Safety, and the culture that produces it
Nobody gets blamed
for telling you.
Safety software usually means a filing cabinet with a login — forms nobody fills in, a binder for the auditor, and an incident report written three days late by somebody who was not there.
That is backwards. The things that keep people whole are the small ones: a driver checking the vehicle before they pull out, a technician saying the roof access is worse than the last visit, somebody mentioning the near miss that did not hurt anybody this time.
All of those are thirty seconds of somebody’s day — if the app makes them thirty seconds, and if telling you is never held against them.
The day has a start and an end
Most field software can only think about jobs. So anything that is not a job — the morning check, the break, the incident on the way to the second call — has nowhere to live, and ends up typed into whatever memo box is nearest.
Here, a person can run a procedure that belongs to them rather than to a job. It is a first-class thing in the system, not a workaround: the run is stamped with who, when, and where, and it does not need a work order to exist.
Start of day
Fit to work. Vehicle walk-around, tyres, lights, load secured. Ladder and harness present and not damaged. Photograph anything that is not right, and it goes to somebody before the van moves.
Break and lunch
Recorded because hours matter, and because a day with no breaks in it is a fatigue problem you cannot see until somebody is hurt.
Injury or incident
Reportable in the moment, from the phone that is already in their hand, with photographs, the time and the place captured rather than recalled. Not a form somebody fills in on Thursday.
End of day
Everybody checked out. Anything left unsafe on a site handed over deliberately instead of forgotten. And an honest answer to whether the day went the way it was planned.
Near misses and good catches
A near miss is the cheapest information a company will ever get. Somebody nearly fell, nearly cut through a live conductor, nearly reversed into a bollard — and nothing happened. The cost was zero. The warning was free.
And in most companies it is never written down, because writing it down feels like admitting something.
Under a minute, from the van
What happened, roughly where in the business it sits, how close it came, and what you would do about it. Speak it, type it, or photograph it — a picture of the access ladder says more than a paragraph about the access ladder.
Three kinds, one report
A near miss — nothing happened, this time. A good catch — somebody spotted it before it could. A defect — a process that is quietly wrong every single week. They go in the same place because they are the same signal at different distances from harm.
And it is not only the field
A dispatcher who notices the notification never fires on a Tuesday, a billing clerk who spots that one customer rejects fifteen percent of invoices over a formatting rule nobody documented — same report, same treatment, same credit.
The no-blame rule, and why it is not softness
There is a 110-year-old electrical contractor in York, Pennsylvania called I.B. Abel. Since 2010 they have cut their OSHA incident rate by 400%, all but eliminated lost-time injuries, and hold a 0.00 DART rate and a 0.91 total recordable incident rate — while tripling their workload and growing the company 500%.
They did it by never blaming an employee.
The philosophy behind it is called Human Performance, and its premises are uncomfortable in exactly the right way:
So the rule is absolute: we never blame the person who reports something. Ever. Not the one who reports a near miss, and not the one who reports their own mistake. They are thanked, they are recognized, and the process gets fixed.
This is not leniency, and it is worth being blunt about why. A company that punishes reporters does not have fewer problems. It has the same problems and no longer hears about them — right up until one of them costs somebody a hand.
| What most owners expect | What actually happens |
|---|---|
| Reports stay low if the culture is good. | Reports spike in the first months — things that were always there stop being hidden. This is the system working. |
| A rising number means things are getting worse. | It means visibility is rising. Punish it here and you teach everyone, permanently, never to tell you. |
| The number should be driven down. | It falls on its own, later, because root causes are actually gone — not because people went quiet. |
That first stage is where these programs die, and it is why it is written down here. Knowing the spike is coming is what lets an owner welcome it instead of panicking at it.
A scoreboard that counts catches
If reporting is genuinely a good thing, then the number of reports somebody has filed should be a number they are proud of — on a screen in the shop, in a Monday meeting, in a review.
It counts catches made
Never mistakes attributed. That single design decision is the difference between a culture people join in with and a culture they hide from.
By person and by team
Zones can see each other. Healthy competition over who is finding the most problems is the only leaderboard in this product that points the right way.
And it closes the loop
When a fix lands, the people who reported it are told, by name. Nothing kills a reporting culture faster than reports disappearing into a void.
A catch becomes a procedure
Here is the part that makes this software rather than a suggestion box, and it is the reason we built it on top of the procedures instead of beside them.
A report names a part of the business — and the system already knows which written procedure governs that part. So a catch does not land in a list somebody reads once. It attaches to the procedure it is evidence against.
-
Somebody reports it
Thirty seconds, from wherever they are standing.
-
It attaches to the procedure it indicts
Three reports against the same step is not an opinion about that step. It is evidence, and the person who owns that procedure is the one who gets it.
-
Or it proves one is missing
When reports pile up somewhere with no procedure behind it, that is the system telling you where to write the next one — ranked by what it is costing you. You stop guessing which SOP to build next.
-
The procedure changes, and so does the number
The revised step runs on the next job, the standard behind it moves, and it shows up in the quarter. The person who reported it can see the line from what they said to what changed.
And if something does happen
Prevention is most of this. But when there is an incident, what you have afterwards is whatever was captured at the time — and a report reconstructed on Thursday from three people’s memories is worth very little to anybody.
The photograph is evidence, not a thumbnail
The full-size image crosses the wire, the camera metadata is read on our side, and the original bytes are fingerprinted before anything is resized. A photograph shrunk on the handset has already lost the thing that made it proof.
Where and when, recorded not recalled
Every step a technician takes carries its time, and the phone’s position rides along with the timeline. Nobody has to remember what time it was.
It prints as a document
The same machinery that turns a day’s work into a proof-of-service PDF turns an incident into one — and what was sent is stored as it was sent, so it is never re-rendered into something the recipient never saw.
What is built today
We would rather tell you this straight than have you find it out in a demo.
| Shipped | Being built now |
|---|---|
| Procedures that belong to a person rather than a job — start of day, end of day, break, anything that is not a work order. In the app today. | The safety procedure pack itself: vehicle check, incident, near miss, good catch, ready to run on day one. |
| The workflow engine that runs them, on a phone, with photographs, typed answers and signatures. | The no-blame scoreboard, counting catches by person and by team. |
| Events, so a report can route itself to the right person the moment it is filed. | The correlation from a report to the procedure it indicts — or to the gap where one should be. |
| Photograph capture with the original metadata and a fingerprint of the untouched bytes. | Incident documents, and the notification back to the reporter when their catch gets fixed. |
The machinery is shipped; the safety surface on top of it is next. That order is deliberate — a safety module built on its own becomes another filing cabinet, and this one is built on the same procedures, the same events and the same evidence pipeline as the work itself.