Permit to Work
A Permit to Work (PTW) is a formal, temporary and tracked authorization that allows a person or a team to carry out a specific activity, in a given location and for a precise time window.
It is a central tool in operational safety management, in particular for:
- high-risk work (hot work, confined spaces, electrical work, work at height);
- complex industrial environments;
- sites and yards with multiple contractors.
In these scenarios safety is not just “being compliant”, but being authorized right now: the permit to work answers exactly this need.
PTW in 4HSE
Section titled “PTW in 4HSE”In 4HSE the permit to work is not a separate object: it is a certificate issued at the end of a procedure, enriched with the characteristics typical of an operational authorization. In this way 4HSE builds on the procedures, forms and certificates you already use, without introducing a separate flow.
A certificate that acts as a permit to work carries:
- the type of activity authorized;
- the location / site / area;
- the worker or team authorized;
- the start and end date and time of validity;
- a status (draft, valid, expired, revoked, rejected);
- the completed forms (checklists, authorizations, assessments) that become an integral part of the certificate.
The permit is therefore a cross-cutting procedure that runs through features you probably already know: the prevention action that defines what to authorize, the linked forms to be completed, the certificate that attests the authorization, the scheduler from which it is issued and monitored, and the public verification page that anyone can open by scanning a QR code.
The permit life cycle
Section titled “The permit life cycle”Every certificate-permit has a status that describes where it is in its life cycle. The status is visible in the certificate detail, in the scheduler, and on the public verification page.
| Status | Meaning |
|---|---|
| Draft | The permit is being prepared: it is not yet authorized and does not grant the right to operate. |
| Valid | The permit is authorized and effective within its validity dates. |
| Expired | The permit has passed its end date/time and must be renewed. Expired is derived automatically from the dates. |
| Revoked | The permit was withdrawn before its natural expiry (for example because conditions on site changed). |
| Rejected | The permit was not approved. |
Time-bound validity: date, or date and time
Section titled “Time-bound validity: date, or date and time”A permit is effective between the Date release and the Date expire. When you issue the certificate, the Time precision checkbox determines the precision of these dates:
- Time precision off (date only) — the permit is valid for the whole day and expires at the end of the expiry day. Suitable for authorizations measured in days, months or years.
- Time precision on (date and time) — an Hour field appears next to each date and the permit expires at the exact moment chosen. This is the right choice for short-lived permits: hot work, an access lasting a few hours, a single shift.
Full example: hot work permit
Section titled “Full example: hot work permit”Let’s walk through the whole flow with a concrete case. A worker must carry out a welding job (hot work) in an area of the plant. The activity must be authorized only after the due checks, must last a few hours and be verifiable on site by a supervisor or an inspector.
The same flow applies to the other high-risk permits (confined spaces, electrical work, work at height) and, in its simplest form, to authorizing a person’s site access.
1. Create the procedure
Section titled “1. Create the procedure”The permit is issued through an action of type Procedure.
- Open the project and go to the relevant office.
- Go to Actions → Procedures and create a new procedure, for example “Permit to Work – Hot work”.
- Set the validity and the other parameters of the procedure.

2. Add the PTW linked forms
Section titled “2. Add the PTW linked forms”In the Related Forms tab of the procedure, add the forms that must be completed to authorize the permit. 4HSE provides predefined, regulation-compliant PTW forms, including:
- General work permit
- Hot work permit
- Confined Space Entry Permit
- Electrical work permit
- Work at height permit
For our case we add the Hot work permit form, which gathers all the necessary information: performing company and contract coordination, location, fire-risk classification of the area, fire prevention measures, and start and end time of the work.
We mark this form as Required: this way the permit cannot be issued until the form has been completed.

3. Associate the worker
Section titled “3. Associate the worker”Associate the person to be authorized with the procedure: in our case the welder who will carry out the job. This way the permit is issued to a specific named person, exactly like a nominal authorization.

4. Issue the certificate from the scheduler with the required forms
Section titled “4. Issue the certificate from the scheduler with the required forms”From the scheduler, locate the deadline related to the person associated with the procedure and start the certificate creation.
Since the procedure includes a required form, 4HSE opens the “Forms linked to certificate” window:
- the associated forms are listed, with the Required column indicating which ones are mandatory (in our case, “Yes” for the Hot work permit);
- each form has a Fill link: the operator opens the checklist, completes it, applies signatures where required, and saves;
- the Create certificate button stays disabled until the required form has been completed.

Clicking Fill opens the form — in our case the Hot work permit — with all its fields: performing company and contract coordination, location, fire-risk classification of the area, fire prevention measures, work times, authorizations and signatures. Once completed, the form is saved and you return to the linked-forms window.

Once the required forms are completed, the Create certificate button becomes enabled and you can proceed with the issuance. In the New certificate window, turn on the Time precision checkbox and set the Date release and Date expire with their respective Hour: for example release at 13:00 and expiry at 15:00, for a 2-hour duration. The permit will then be valid only for the hot-work window and will expire automatically at the end.

The certificate is now valid: the completed form is attached to the certificate and becomes an integral part of it.
5. Generate the verification QR code
Section titled “5. Generate the verification QR code”From the certificate detail, click the Verification QR button
The QR code contains no data and does not expose internal identifiers: it only points to a temporary public page. You can display it on screen, print it, or embed it in the permit document.

6. On-site verification and public page
Section titled “6. On-site verification and public page”A third party — inspector, supervisor, client, contractor’s supervisor — scans the QR with their phone. The browser opens the public verification page, read-only and without needing a 4HSE account, which recalculates and shows the up-to-date status of the permit.

The page shows a concise view of the permit:
- the header with the permit name and the activity type (in our case, Procedure), next to the QR;
- the status highlighted with a colored badge: Valid (green), Expired (red), Revoked / Rejected, or Draft;
- the Permit details: the Worker or team and the Valid from and Valid until validity;
- any Attachments (for example the completed hot-work form), which can be opened from the page;
- the Verified on line, i.e. the date and time the page was consulted.
Because the status is recalculated in real time, if the permit has expired (past the 2 hours) or has been revoked, the page shows it immediately on the next scan. This is the difference from a paper permit: the QR always answers the question “is this permit valid right now?”.
Security and privacy
Section titled “Security and privacy”The verification model is designed to be secure and privacy-respecting:
- the verification link is signed and has a limited lifetime: it is not a guessable address and stops working when it expires;
- the QR does not expose internal identifiers or sensitive data;
- when you need to share the permit again after the link has expired, you generate a new QR from the certificate detail.
This approach is consistent with the GDPR principles of data minimization, purpose limitation and security.