area is worse than no control.
The workable pattern has three parts: a warning before expiry to the permit holder and the area owner, an extension path requiring the same approvers as the original, and a controlled exit — expiry stops new entry rather than trapping anyone inside.
Extensions must be recorded as extensions rather than silently updating the original permit, because the pattern of extensions is itself safety information: a task extended three times was scoped wrongly.
These two carry the highest consequence and deserve tighter handling than other types:
The last item is a genuine gap in most paper systems: two permits, each individually sound, can be dangerous together. Only a system that shows all active permits by area can surface that.
They have to be, because breakdowns do not respect shift patterns. What matters is that the out-of-hours path is designed rather than improvised:
A defined on-call approver with genuine authority, a shorter default window than daytime permits, and mandatory documentation on the next working day. The risk of an out-of-hours permit is not that it is granted — it is that it is granted by whoever answered the phone.
After an incident, the permit record is examined first. A defensible record contains:
Point four is where paper systems fail hardest: the names written on a permit are an intention; the gate record is evidence of who was actually there. When those two disagree, only one of them is defensible.
In Haseen, permits are first-class records with their own approval chains, areas and windows, linked to named workers whose site access is scoped to that permit. Closure and expiry end the associated access, an expired certificate or induction overrides an otherwise valid permit, and extensions are recorded separately from the original.
See Haseen permits and the buyer view in contractor management software: buyer's checklist.
It authorises a specific hazardous task, in a specific location, during a specific window, after defined controls are verified — and closes when the task ends. As software, its value is that the authorisation becomes an enforceable condition of site access rather than a signed document in a folder that the gate knows nothing about.
By linking permit validity to badge validity: the permit is approved for a task, area and window; named workers are linked to it; their access is scoped to that area and window rather than to the site generally; the gate confirms an active permit before entry; and closure ends the access. Site-wide access with a task-specific permit is what produces unpredicted incidents.
The area owner and the safety function, separately — not one general approver. The area owner knows what else is happening in that space, including other active permits nearby; safety knows whether the controls are adequate. Hot work also warrants shorter windows, a named fire watch recorded as a person, verified pre-work checks with timestamps, and post-work monitoring before closure.
They must be, since breakdowns ignore shift patterns — but through a designed path rather than an improvised one: a defined on-call approver with genuine authority, a shorter default window than daytime permits, and mandatory documentation the next working day. The risk is not that an out-of-hours permit is granted, but that it is granted by whoever answered the phone.
A hard cut-off that strands workers inside a hazardous area is worse than no control. The workable pattern is a warning before expiry to the holder and area owner, an extension path requiring the same approvers as the original, and expiry that stops new entry rather than trapping anyone. Record extensions separately — a task extended three times was scoped wrongly.
Who requested it and for what task, which controls were verified and by whom with timestamps, each approver separately, who actually worked under it, how and when it closed, and every extension with its justification. The critical one is who actually worked: names on a permit form are an intention, while gate records are evidence — and when they disagree, only one is defensible.
Take one closed permit from last month and check whether the people who entered site that day match the names on it. That comparison tells you whether your permits are controls or paperwork.
Scoped to an area and a window, with closure and expiry that actually revoke — and extensions recorded separately.