Lone Worker FAQ
Answers to common setup and operating questions about Lone Worker.
For what the app is and how to set it up from scratch, see the
Lone Worker Overview.
Setup
What do I need to configure before check-ins start?
Two things: a responder roster and, optionally, a check-in schedule. A shift is “covered” — meaning timed check-ins arm automatically when a worker clocks in — only when a responder roster resolves for that shift’s site, team, or specific shift. Without a roster, check-ins will not arm, and a worker’s SOS will route to the break-glass safety-admin broadcast instead of a named responder ladder. You can also create a check-in schedule for a site or team to override the tenant default cadence. If you skip the schedule, check-ins use your tenant’s default interval and grace window (set in Settings).
Who can manage rosters, schedules, and settings?
Settings are restricted to admins and Lone Worker app admins. Rosters and check-in schedules follow the Who Can Manage Rosters & Escalation Policy setting, which defaults to Admins only. Changing it to Any user opens roster and schedule management to all members. Analytics are available to anyone who can manage rosters.
Permissions and access
Why can’t some employees see the Lone Worker app?
The app must be both enabled and licensed for your business, and accessible to the employee. If you use Access Management to restrict the app to specific groups, employees outside those groups are blocked on both the web and the API. Check the app’s access settings in your Apps Marketplace.
Who can see which alerts on the dashboard?
Admins and Lone Worker app admins see every alert across the business. Everyone else sees only their own alerts plus alerts on rosters they belong to as a responder. This scope also applies to the Alerts list and the CSV export. The dashboard’s active-alert table shows who has a live SOS or overdue check-in, so it is never served business-wide to a regular member.
Day-to-day
Which roster applies when a worker triggers an SOS or misses a check-in?
The most specific active roster wins: a roster scoped to the worker’s exact shift is checked first, then one scoped to their team, then one scoped to their site. If nothing resolves, the alert routes to a break-glass broadcast — every business admin is notified over push, SMS, and voice. That fallback is always on; a missing roster never swallows an alert.
What happens when a worker misses a check-in?
If a worker does not tap “I’m safe” before the due time plus the grace window elapses, the check-in is marked missed and an alert is raised automatically. That alert climbs the responder ladder exactly like an SOS. No one has to monitor a board — the system detects misses every minute.
Can a worker cancel their own SOS?
Yes, but only as a false alarm. A worker can resolve their own alert with the False alarm outcome. They cannot acknowledge it — acknowledgement must come from a different responder, because self-acknowledgement would silently stop the escalation ladder. Responders and admins can resolve an alert with any outcome: Safe, False alarm, or Incident.
What happens when I resolve an alert as “Incident”?
A note is required. If the Open a Safety Hub Incident setting is on (on by default), resolving as “Incident” automatically creates a Safety Hub incident record. Floor-issue alerts produce an equipment-failure incident; all other trigger types produce a security incident. The Safety Hub handoff is best-effort — if it fails, the alert still resolves and the failure is logged.
How do wearable and IoT device alerts work?
Devices (RFID badge presses, push-to-talk panic buttons, line sensors) POST events to a signed webhook endpoint. Each event must be signed with the HMAC-SHA256 secret configured on the wearables integration. The device event is attributed to a worker by badge ID; if no badge matches, it falls back to the integration’s configured fallback user. Events with neither a matching badge nor a fallback user are rejected. Accepted events raise an alert on the same responder ladder, acknowledgement flow, and audit trail as a phone-raised SOS or floor issue.
When something looks wrong
I tapped SOS and nothing happened — what’s going on?
If you already have an active SOS, a second tap is blocked to prevent restarting the escalation ladder from tier 1. You should see a message confirming your SOS is already active. If you see an error instead, the alert could not be saved — call your local emergency number if it is an emergency. Location capture is best-effort: a missing or denied location permission does not block the SOS.
My check-in keeps saying “Are you safe?” even after I answered
The “I’m safe” button is always visible while you have an armed check-in, even when it is not yet due. The prompt text (“Are you safe? Due by…”) clears the moment your answer is recorded, but the button stays so you can confirm safety any time. If the prompt text reappears quickly, your site or team may have a short check-in interval — ask your admin to check the schedule.
Check-ins are not arming for workers who are on shift
Three things must all be true for a check-in to arm: the Lone Worker app is enabled for your business, the worker has clocked in (an active attendance record exists), and a responder roster resolves for the shift’s site, team, or shift. If any is missing, no check-in is armed. The most common cause is a missing roster — create one scoped to the site or team and check-ins will start arming on the next clock-in.
The dead-man’s switch fired — what does that mean?
It means an alert climbed every tier of the responder ladder and no one acknowledged it. The dead-man’s switch broadcasts to every business admin over push, email, SMS, and voice. It is non-suppressible — no setting can turn it off. Intervene immediately: open the alert in Lone Worker, acknowledge it, and resolve it. If no roster was configured, the break-glass reached your admins directly.
Licensing and limits
Does Lone Worker require a licence?
Yes. An admin enables and licenses the app from the Apps Marketplace. Enabling the app does not start check-ins on its own — a responder roster must also be configured before any shift is covered.
What are the configurable ranges and limits?
| Setting | Default | Allowed range |
|---|---|---|
| Check-in interval | 60 minutes | 5–480 minutes |
| Check-in grace window | 10 minutes | 1–120 minutes |
| Acknowledgement timeout per tier | 120 seconds | 30–1,800 seconds |
| Notification channels per tier | Push, SMS | Push, SMS, Voice (any combination) |
| Floor-issue / SOS note | — | Up to 280 characters |
| Alert audit-trail CSV export | — | Up to 10,000 rows per export |
| Stale armed check-in cutoff | 24 hours | Fixed (armed check-ins more than 24 hours past due are cancelled without raising an alert) |
| Escalation driver cadence | Every minute | Fixed |
| Missed-check-in detector cadence | Every minute | Fixed |
| Check-in scheduler cadence | Every 5 minutes | Fixed |
More help
- Lone Worker Overview
- Ask AI — the assistant answers Lone Worker questions from these articles.