Safety Hub
1. What it is
Safety Hub is the workplace safety app. It records incidents and runs their investigations, tracks corrective actions in a register shared with Inspections, collects safety observations, schedules toolbox talks, tracks required certifications, issues permits to work, pre-qualifies contractors, dispatches emergency alerts with a muster roll-call, and produces OSHA (US) and WCB (Canada) determinations. A public portal at /safety lets anyone report a hazard without logging in.
- Enablement: Safety Hub requires a licence. An admin enables it per business from Admin → Apps Marketplace; it is never turned on automatically.
- What it is not: Safety Hub is not Lone Worker (timed check-ins and SOS for people working alone — Lone Worker can open a Safety Hub incident, but the alert engines are separate). It is not Inspections (checklists and field audits — the two apps share one corrective-action register). It is not Compliance Hub — the risk register and legal register live there, and Compliance Hub reads Safety Hub records as evidence. It is not the Broadcasts app — emergency alerts are composed and sent inside Safety Hub.
2. Standing it up
- Enable the app at Admin → Apps Marketplace. Grant access to the people who should see it through Access Management; anyone the app is published to can report incidents and observations.
- Create locations at Admin → Locations. Incidents, observations, permits and talks are tied to a location. A manager sees safety records only at the locations they manage, so a record with no location is invisible to plain managers.
- Choose modules at Safety Hub → Admin → Settings → Modules. Eight toggles: Incidents, Observations, Toolbox Talks, Certifications, Emergency Alerts, Contractor Pre-qualification, Permits to Work, and OSHA Compliance (US) under Compliance. All are on by default. WCB Compliance (Canada) is off by default. Each module’s sidebar entries appear only while its toggle is on.
- Decide who sees every site and who may send alerts under Settings → Who Can Do What. Who can see safety records at every site? defaults to Safety Hub app admins. Who can send an emergency alert? defaults to managers and admins. Pick a group for either to hand the capability to an EHS team without making them business admins.
- Define certification requirements at Safety Hub → Admin → Certification Requirements. A requirement alone shows nothing: compliance is computed against certifications employees actually hold, which come from certified skills in Skills & Credentials or training records from Training Connect. Set up both sides or every roster stays empty.
- Assess contractors before their first permit. With Require a current pre-qualification before issuing a contractor permit on (the default), a permit naming a contractor cannot be issued until that contractor has an approved or conditional assessment under Team → Contractors. Permits for your own employees are unaffected.
- Open the public portal, if you want one. The
/safetyportal needs two things: Safety Hub enabled, and the Safety Hub portal switched on in the Portals app. Safety Hub’s own Settings page shows a Public Hazard Portal card with Open portal settings and a Close the public portal button — it can close the portal but never open it. Fill in Public Emergency Contacts and the Emergency number (shown as 911 when blank), and mark the knowledge-base articles that should be public. - Leave autonomous operations off until you are ready. Enable Autonomous Safety Operations is off by default. Turning it on does nothing by itself: the AI Console (linked from the Settings page) also needs a trust level, and on probation every proposed action waits for your approval.
- Confirm it worked. A manager landing on Safety Hub sees the dashboard tiles (days without injury, incidents this month, open investigations, permit tiles, expiring certifications). An employee is taken straight to Submitted by Me. On mobile, employees see their own submissions, permits and alerts.
3. How it fits together
Incident vs observation vs near miss — An incident is a formal event record with one of eight types: Injury, Near miss, Property damage, Environmental, Security, Vehicle accident, Equipment failure, or Other. It carries a severity (Low, Medium, High, Critical), an investigation, OSHA/WCB determinations and corrective actions. An observation is a lightweight sighting — Positive, At-risk or Near miss — with an optional follow-up and no investigation. “Near miss” therefore exists on both sides, and the public portal files a Near Miss as an observation, not an incident. Other is the neutral landing type for reports that fit nothing else; reclassify it once reviewed.
Investigation vs corrective action — High or Critical incidents, and every Injury, require an investigation. The investigator records findings and completes it; completion is one-way. Corrective actions are separate rows in the Corrective Actions register, shared with Inspections and Leader Rounds, each with a type, priority, due date and assignee. An incident cannot close while its investigation is open. When Require Effectiveness Verification Before Closing Over Completed Actions (ISO 45001) is on, it also cannot close while a completed action is awaiting the Verify step — which must be done by a manager who is not the assignee.
Requirement vs held certification — A certification requirement says who must hold what, scoped by role, location, department or job title, with a validity period and reminder lead. A held certification is the employee’s certified skill or training record. Compliance is the match between the two; the Training Gaps view separates “expired” from “never certified”.
Alert vs muster check-in — An emergency alert is the message you dispatch over In-app, Email, Push, SMS and Voice. Its recipient response is either Require acknowledgement (recipients confirm they saw it) or Require safety check-in — the muster, where each recipient answers “I’m safe” or “I need help” and the roster shows who has not answered. “I need help” pages responders: the author, then app admins, then business admins plus the configured group.
Permit stored status vs what the board shows — A permit’s status is Draft, Requested, Approved (shown as Issued), Suspended, Closed, Cancelled or Expired. Active and Past end time are not statuses: an issued permit is Active inside its work window and Past end time once the window closes. Nothing flips a permit to Expired until an hourly check finds it 24 hours past its end without a close-out.
Pre-qualification current vs lapsed — An assessment decided Approved or Conditional is current until its Valid until date. Past that date it shows a Lapsed badge and no longer satisfies the permit gate; a daily check then moves it to Expired. Conditional counts as current, with the conditions recorded on the assessment.
“Safety officer” is not a role — Wherever Safety Hub adds “safety administrators”, it means up to 5 business admin accounts. To name a real EHS team, set Route incident and hazard alerts to this group under Settings → Notifications.
My, Team and Admin zones — Everyone gets the My zone: Report Incident, Submit Observation, Submitted by Me, My Certifications, My Alerts, My Toolbox Talks, My Corrective Actions, My Permits and Knowledge Base. Managers add the Team zone: Emergency Alerts, Incidents, Corrective Actions, Observations, Campaigns, Toolbox Talks, Topic Library, Certifications, Permits to Work, Contractors, OSHA (US), WCB (Canada) and Analytics. Admins and Safety Hub app admins add Alert Templates, Certification Requirements and Settings. Within the Team zone a plain manager is site-scoped; admins, app admins and anyone granted Who can see safety records at every site? see everything.
Worked example: a hot-work permit for a contractor. A supervisor opens My Permits, clicks Create Draft Permit, picks Hot work, describes the work, sets the site, the Work starts / Work ends window (14 days at most) and the Contractor (if external), and ticks the hazards. They click Request approval; the permit becomes Requested and authorisers get an in-app notification. Another manager for that site opens it and confirms all six precautions — from Combustibles removed or shielded within 11 m (35 ft) to Fire watch during work and 60 minutes after — then clicks Confirm precautions and issue permit. If the contractor has no current pre-qualification and the gate is on, that click is refused with the contractor’s name. Once issued, the board shows it as Active during the window. At the end of the shift either party clicks Close out, ticks Work complete or stopped; area inspected and left safe, adds close-out notes and clicks Close permit. The record then reads “Area left safe”.
Worked example: a contractor assessment. A reviewer answers the 15-question questionnaire for a roofing contractor, answering Yes to everything except Workers’ compensation / employer’s liability cover in force. The score is 91% — normally a Low suggestion — but the suggested tier is capped at High, because a No on any 3-point Performance or Insurance question always caps it. The reviewer records the decision as Conditional, keeps High risk, sets the conditions and a Valid until date defaulting to 12 months out.
4. Running it
Investigating an incident
- Go to Safety Hub → Team → Incidents. Filter by status, severity, type or location.
- Open the incident. If Auto-assign Investigators is on, an investigator was assigned at report time — the location’s manager, else a business admin, else any manager — with a deadline of Investigation Deadline (days) after the event. Assign or change the investigator here if needed.
- The investigator records findings and completes the investigation. Add corrective actions; they appear in the shared register with due dates and assignees.
- Determine OSHA recordability (or WCB reportability) from the incident. A fatality is always recordable; otherwise an injury with days away, restricted work, medical treatment beyond first aid, loss of consciousness or a significant injury is. A case number is issued and the entry appears on the 300 Log.
- Close the incident. Closure is blocked while the investigation is open or, with the ISO 45001 policy on, while an action awaits verification. Use Print report or the Evidence pack when an auditor asks.
Running a toolbox talk
- Go to Team → Toolbox Talks and schedule a talk: title, a topic from the Topic Library, location, facilitator, time, duration (prefilled from Default Talk Duration) and expected attendees. Attendees are invited when Send Toolbox Talk Invitations and Day-Of Reminders is on.
- The facilitator starts the talk and records attendance. With Require Attendance Signatures on, an unsigned roster is refused. Employees can self-record their own attendance on mobile.
- Complete the talk with post-meeting notes, and print the attendance sheet if you keep paper records. The next morning, absentees’ managers and the facilitator are told who was missing.
Issuing a permit to work
- Go to Team → Permits to Work. The board counts permits awaiting approval, active now and past end time; the default filter shows requested and issued permits.
- Open a Requested permit, confirm every precaution for its type, add Authoriser’s notes and click Confirm precautions and issue permit. Precautions can only be ticked by managers.
- Use Suspend (with a reason — work must stop; the requester is told) and Resume while the work is paused. Either the requester or the authoriser closes the permit; a permit left open past its end time is nudged, then expired 24 hours later. Cancelling a permit notifies the requester and the authoriser.
Assessing a contractor
- Go to Team → Contractors and click to open an assessment for the vendor: scope of work, trades on site, EMR, TRIR, fatalities and citations in the last 3 years, insurance expiry.
- Answer the questionnaire — Yes, No or N/A with evidence notes per question — and attach documents (insurance certificates already on the vendor are listed alongside). Click Submit for decision.
- Record the decision: Approved, Conditional (with conditions) or Rejected, the risk tier, and Valid until. The register counts current, open, expiring-within-30-days and lapsed assessments, and the reviewer is warned 30 days before expiry.
Dispatching an alert and reading the muster
- Go to Team → Emergency Alerts and compose: title, body, an SMS/voice version, audience, channels, the recipient response and a chase-up deadline. Saving always creates a draft; start from an Alert Template for recurring scenarios.
- Send it. Only the people named by Who can send an emergency alert? can press Send; if your Comms Hub requires approval for emergency alerts, submit it first (admins bypass). With Translate emergency alerts into recipients’ languages (AI) on, each non-English recipient gets a translated copy.
- Watch the roster: safe, needs help and unresponded, with per-channel delivery diagnostics. A “needs help” pages responders with an Inbox action item. Unacknowledged recipients are chased every 6 hours over in-app, email and push for 7 days.
- Cancelling a sent alert broadcasts a stand-down to everyone it reached. Open incident from the alert pre-fills an incident with the alert’s details.
Monitoring certifications
- Go to Team → Certifications for the roster, then Expiring, Expired, By Employee, By Requirement and Training Gaps.
- Holders and their managers are reminded at the requirement’s lead time (default 30 days), then 7 and 1 days before expiry; expired notices go to the manager and safety administrators weekly for 30 days.
- Employees see their own under My Certifications, with a Practice Hub link for re-certification practice.
5. Settings
All settings live at Safety Hub → Admin → Settings, grouped by card. Changes apply immediately. Reset clears only Safety Hub’s own keys back to these defaults.
| Setting | Card | Default | What it changes |
|---|---|---|---|
| Enable Safety Hub AI Agent | top of page | On | Whether Ask AI answers Safety Hub questions and runs its tools |
| Enable Autonomous Safety Operations | top of page | Off | Lets the hourly detector nudge owners of stalled investigations and escalate unassigned High/Critical incidents; also needs a trust level in the AI Console |
| Enable AI authoring assists (alert copilot and describe-to-fill) | top of page | On | The alert composer copilot and describe-to-fill on the observation, requirement and topic forms |
| Enable Incidents Module | Modules | On | Incident reporting, investigations, the corrective-action register, OSHA and WCB |
| Enable Observations Module | Modules | On | Observations and campaigns |
| Enable Toolbox Talks Module | Modules | On | Talks and the Topic Library |
| Enable Certifications Module | Modules | On | Requirements, rosters and expiry reminders |
| Enable Emergency Alerts Module | Modules | On | Alerts, templates, muster and the alert API |
| Enable Contractor Pre-qualification Module | Modules | On | The Contractors register and expiry warnings |
| Enable Permits to Work Module | Modules | On | The permit board, My Permits, mobile permits and the hourly permit check |
| Require a current pre-qualification before issuing a contractor permit | Modules | On | Refuses to issue a contractor permit without a current assessment |
| Default pre-qualification validity (months) | Modules | 12 | Prefills Valid until on a decision |
| Emergency number | Public Emergency Contacts | blank (shows 911) | The number on the portal’s emergency page |
| Emergency contacts | Public Emergency Contacts | none | Name, role and phone shown on the portal |
| Who can see safety records at every site? | Who Can Do What | Safety Hub app admins | Cross-site visibility of incidents, corrective actions, certification rosters and observations |
| Who can send an emergency alert? | Who Can Do What | Managers and admins | Who may press Send (web, API and Ask AI) |
| Default channels | Emergency Alert Defaults | In-app, Email, Push | Pre-selected channels in the composer |
| Default recipient response | Emergency Alert Defaults | Require acknowledgement | Pre-selected response mode in the composer |
| Translate emergency alerts into recipients’ languages (AI) | Emergency Alert Defaults | On | Per-recipient translation at send time |
| Enable OSHA Compliance (US) | Compliance | On | OSHA dashboard, 300 Log, Form 301, Form 300A |
| Enable WCB Compliance (Canada) | Compliance | Off | WCB dashboard, incident log, employer’s report, annual summary |
| Default WCB Province | Compliance | blank | Province used when an incident’s location has none |
| Auto-determine WCB Reportability | Compliance | On | Runs the WCB determination when an injury is created or updated (only with WCB on) |
| Require Photos for Injury Incidents | Incident Settings | On | Refuses an Injury report without a photo on desktop and mobile — never on the public portal |
| Auto-assign Investigators | Incident Settings | On | Assigns an investigator when a qualifying incident is reported |
| Investigation Deadline (days) | Incident Settings | 7 | Days after the event before an investigation is overdue |
| Require Re-authentication Before Printing or Exporting Incident Reports | Incident Settings | Off | Step-up identity check before exports, prints and OSHA/WCB filings |
| Require Effectiveness Verification Before Closing Over Completed Actions (ISO 45001) | Corrective & Preventive Actions (CAPA) | Off | Blocks closing an incident while a completed action awaits verification |
| Escalate Overdue Actions To | Corrective & Preventive Actions (CAPA) | No escalation | Daily overdue email to Safety officers or the Assignee’s manager |
| Allow Anonymous Observations | Observation Settings | Off | Shows the anonymous option on observation forms |
| Observation Categories | Observation Settings | PPE, Housekeeping, Behavior, Equipment, Ergonomics, Chemical, Other | Category choices on observation forms |
| Default Talk Duration (minutes) | Toolbox Talk Settings | 15 | Prefilled duration on a new talk |
| Require Attendance Signatures | Toolbox Talk Settings | On | Refuses an unsigned attendance roster |
| Expiry Reminder (days before) | Certification Settings | 30 | Lead time for expiry reminders and the “expiring” window |
| Route incident and hazard alerts to this group | Notifications | none (site managers, then business administrators) | Extra recipient group for incident and observation alerts and help-request paging |
| Enable Email Notifications | Notifications | On | The email leg of every Safety Hub notification |
| Alert Site Managers and Administrators on New Incidents | Notifications | On | Master switch for new-incident alerts, including the High/Critical escalation |
| Add Safety Administrators to High-Severity Incident Alerts | Notifications | On | Adds up to 5 admin accounts on High/Critical |
| Alert on At-Risk, Near-Miss and Portal Suggestions | Notifications | On | Alerts for at-risk and near-miss observations and portal suggestions |
| Send Toolbox Talk Invitations and Day-Of Reminders | Notifications | On | Invitations, reschedule notices and day-of reminders |
| Send Certification Expiry Reminders | Notifications | On | Milestone and expired notices |
| Send Weekly Safety Summary | Notifications | Off | Monday email digest to every active manager and admin |
6. More help
- Safety Hub FAQ — specific setup and operating questions, employee complaints, and every limit
- Ask AI — the assistant answers questions about Safety Hub from these articles.