Safety Hub FAQ
Answers to common setup and operating questions about Safety Hub.
For what the app is and how to set it up from scratch, see the
Safety Hub Overview.
Setup
Do I have to configure anything before Safety Hub starts working?
Mostly no. Once an admin enables the app, the Incidents, Observations, Toolbox Talks, Certifications, Emergency Alerts, Contractor Pre-qualification, Permits to Work and OSHA Compliance (US) modules are all on; only WCB Compliance (Canada) is off. Three things do stay silent until a second piece exists: certification rosters need both a requirement and a source of held certifications (certified skills or Training Connect records); contractor permits cannot be issued until the contractor has a current pre-qualification (the gate is on by default); and autonomous safety operations need both the Enable Autonomous Safety Operations toggle (off by default) and a trust level in the AI Console.
Why does the public safety portal say it is not available?
The /safety portal needs Safety Hub enabled for your business and the Safety Hub portal switched on in the Portals app; if either is missing, visitors see a branded “not available” page. Safety Hub’s own Settings → Public Hazard Portal card can only close the portal — re-opening it is done in Portals. Only knowledge-base articles marked visible in the public portal are published there.
Permissions and access
Who can see and do what in Safety Hub?
Three tiers. Members (anyone the app is published to) report incidents and observations, see their own submissions, certifications, talks, assigned corrective actions and permits, read the knowledge base, and respond to alerts. Managers (platform Manager or above, or a Safety Hub app admin) get the Team zone: incidents and investigations at their sites, the corrective-action register with Complete and Verify, campaigns, talks, certification rosters, permit issue and suspend, contractor assessments and decisions, OSHA/WCB, analytics and the alert composer. Admins (platform Admin or above, or a Safety Hub app admin) add Settings, Certification Requirements, Alert Templates, sample data, closing the portal, deleting incidents and observations, and the AI Console. Two capability pickers under Settings → Who Can Do What widen this: Who can see safety records at every site? (default: app admins) and Who can send an emergency alert? (default: managers and admins).
Why can’t a manager see incidents at another site?
A plain manager sees safety records only at the locations they manage; an incident at another site, or with no location at all, is invisible to them. Admins and Safety Hub app admins see every site. To give a safety committee cross-site visibility without making them admins, set Who can see safety records at every site? to a specific group.
Who can authorise a permit to work?
A manager for the permit’s site — never the person who requested it. Managers granted Who can see safety records at every site? can authorise anywhere; a site-scoped manager only sees and issues permits at their own sites (a permit with no site is open to any manager). The authoriser opens the Requested permit, confirms every precaution for its type and clicks Confirm precautions and issue permit; precaution ticks are writable by managers only, and a manager who requested a permit must hand it to another manager to issue. The permit records who issued it and when. Either the requester or the authoriser can close it; suspending and resuming are manager actions.
Day-to-day
How do I get a permit for hot work?
Open My Permits, click Create Draft Permit, choose Hot work, describe the work, set the site, the Work starts and Work ends window (no more than 14 days) and the contractor if external, and tick the hazards you have identified. Save, then click Request approval. A manager confirms the six hot-work precautions and issues it; you will see it as Issued or Active on My Permits and on your phone.
Why was my permit refused?
A permit is only issued from Requested, and the refusal names the reason: you requested it yourself, the work window has already ended, one or more precautions are not yet confirmed, or the contractor has no current pre-qualification. Fix the cause — adjust the window, have the authoriser tick the remaining precautions, or have the contractor assessed under Team → Contractors — and request approval again.
What happens when a permit runs past its end time?
Nothing is flipped automatically at first. The board shows it as Past end time and the requester and authoriser are nudged; an hourly check had already warned them when the permit was within 1 hour of ending. If nobody closes it, the same check marks it Expired 24 hours after the end time (a suspended permit nobody resumed expires the same way), tells the requester and authoriser, and the record reads “Passed its end time without close-out.” Once issued, a permit’s type, window, site and contractor are frozen — cancel it and request a new one rather than editing. Close permits on time: tick Work complete or stopped; area inspected and left safe and click Close permit.
Why can’t I close this permit from my phone?
You can close a permit from mobile, but only if you are its requester or its authoriser, and only while it is Issued or Suspended. The close-out also requires the area inspected and left safe box to be ticked. Creating, editing, issuing and suspending a permit are desktop-only; mobile shows the permit list, a read-only checklist and the close-out.
What does a “conditional” pre-qualification mean?
Conditional is an approval with strings attached: the reviewer records the conditions (for example, a rescue plan on file before any work at height) and a Valid until date, which defaults to 12 months out. For the permit gate, Conditional counts as current exactly like Approved until Valid until passes. After that date the assessment shows Lapsed, permits for that contractor are refused, and a daily check moves it to Expired.
How is a contractor’s score and risk tier worked out?
The 15 questions carry weights of 1 to 3 points; the score is the points earned by “Yes” answers as a percentage of the points available, with “N/A” removed from the denominator. The suggested tier is Low at 85% or more, Medium at 60% or more, otherwise High — except that a “No” on any 3-point Performance or Insurance question (EMR at or below 1.0, no fatalities, general liability, workers’ compensation) caps the suggestion at High regardless of score. The reviewer chooses the final tier on the decision form.
Who is notified when a high or critical incident is reported, and how?
Site managers, up to 10 administrators, up to 5 safety administrators (with Add Safety Administrators to High-Severity Incident Alerts on) and any group named in Route incident and hazard alerts to this group are notified in-app, by push and by email. High and Critical incidents also run the escalation cascade: in-app and push first, then SMS and email, then voice. An investigator is assigned at once when Auto-assign Investigators is on. All of this is gated by Alert Site Managers and Administrators on New Incidents, and the email leg by Enable Email Notifications.
Why do the OSHA TRIR and DART rates show as an estimate or blank?
Safety Hub does not track hours worked. The OSHA dashboard and the 300A summary therefore leave TRIR, DART and total hours blank, while the Analytics page shows an estimated rate using active users × weekdays × 8 hours. Recordable counts, DART cases and days away or restricted are exact; only the rates are estimated.
Why does my tenant see no Canadian WCB screens?
Enable WCB Compliance (Canada) is off by default; turn it on under Settings → Compliance and the WCB (Canada) entry appears in the Team zone. Reportability is auto-determined for injuries when Auto-determine WCB Reportability is on. Province rules exist for Ontario, British Columbia, Alberta, Manitoba and Saskatchewan only, and the province is read from the incident location’s state (or Default WCB Province); an incident with no province is flagged but gets no WCB log entry.
Why hasn’t the weekly safety summary arrived?
Send Weekly Safety Summary is off by default. Turn it on under Settings → Notifications and every active manager and admin receives the digest by email on Monday at 08:00 UTC; Enable Email Notifications must also be on, because the summary is email-only.
Someone reported a hazard anonymously on the portal — where does it go?
It depends on the report type. Injury or Illness and Property or Equipment Damage become an anonymous incident (the title is the first 100 characters of the description). Hazard or Unsafe Condition, Near Miss and Safety Suggestion become a safety observation marked as coming from the public portal, and suggestions alert managers when Alert on At-Risk, Near-Miss and Portal Suggestions is on. Portal reports carry no photos and no reporter account, and each address may file 5 reports per 10 minutes.
When something looks wrong
Why can’t I see the incident I reported?
Look under Submitted by Me — members do not get the Team zone’s Incidents list, and on mobile the same feed is “Submitted by me”. If you filed the report through the public portal, it is anonymous and not tied to your account, so it never appears there. Managers who cannot see a colleague’s report are usually outside the incident’s site.
I reported an injury but it was rejected because no photo was attached — why?
Require Photos for Injury Incidents is on by default, so an Injury report without at least one photo is refused on both desktop and mobile. Attach a photo (mobile can capture one with the camera) and submit again. The public portal never asks for photos, so a portal report is accepted without one.
Why can’t I close this incident — it says actions still need verification?
Require Effectiveness Verification Before Closing Over Completed Actions (ISO 45001) is on. Every completed corrective action on the incident must be verified by a manager other than its assignee, with notes, before the incident can close; check the register’s awaiting-verification filter. The investigation must also be complete. If the policy does not apply to you, turn the setting off under Settings → Corrective & Preventive Actions (CAPA).
Why isn’t autonomous monitoring flagging stalled investigations?
Check three things. Enable Autonomous Safety Operations is off by default and Enable Safety Hub AI Agent must be on too. In the AI Console, the agent needs a trust level — on Probation (10 actions a day) every action waits for your approval, and three rejections in 30 days force approval again; a paused agent does nothing. It only watches two patterns — investigations untouched for 7 days and Reported High/Critical incidents with no investigator — and it only sends nudges; it never changes records.
Licensing and limits
Does Safety Hub require a licence?
Yes. Safety Hub requires a licence and is disabled until an administrator enables it for the business from the Apps Marketplace. It is never auto-enabled.
Are there limits I should know about?
| Item | Value |
|---|---|
| Permit work window | up to 14 days |
| Permit ending-soon nudge | within 1 hour of end time |
| Permit auto-expire | 24 hours after end time, if not closed |
| Pre-qualification expiry warning | 30 days before Valid until; expired the day after |
| Pre-qualification documents | under 25 MB each |
| Pre-qualification EMR / TRIR | EMR 0 to under 100; TRIR 0 to under 1,000 |
| Suggested tier thresholds | Low at 85% or more, Medium at 60% or more |
| Incident title / description | 3–255 / 10–5,000 characters |
| Days away / days restricted | 0–9,999 |
| Investigation deadline | 1–90 days (default 7) |
| Investigation overdue reminders | daily for 7 days, then weekly, stopping at 90 days |
| Observation description / specific location | up to 5,000 / 255 characters |
| Campaign target / reward points | 1–1,000,000 / 0–1,000,000 |
| Talk duration | 1–1,440 minutes |
| Requirement validity / reminder lead | 1–1,200 months / 1–3,650 days |
| Certification reminder milestones | lead (7–90 days, default 30), then 7 and 1 days; expired notices weekly for 30 days |
| Corrective action due-soon reminders | 7, 3 and 1 days before; overdue escalation stops at 90 days |
| Corrective action description / verification notes | up to 2,000 / 4,000 characters |
| Alert title / body / SMS / voice | 200 / 10,000 / 320 / 700 characters |
| Alert media | up to 4 files; images 10 MB, videos 50 MB |
| Chase-up deadline options | 1, 2, 4, 8, 24 or 72 hours; re-notified every 6 hours for 7 days |
| Check-in note | up to 2,000 characters |
| Muster roster / permit board / contractor register pages | 25 per page |
| Public portal | 5 reports per 10 minutes per address; 120 reads per minute; description 10–5,000, location 255 |
| Similar incidents | 5 results |
| Incident access log | 500 rows per export; kept 7 years |
| Submitted by Me | 500 per source, 20 per page |
| Analytics windows | 7, 30, 90 or 365 days |
| API page size | 25 by default, 100 maximum |
| Autonomous actions per day | 10 (Probation), 50 (Standard), 200 (Trusted) |
More help
- Safety Hub Overview
- Ask AI — the assistant answers Safety Hub questions from these articles.