Search or navigate to a page
At 21:58 on 6 July 1988, the Piper Alpha platform in the North Sea began a chain of explosions that killed 167 men and destroyed one of the most productive installations in the UK sector. The public inquiry led by Lord Cullen identified many failures, but one sits at the centre of the disaster: a breakdown in the permit-to-work system. A pressure safety valve had been removed from a condensate pump for maintenance and a blank flange fitted in its place. Two permits existed for work on that pump, they were not cross-referenced, and the night shift, unaware the valve was missing, restarted the pump. The result was a catastrophic release of condensate and ignition. Nearly four decades later, permit-to-work remains one of the most safety-critical administrative controls on any high-hazard site, and one of the most consistently mismanaged. This article examines what a technically sound permit-to-work system actually requires, where these systems fail in practice, and how HSE professionals can build one that holds up under operational pressure.
A permit-to-work (PTW) system is a formal, documented process used to control work identified as potentially hazardous. Its purpose is to ensure that before non-routine or high-risk work begins, the hazards have been assessed, the necessary precautions are in place, the work is authorised by a competent person, and everyone involved shares a common understanding of what is being done, where, and under what conditions. It is a communication and authorisation instrument first, and a paperwork exercise a very distant second.
The distinction matters because the most common organisational failure is to treat the permit as the safety measure itself. A permit does not make a confined space safe; isolation, gas testing, ventilation and rescue cover do that. The permit is the mechanism that verifies those controls exist and coordinates the people who depend on them. The UK Health and Safety Executive makes this explicit in HSG250, Guidance on permit-to-work systems, which stresses that a PTW is not a replacement for robust risk assessment but the operational bridge between the assessment and the work on the ground.
Typical activities that warrant a permit include hot work, entry into confined spaces, work on or near live electrical systems, breaking containment on process lines, excavation, work at height in live areas, and any task requiring the isolation of hazardous energy. ISO 45001:2018 reinforces the requirement indirectly through Clause 8.1.2, which obliges organisations to eliminate hazards and reduce risks using the hierarchy of controls, and through its emphasis on controlling changes and managing contractors — activities where permits are the practical enforcement point.
A defensible permit is built from a small number of non-negotiable elements, each of which corresponds to a known failure mode. Understanding the function of each is more useful than memorising a template.
Precise scope and location. The permit must describe the specific task, the specific equipment (by tag number, not description), and the exact location. Vague scope is a recurring root cause: "work on the pump" invites exactly the ambiguity that killed people on Piper Alpha. Where multiple permits touch the same equipment or area, they must be explicitly cross-referenced so that no authoriser can approve work in ignorance of a conflicting activity.
Hazard identification and precautions. The permit should list the hazards specific to that task and the controls required before, during and after — isolations to be applied, atmospheric tests to be taken and their acceptance criteria, PPE, standby personnel, and firefighting or rescue arrangements. Gas test results, where required, should be recorded with the time taken and the instrument used, and should carry a defined validity period rather than being treated as a one-off clearance.
Isolation and lock-out verification. The permit must confirm that energy isolation has been physically applied and verified, linking to the lock-out/tag-out register. Isolation described on paper but not proven at the source is one of the most dangerous gaps in any system.
Authorisation by a competent person. A single, named, competent issuer must authorise the permit, and the person accepting it must sign to confirm they understand the conditions and precautions. This mutual sign-off is the heart of the system — it is where the shared mental model is created. Authorisation must never be delegated to someone without the technical competence to judge whether the precautions are adequate.
Time limits and hand-back. Every permit must have a defined validity, expiring at the end of a shift or task, and a formal hand-back step in which the issuer confirms the work is complete, the area is safe, isolations can be removed and equipment returned to service. A permit that outlives the assumptions it was written under is worthless. Shift-change hand-over is a particularly high-risk moment and must be managed as a deliberate, documented transfer, not an informal conversation.
The failure modes of PTW systems are remarkably consistent across industries, and none of them are about the design of the form. They are about the behaviours and pressures that surround it.
The first is normalisation and rubber-stamping. When issuing a permit becomes a high-frequency clerical task, authorisers stop reading them. Signatures are applied without verification, boxes are ticked from memory, and the permit degrades into a record that work happened rather than a control that made it safe. This is a direct expression of what safety scientists call the drift into failure: small deviations become routine because they are usually followed by no adverse outcome.
The second is scope creep and undocumented change. Work begins under a permit and then expands — an extra valve, a second confined space, a different method — without the permit being reassessed and reissued. The controls that were adequate for the original scope no longer match the work. This is why management of change and PTW must be tightly coupled.
The third is simultaneous operations (SIMOPS) and permit conflict. When several crews work in the same area under separate permits, the hazard is the interaction between activities that no single permit captures — hot work above a line that another crew is opening, for example. Without a coordinating overview, typically a permit coordinator and a spatial or master-permit register, these interactions are invisible until they cause harm.
The fourth is weak isolation and inadequate gas testing. Isolations assumed rather than verified, single isolations where positive isolation is required, and gas tests taken once and treated as valid indefinitely are persistent contributors to fatalities in confined space and breaking-containment work.
The fifth, and the one that reappears in almost every major-accident inquiry, is failure at hand-over. Piper Alpha itself was, at its core, a hand-over failure. Information about the removed safety valve did not cross the shift boundary. Any PTW system that relies on individuals to remember and verbally relay permit status across shifts is one bad night away from a serious incident.
A permit-to-work system earns its keep only if it works under real operational conditions — time pressure, fatigue, production targets and staff turnover. Several design and management choices measurably improve resilience.
Invest in competence, not just compliance. Issuers and acceptors should be trained and formally assessed against the specific permit types they handle, and that competence should be periodically revalidated. A permit is only as good as the judgement of the person signing it. Frameworks such as NEBOSH and IOSH qualifications provide a baseline, but site-specific authorisation training is what actually confers competence.
Design permits to be read. Overlong, generic forms invite tick-box behaviour. A permit that forces the issuer to actively confirm task-specific hazards, rather than acknowledge a pre-printed checklist, keeps cognition engaged. Colour-coding by permit type and hard cross-reference fields for concurrent work reduce coordination errors.
Make coordination a defined role. On sites with meaningful SIMOPS exposure, a permit coordinator holding a master view of all live permits — increasingly through electronic permit-to-work (ePTW) systems — closes the interaction gap that individual permits cannot. Electronic systems add real value here: they enforce mandatory fields, flag conflicting permits on the same equipment tag, prevent expired permits from remaining open, and create an auditable trail. They are not a substitute for competence, but they remove several mechanical failure modes.
Audit for quality, not quantity. Counting permits issued tells you nothing about whether they controlled risk. Effective assurance samples closed permits and asks whether the hazards were correctly identified, whether isolations were verified, whether gas tests were valid, and whether hand-back actually occurred. Field verification — physically checking that the isolations and precautions described on an active permit exist on the equipment — is the single most revealing audit any HSE professional can perform.
Treat hand-over as a controlled process. Shift-change should include a structured, documented review of every live permit, with the outgoing and incoming authorisers jointly confirming status. This is precisely the step whose absence defined Piper Alpha, and it is the cheapest high-impact improvement most organisations can make.
For HSE professionals responsible for a permit-to-work system, a short set of actions delivers disproportionate risk reduction:
The permit-to-work system occupies an uncomfortable position in the hierarchy of controls: it is an administrative measure, and administrative controls are inherently weaker than elimination or engineering solutions because they depend on human behaviour every single time they are applied. That is precisely why it demands rigour. A well-designed permit does not merely record that hazardous work was authorised; it forces a competent person to think, verifies that physical controls are in place, and builds a shared understanding among everyone who could be harmed. Piper Alpha remains the industry's most painful reminder that when this control degrades into a paperwork ritual, the consequences are measured in lives. The technical elements of a good permit are well understood and have been for decades. The enduring challenge for HSE professionals is not designing the form — it is defending the discipline behind it against the daily pressure to cut the corner.
Sign in to join the conversation