Chapter 1 · Incidents, near misses and observations
Reporting, investigating and learning
A safety record is only useful if people report, if someone finds out why, and if the fix actually changes the work. This chapter says what the EHS module replaces, how an incident or near miss is captured from a phone, how severity and potential are kept apart, and how an investigation ends in actions ranked by the hierarchy of controls.
20 min8 incident types5 investigation methods5 levels of control
By the end of this chapter you can
- Say what the EHS module replaces, what it leaves to other modules, and which standards it is measured against.
- Report an incident or near miss with actual and potential severity, and explain the SIF potential flag.
- Choose an investigation method and class each corrective action by the hierarchy of controls.
What the EHS module does
The EHS module prevents harm and proves compliance. It captures incidents and near misses, investigates them, produces the OSHA injury and illness records, runs risk assessments and permits to work, controls lockout/tagout, manages chemicals and safety data sheets, tracks environmental permits and waste, and controls changes, contractors and visitors. It replaces the EHS software a business usually pays for: the module specification names Intelex, Cority, Enablon, VelocityEHS, Sphera, Benchmark Gensuite, EHS Insight, Vector EHS and SafetyCulture. Vendor pages describe the same core: incident management with notifications and investigation [3][4], plus the wider feature set a buyer expects [5].
It sits on the shared spine, so people, sites and equipment come from the core tables (core_person, core_site, core_equipment) and follow-up uses the core action item engine. Every table in the module starts with ehs_.
| In the module | Left to another module |
|---|---|
| Incidents, near misses, investigations, OSHA recordability and logs | Inspection execution: reuses the digital forms of M01 |
| Observations, hazard reports and leading indicators | Safety training records: M07 |
| JSA and JHA risk assessments, permits to work, lockout/tagout | Enterprise ESG reporting suites: a later wave of the catalogue |
| Chemical inventory and safety data sheets, environmental permits, waste, basic greenhouse gas | |
| Management of change, contractors and visitors |
Reporting from a phone, with the option to stay anonymous
Most reports are made at the place the event happened, by the person who saw it, on a phone. The module therefore takes a report in seconds: what happened, where, a photo, and who reported it unless the person chooses to stay anonymous (the anonymous flag on ehs_incident). A report that is slow or exposes the reporter is a report that does not get made.
The incident type is one of eight: injury or illness, near miss, property damage, environmental release, vehicle, fire, security, or first aid only. A near miss is an event that did no harm but could have. It is the cheapest lesson a site can learn, which is why the module counts near misses as a key measure in chapter 4.
Actual severity and potential severity
An incident has two severities. severity_actual is what happened: none, minor, moderate, serious, major or fatal. severity_potential is what could reasonably have happened: the same ladder without "none". A worker who ducks as a loose load swings past has severity_actual none, and may still have a potential of fatal.
The sif_potential flag marks an event that could have led to a serious injury or a fatality (SIF), whatever actually happened. Filtering for it lets a safety lead spend investigation time on the events with the worst potential, not only on the ones that injured someone. Immediate notifications go out by severity; who is told at each level is a rule the business sets, not something the module guesses.
Observations and hazards
Not everything is an incident. The ehs_observation table holds five kinds of observation: safe act, unsafe act, unsafe condition, hazard and good catch. Each can carry a risk rating (low, medium, high, critical) and a status (open, actioned, closed). A high-risk observation publishes the event ehs.observation.high_risk. Observations are leading indicators: they show where harm could happen before anyone is hurt, and they are counted per 100 employees per month in chapter 4.
Investigating: finding the cause, not the culprit
An ehs_investigation belongs to an incident. It records the method (five why, fishbone, causal factor, a TapRooT-style method, or other), a timeline, the root causes, the contributing factors and the findings. The investigation is approved with an electronic signature. The incident's investigation lead (investigation_lead_id) is a named person.
- Five why: ask why of each answer until you reach something the business can change. Stop when the answer is a process or a design, not a person's carelessness.
- Fishbone: sort possible causes under headings such as people, method, machine, material and environment, then test each against the facts.
- Causal factor: lay the events on a timeline and find the conditions that, if absent, would have prevented the outcome.
Vendor guidance on investigation software describes the same elements: team, timeline, root cause and tracked actions [4]. A good timeline is built from what people saw and did, in order, before any cause is written down.
Actions, ranked by the hierarchy of controls
Every corrective action is classed by its control type: elimination, substitution, engineering, administrative or personal protective equipment (PPE). The order matters. Removing the hazard beats guarding it, which beats a procedure, which beats a pair of gloves, because each step down depends more on a person getting it right every time.
You need: Your current EHS tool or incident log, and the person who looks after safety records
Work with categories and counts only. Do not copy a worker's name, body part, diagnosis or photo into your notes, the repository or a chat with an AI agent. Use one near miss, one injury case and one observation.
Outcome: Three real records classified by the ehs_ tables that would hold them, a near miss with actual and potential severity, and two actions ranked by the hierarchy of controls.
Knowledge check
A load swings past a worker and nobody is touched. Which record fits best?
Knowledge check
Which corrective action is the strongest on the hierarchy of controls?
References
- OSHA: Injury and illness recordkeeping and reporting requirements. https://www.osha.gov/recordkeeping
- ISO 45001:2018 Occupational health and safety management systems. https://www.iso.org/standard/63787.html
- VelocityEHS: incident management capability sheet. https://www.ehs.com/wp-content/uploads/2024/07/VelocityEHS_Capability-Sheet_Incident-Management.pdf
- Vector Solutions: incident investigation software. https://info.vectorsolutions.com/incident-investigation-software
- EHS Insight: key features to look for in EHS software. https://www.ehsinsight.com/blog/key-features-to-look-for-in-ehs-software
Chapter 2 · Recordkeeping under 29 CFR 1904
OSHA records and the rates they feed
The OSHA injury and illness log is a legal record, and it is also health information. This chapter walks the recordability decision, shows how the 300, 300A and 301 are produced from recorded cases, keeps injury detail behind the EHS role, and works out the two rates every safety report quotes.
25 min3 OSHA forms5 years of retention200,000-hour base
By the end of this chapter you can
- Walk the three recordability questions and keep the reasoning on the case.
- Say what the 300, 300A and 301 hold, how long they are kept, and what the privacy case rule does to the 300.
- Calculate TRIR and DART from cases and hours worked, and say who may read an injury case.
The records OSHA asks for
29 CFR 1904 sets out how employers record and report work-related injuries and illnesses [1][2]. Employers with partial exemptions, such as some small businesses and some low-hazard industries, should read sections 1904.1 and 1904.2 of the rule to see whether they are covered. The module's job is to hold the case data once and generate the forms from it.
| Form | What it is | Produced from |
|---|---|---|
| Form 300 | The log: one line per recordable case in the year | ehs_injury_case rows where recordable is true |
| Form 300A | The annual summary: totals for the year, certified by a company executive and posted | Case counts plus ehs_osha_annual_summary (average employees, total hours, certification, posting) |
| Form 301 | The incident report for one case | The incident and its injury case |
The summary is posted in the workplace for part of each year and can be submitted electronically through OSHA's Injury Tracking Application (ITA), so the module stores when each step happened: certified_at, posted_at and ita_submitted_at. Records are kept for five years after the year they cover (1904.33). A cut-over to a new tool therefore has to keep every old case reproducible with its original determination.
Is it recordable? Three questions in order
The recordability wizard is built from the rule. An analyst answers three questions, and a no at any step ends the check.
- Work-related. Did an event or exposure at work cause or contribute to the condition, or significantly aggravate an existing one (section 1904.5)?
- New case. Is it a new injury or illness, not a continuing one (section 1904.6)?
- General recording criteria (section 1904.7). Does it result in death, days away from work, restricted work or job transfer, medical treatment beyond first aid, loss of consciousness, or a significant injury or illness diagnosed by a physician or other licensed health care professional?
The result is stored on the case: recordable (true or false), outcome (death, days away, restricted or transfer, other recordable, or not recordable) and recordability_rationale, a JSON record of the answers. A case judged not recordable still keeps its rationale, so a later reviewer can see the reasoning. The wizard asks; a trained person decides.
The case record
ehs_injury_case holds the person (person_id, or non_employee_name for a visitor or contractor), job title, body part, nature of injury, treatment (first aid, medical treatment, hospitalized, emergency room), the outcome and the days away and days restricted, with a return-to-work date and an OSHA case number.
Injury detail is health information
A body part and a diagnosis are health information about a named person. The module therefore splits its data in two tiers. What happened, where and how severe sits in general-access tables such as ehs_incident, so a supervisor can see an incident and act on it. The injury case sits behind field-level row-level security for the EHS role only. Row-level security means the database refuses to return the rows to anyone outside the role before the application is even asked.
Section 1904.29 requires an employer to keep the name off the log for a privacy concern case, such as an injury to an intimate body part or a sexual assault [1]. The log shows "privacy case" in the name column and the employer keeps a separate, confidential list that links each case number to the name. The module stores the flag on the case (privacy_case) and substitutes the words when it generates the 300.
Two rates, worked by hand
Safety reports quote two rates. TRIR (total recordable incident rate) is recordable cases times 200,000, divided by hours worked. DART (days away, restricted or transferred) is the number of those cases that involved days away, restricted work or transfer, times 200,000, divided by hours worked. The 200,000 is the hours of about 100 full-time workers over a year, so the rate reads as cases per 100 workers and different-sized sites can be compared. The specification also lists LTIR (lost-time incident rate), which counts only the cases with days away from work, times 200,000, divided by hours worked. This course shows TRIR and DART on the page and leaves LTIR as a later addition, because it is the same count taken from the days-away cases alone.
Check the rate by hand every time you build it. If your hand count of a seeded set of cases gives 3.2 and the dashboard says 3.1, one of them has the wrong hours or the wrong set of cases. The definition of done for this module includes that the 300 and 300A generated from seeded cases match a form completed by hand.
You need: Your own EHS tables or sandbox, a made-up case, and two test users: one in the EHS role and one outside it
Use invented data only: a fictional worker, a fictional date. Never enter a real person's details in a learning exercise.
Outcome: One recordable and one non-recordable case with their reasoning kept, a privacy case shown without a name on the 300, a refused read by a non-EHS user, and a TRIR you worked out yourself.
Knowledge check
A case is judged not recordable. What should the module keep?
Knowledge check
Why is injury detail kept in a separate table limited to the EHS role?
References
- OSHA: Part 1904 Recording and reporting occupational injuries and illnesses. https://www.osha.gov/laws-regs/regulations/standardnumber/1904
- eCFR: 29 CFR Part 1904. https://www.ecfr.gov/current/title-29/subtitle-B/chapter-XVII/part-1904
- VelocityEHS: OSHA recordkeeping. https://www.ehs.com/?p=20045
- OSHA: 1904.7 General recording criteria. https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.7
- OSHA: 1904.33 Retention and updating. https://www.osha.gov/laws-regs/regulations/standardnumber/1904/1904.33
Chapter 3 · Controlling the work before it starts
Risk assessments, permits and lockout
The most dangerous work is the work done on live equipment. This chapter covers the job safety analysis that finds the hazards, the permit that authorises risky work, and the lockout/tagout procedure that isolates energy. The point of the chapter is that these records must stop the work, not just describe it.
25 min7 permit types9 energy types3 lockout steps recorded
By the end of this chapter you can
- Build a job safety analysis with a risk score before and after controls.
- Follow a permit through its statuses and say what each signature means.
- Explain how a lockout application is verified and how it blocks a work order.
A job safety analysis
A job safety analysis (JSA, also called a JHA) breaks a task into steps, finds the hazard in each, and decides the controls. The module stores the assessment in ehs_risk_assessment (a number, a type, a revision, a status and a review date) and each step in ehs_risk_step: the task step, the hazard, the consequence, likelihood and severity, the risk score, the controls with their control type, and the residual likelihood, severity and score after the controls.
The sequence is: score the hazard as it is, add controls from the top of the hierarchy down, score again, and approve only when the residual score is one the business accepts. The assessment is approved with an electronic signature, carries a review date, and moves to due review when that date passes. The assessment status runs draft, approved, due review and superseded.
A permit to work
Some work is risky enough that nobody may start until someone with authority has checked it. A permit to work records that check. The module covers seven permit types: hot work, confined space, line break, electrical, working at height, excavation and general. Hot work is governed in the United States by OSHA 1910.252 [3], and a permit-required confined space by 1910.146 [2].
- Requested by a named person (requested_by), for a window (valid_from to valid_to), with the hazards and precautions written down.
- Approved by the issuer, who signs. Active when the receiver, who will do the work, signs. Neither signature is a formality: each says who accepted responsibility for what.
- Gas tests are recorded on the permit where the work needs them, such as for a confined space.
- Suspended if conditions change, then resumed by the supervisor who issued it once the conditions are checked again. Closed only with the close-out signature, and only after any locks have been removed. Expired automatically when valid_to passes.
- Activation depends on the lockout. When a permit has a lockout application, or its procedure requires one, the receiver cannot activate it until the application is verified.
A permit is linked to the CMMS work order it authorises (a soft link, so the work order can live in another module) and to the equipment and area. Activating a permit publishes ehs.permit.activated; closing it publishes ehs.permit.closed.
Lockout/tagout
Lockout/tagout (LOTO) keeps a machine from starting or releasing energy while someone is working on it. OSHA's control of hazardous energy standard, 1910.147 [1], requires energy-control procedures, locks and tags, training, and a periodic inspection of the procedure at least once a year. The module holds three things.
| Table | What it holds |
|---|---|
| ehs_loto_procedure | The machine-specific procedure: the equipment, its revision, the energy sources, the date of the last annual inspection, and a status of draft, approved or superseded. |
| ehs_isolation_point | One row per isolation point: the sequence, energy type (electrical, pneumatic, hydraulic, mechanical, thermal, chemical, gravity, stored or radiation), the device, where it is, how to isolate it and how to verify it. |
| ehs_loto_application | One application of the procedure for one job: who applied the locks and when, who verified and when, the lock identifiers, and who removed them and when. |
An application has three statuses: applied (locks are on), verified (someone has tried to start the machine, a try-out, and proved the energy is gone) and removed (the locks are off). The events ehs.loto.applied and ehs.loto.removed are published when those steps happen.
Records that stop the work
A permit or a lockout record that nobody checks is paperwork. The refusal is therefore made in the database, at the moment the status changes: a rule on the work order table (a trigger, code the database runs by itself) refuses the move to in progress while the lockout application is not verified. The same rule applies to a permit-controlled job: the work the permit authorises cannot start unless the permit is active. An event cannot do this job, because it is published after the change has already happened. The module uses cmms.work_order.status_changed afterwards, to record the change and to notify people. This course does not build that consumer; it relies on the database refusal. (The specification also lists three more events the module consumes, from forms, shift handover and training; this course defers them.)
You need: Your own EHS and maintenance tables, one made-up piece of equipment, and a made-up work order
Use a fictional machine and fictional lock numbers. The point is to see the system refuse, so do not skip the step where you try to break the rule. You play every role in turn, so write down which one you are at each step.
Outcome: A refusal you saw yourself, then a permitted start after verification and activation, and a lockout removed and a permit closed with their signatures and times, in that order.
Knowledge check
A work order tries to enter in progress while its lockout application is applied but not verified. What should happen?
Knowledge check
What does the receiver's signature on a permit say?
References
- OSHA: 1910.147 The control of hazardous energy (lockout/tagout). https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.147
- OSHA: 1910.146 Permit-required confined spaces. https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.146
- OSHA: 1910.252 General requirements for welding, cutting and brazing (hot work). https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.252
- Reliability Magazine: best EHS software, permit to work and LOTO linked to maintenance. https://reliamag.com/guides/best-ehs-software/
Chapter 4 · The rest of the module, its measures and the move
Chemicals, change and cutting over
This chapter finishes the module: approved chemicals with their safety data sheets, environmental permits and waste, management of change, and contractors and visitors. It then gives the five measures the module reports, the migration rules for leaving the old tool, and the tests that say the module is done.
25 min19 ehs_ tables5 KPIs3 done tests
By the end of this chapter you can
- Say how a chemical is approved, stored and reported, and what the safety data sheet holds.
- Describe management of change, contractor prequalification and the visitor log.
- Calculate the module's five measures, and apply the migration rules and the three done tests.
Chemicals and safety data sheets
OSHA's Hazard Communication standard (1910.1200), aligned to the Globally Harmonized System (GHS), requires labels and safety data sheets (SDS) so workers know what they handle [1]. The module keeps an approved list: ehs_chemical holds the product, the manufacturer, the CAS numbers, the attached SDS with its revision date, the GHS hazards, the signal word (danger, warning or none) and the PPE. Its approval status is requested, approved, restricted or banned. In the specification the SDS attachment is an optional column, so requiring it before approval is a rule of this course's design, and a good one: a chemical list with no safety data sheet tells a worker nothing.
Where each chemical is, and how much, goes in ehs_chemical_inventory: the storage location, the quantity and its unit, the container count, the maximum quantity and the date it was last verified.
Under the Emergency Planning and Community Right-to-Know Act, section 312, facilities that store hazardous chemicals above thresholds report an inventory each year, known as Tier II; section 313 covers releases reported to the Toxics Release Inventory [3]. The module aggregates the inventory by site and by chemical so the report is a query, not a hunt. Check the current thresholds on the EPA page; the course does not state them.
Environmental records and waste
- ehs_env_permit: a permit from an agency for a medium (air, water, stormwater, waste or other), with its limits, issue date and expiry date.
- ehs_env_measurement: a monitoring result against a limit, with the parameter, value, unit, time and an
exceedanceflag. An exceedance is the number that needs a report. - ehs_waste_shipment: a hazardous waste manifest: the manifest number, waste codes, quantity, transporter, treatment, storage or disposal facility, ship date and the date the signed copy returned. Federal manifests move through EPA's e-Manifest system [4]. A missing returned copy is a finding.
- Basic greenhouse gas: an inventory of scope 1 (direct emissions the business controls) and scope 2 (purchased electricity and heat) under the GHG Protocol Corporate Standard [5].
ISO 14001:2015 is the environmental counterpart of ISO 45001 [2]: a management system standard for the business to manage its environmental responsibilities.
Management of change, contractors and visitors
Management of change (MOC) asks the question before the work: what could this change break? An ehs_moc record holds the change type (temporary, permanent or emergency), whether it is covered by Process Safety Management, the description, the hazard review, and a status that runs draft, review, approved, implemented, closed or rejected. For a covered process, OSHA's PSM standard (1910.119) requires a management of change procedure and a pre-startup safety review (PSSR) [6]; the record stores whether a PSSR is required and when it was completed. A temporary change carries an expiry date so it cannot quietly become permanent.
Contractors are prequalified in ehs_contractor_company: a status of pending, approved, conditional, rejected or expired, the insurance expiry date, the experience modification rate (EMR) and the safety program on file. Visitors sign in at a site in ehs_visitor_log with the host, the times, the badge number and a required tick that they received the safety briefing.
Five measures
| Measure | Definition | Comes from |
|---|---|---|
| TRIR | Recordable cases x 200,000 / hours worked | ehs_injury_case, ehs_osha_annual_summary |
| DART rate | Days-away, restricted or transfer cases x 200,000 / hours worked | ehs_injury_case |
| Near-miss to injury ratio | Near misses reported / recordable injuries | ehs_incident, ehs_injury_case |
| Action closure on time | EHS actions closed by their due date / actions due | Core action items |
| Leading indicator rate | Observations per 100 employees per month | ehs_observation |
The first two are lagging: they count harm that has already happened. The last three lead: they show whether the system is reporting, learning and fixing. A rising near-miss to injury ratio, for example, usually means people trust the system enough to report, which is good news. Make the dashboard show leading and lagging measures side by side.
The tables, column by column
The module has nineteen tables, all with the prefix ehs_. Session 2 of the lesson notes builds the first eleven (incidents, injury cases, investigations, observations, risk assessments and steps, permits, lockout procedures, isolation points, applications and the annual summary). The other eight, chemicals, environment, change, contractors and visitors, come in later extensions, but they are listed here so you can see the whole module.
The table below is the full definition: every column the module adds to the standard ones, with its type and whether it is required (marked req). Types are written as in the specification: text, int, num (a decimal number), qty (a quantity), bool, date, ts (a timestamp with time zone), uuid and json (a text format for lists and labelled values, stored in a json column); an arrow means a foreign key to that table. Allowed values are written after a colon and become check constraints. A column marked unique is unique per business. It is what your agent builds from in Session 2.
| Table | Holds | Columns: type, req = required |
|---|---|---|
| ehs_incident | An incident or near miss: what happened, where, when and how severe, and nothing about the body | incident_no text req, unique; incident_type text req: injury_illness, near_miss, property_damage, environmental_release, vehicle, fire, security or first_aid_only; occurred_at ts req; site_id → core_site req; area_equipment_id → core_equipment; location_text text; description text req; reported_by → core_person; reported_at ts req; anonymous bool; severity_actual text req: none, minor, moderate, serious, major or fatal; severity_potential text: minor, moderate, serious, major or fatal; sif_potential bool; status text req: reported, under_investigation, actions_open or closed; investigation_lead_id → core_person |
| ehs_injury_case | The OSHA case record. Restricted to the EHS role | incident_id → ehs_incident req; person_id → core_person; non_employee_name text; job_title text; body_part text; nature_of_injury text; treatment text: first_aid, medical_treatment, hospitalized or emergency_room; outcome text req: death, days_away, restricted_or_transfer, other_recordable or not_recordable; recordable bool req; recordability_rationale json; privacy_case bool req; osha_case_no text; days_away int; days_restricted int; return_to_work_at date |
| ehs_investigation | An investigation with its causal analysis | incident_id → ehs_incident req; method text req: five_why, fishbone, causal_factor, taproot_style or other; timeline json; root_causes json; contributing_factors json; findings text; completed_at ts; approved_signature_id → core_e_signature |
| ehs_observation | A behaviour or condition observed: a leading indicator | obs_no text req, unique; obs_type text req: safe_act, unsafe_act, unsafe_condition, hazard or good_catch; observed_at ts req; area_equipment_id → core_equipment; description text req; observer_id → core_person; anonymous bool; risk_rating text: low, medium, high or critical; status text req: open, actioned or closed |
| ehs_risk_assessment | A JSA, JHA or other task risk assessment | ra_no text req, unique; ra_type text req: jsa, jha, task, hira, ergonomic or chemical; title text req; area_equipment_id → core_equipment; job_role_id → core_job_role; revision text req; status text req: draft, approved, due_review or superseded; review_due date; approved_signature_id → core_e_signature |
| ehs_risk_step | One task step with its hazard, controls and residual risk | risk_assessment_id → ehs_risk_assessment req; step_no int req; task_step text req; hazard text req; consequence text; likelihood int req; severity int req; risk_score int; controls text; control_type text: elimination, substitution, engineering, administrative or ppe; residual_likelihood int; residual_severity int; residual_score int; ppe json |
| ehs_permit | A permit to work | permit_no text req, unique; permit_type text req: hot_work, confined_space, line_break, electrical, working_at_height, excavation or general; work_order_ref uuid, a soft link to cmms_work_order; equipment_id → core_equipment; area_equipment_id → core_equipment; requested_by → core_person req; issuer_id → core_person; receiver_id → core_person; valid_from ts req; valid_to ts req; status text req: requested, approved, active, suspended, closed, cancelled or expired; hazards json; precautions json; gas_tests json; issuer_signature_id, receiver_signature_id and closeout_signature_id → core_e_signature |
| ehs_loto_procedure | The energy control procedure for one machine | equipment_id → core_equipment req; procedure_doc_ref uuid, a soft link to doc_controlled_document; revision text req; energy_sources json req; last_annual_inspection date; status text req: draft, approved or superseded |
| ehs_isolation_point | One energy isolation point in a procedure | loto_procedure_id → ehs_loto_procedure req; seq int req; energy_type text req: electrical, pneumatic, hydraulic, mechanical, thermal, chemical, gravity, stored or radiation; device text req; location_text text; isolation_method text req; verification_method text req |
| ehs_loto_application | The locks applied, verified and removed for one job | loto_procedure_id → ehs_loto_procedure req; permit_id → ehs_permit; work_order_ref uuid, a soft link to cmms_work_order; applied_by → core_person req; applied_at ts req; verified_by → core_person; verified_at ts; lock_ids json; removed_by → core_person; removed_at ts; status text req: applied, verified or removed |
| ehs_osha_annual_summary | The establishment's annual summary (300A) and its certification | site_id → core_site req; year int req; avg_employees num req; total_hours num req; certified_by → core_person; certified_at ts; posted_at date; ita_submitted_at date |
| ehs_chemical (later) | An approved chemical product with its SDS | product_name text req; manufacturer_party_id → core_party; cas_numbers json; sds_attachment_id → core_attachment; sds_revision_date date; ghs_hazards json; signal_word text: danger, warning or none; ppe json; approval_status text req: requested, approved, restricted or banned |
| ehs_chemical_inventory (later) | A chemical's quantity at one storage location | chemical_id → ehs_chemical req; storage_location_id → core_storage_location req; qty qty req; uom_id → core_uom req; container_count int; max_qty qty; last_verified_at ts |
| ehs_env_permit (later) | An environmental permit with limits | permit_no text req, unique; agency text req; medium text req: air, water, stormwater, waste or other; limits json; issued_at date; expires_at date |
| ehs_env_measurement (later) | A monitoring result against a limit | env_permit_id → ehs_env_permit; parameter text req; value num req; uom_id → core_uom; measured_at ts req; limit_value num; exceedance bool |
| ehs_waste_shipment (later) | A hazardous waste manifest | manifest_no text req, unique; waste_codes json req; qty qty req; uom_id → core_uom req; transporter_party_id → core_party; tsdf_party_id → core_party; shipped_at date req; returned_copy_at date |
| ehs_moc (later) | A management of change record | moc_no text req, unique; title text req; change_type text req: temporary, permanent or emergency; psm_covered bool req; description text req; hazard_review json; pssr_required bool; pssr_completed_at ts; expires_at ts; status text req: draft, review, approved, implemented, closed or rejected; approved_signature_id → core_e_signature |
| ehs_contractor_company (later) | A contractor's prequalification | party_id → core_party req, unique; prequal_status text req: pending, approved, conditional, rejected or expired; insurance_expires_at date; emr num; safety_program_attachment_id → core_attachment |
| ehs_visitor_log (later) | A visitor sign-in with safety briefing | visitor_name text req; company_text text; host_id → core_person; site_id → core_site req; signed_in_at ts req; signed_out_at ts; briefing_acknowledged bool req; badge_no text |
Two things to notice. The soft links (work_order_ref, procedure_doc_ref) are plain uuid columns, because the tables they point at live in other modules that may not be installed. And the injury details (job_title, body_part, nature_of_injury, treatment) appear only in ehs_injury_case, never in ehs_incident.
Roles and screens
The specification names one role, the EHS role. The five roles and five screens below are this course's design for it, written into the Role and Exposure Matrix in Session 3 and used in Session 4.
| Role | What the job needs |
|---|---|
| Site worker | Everyone who signs in. Reports an incident, near miss or hazard; reads approved risk assessments and lockout procedures; works their own actions |
| Authorized employee | Adds to the site worker. Requests permits to work, receives them, applies and removes locks |
| Supervisor | An area supervisor. Triages reports, leads the investigation of an event that did not injure anyone, drafts risk assessments, issues, suspends and resumes permits |
| EHS specialist | The EHS role. The only role that reads ehs_injury_case; decides recordability, generates the 300, 300A and 301, approves risk assessments |
| Manager | The site manager. Sees counts and rates, never an injury case; approves investigations and certifies the 300A |
| Screen | Who opens it | What it does |
|---|---|---|
| /ehs/report | Every signed-in role | The phone report screen: an incident, near miss, hazard or good catch in seconds, with a photo, anonymously if the reporter wishes |
| /ehs/investigate | Supervisor, EHS specialist, manager | Incidents by status with their lead and actions; the investigation form |
| /ehs/permits | Authorized employee, supervisor, EHS specialist, manager | Permits in the area and the isolation points of the machine's procedure |
| /ehs/osha | EHS specialist only | The recordability wizard and the 300, 300A and 301, which show names |
| /ehs/kpi | Manager and EHS specialist | The five measures, and the 300A certification panel for the manager, which shows totals only |
Moving off the old tool
- Export incidents, injury cases and actions from the old tool and keep the files untouched as the original.
- Load incidents and cases with their original determinations: do not re-run the wizard on history. The OSHA logs must stay reproducible for the five-year retention period.
- Load cases only into the restricted ehs_injury_case table. Check no health detail landed in a general-access table.
- Run the old and new tool side by side for a short, fixed period, and compare the 300 log line for line.
- Cancel the subscription only when the export is safe and the new logs match. Read the contract for the notice period before relying on a date.
Done means testable
- The 300 and 300A generated from seeded cases match a form completed by hand.
- A user outside the EHS role cannot read injury case fields, proved by a row-level security test.
- A work order cannot enter in progress while its lockout application is not verified.
You need: A spreadsheet, one real product label or SDS you are allowed to use, and the names of two places the product is stored
The chemical tables are not built in this course: Session 2 builds eleven tables and leaves ehs_chemical and ehs_chemical_inventory for a later extension. So this is a design exercise. You lay out rows in a spreadsheet, using the columns in the table earlier in this chapter, and check the arithmetic yourself. Use a common product such as a cleaning fluid, and copy the hazard words and revision date from its SDS, not from memory.
Outcome: A spreadsheet with an approved chemical and two inventory rows laid out in the columns of the module's chemical tables, a site total you checked by hand, and a list of chemicals with no SDS date. The tables themselves come in a later extension.
Knowledge check
Which of these best describes a leading indicator?
Knowledge check
Why are old OSHA cases migrated with their original determinations?
References
- OSHA: 1910.1200 Hazard communication. https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.1200
- ISO 14001:2015 Environmental management systems. https://www.iso.org/standard/60857.html
- EPA: Emergency Planning and Community Right-to-Know Act (EPCRA). https://www.epa.gov/epcra
- EPA: e-Manifest, the hazardous waste electronic manifest system. https://www.epa.gov/e-manifest
- GHG Protocol: Corporate Standard. https://ghgprotocol.org/corporate-standard
- OSHA: 1910.119 Process safety management of highly hazardous chemicals. https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119
Chapter 5 · 12 questions · 80% passes
Final assessment
Twelve questions across the element. Score 80% (10 of 12) to pass. Your LMS records your score and each answer; you can review the chapters and try again.
15 min12 questions≈ 15 minutesRetake allowed
Your result
CivOps AI Academy
Safety (EHS): Incidents, OSHA Records, Permits and Lockout/Tagout
Element M11 complete · Learner
Your LMS records this completion. For the CivOps Foundation certificate, finish the Foundation Course at https://civops.io/learn.