Safety documents nobody reads are not safety.
The RAMS sits in a folder on a shared drive, unread, until an auditor asks and the hunt begins. Operify AI attaches it to the work itself and refuses to let the task start until the operative has read and signed the current version.
Cleared, or it does not start.
- 01Documents attach to the task type, not the task. Declare them once and every occurrence of that work is covered, forever.
- 02Every applicable document must be signed by that operative. Anything unsigned is named as its own outstanding item.
- 03Signatures respect versions. A signature only counts against the document's current major version, inside its review window. A major revision voids prior signatures and forces a re-sign.
- 04The operative signs on their phone. The pre-start screen shows the required PPE, a plain-language briefing, then the document. The sign button unlocks only when it has been read to the end.
- 05Enforced on the server. On start, on completion, on resume, and on the generic status path.
There is no override and no back door.
Three things block the work, automatically.
- A person flags it with a reason
- A safety form answer breaches a configured limit, for example a wind reading above the safe threshold for external work
- An operative's mandatory certificate expires, which automatically blocks every task it covers until it is valid again
An expired ticket should stop the work. Automatically.
Certificate types define a validity period and a grace window. State is computed live: valid, in grace, expiring soon, expired, revoked, or lifetime. A task type can require a certificate as mandatory, which gates the work, or preferred, which warns in the picker. A sweep runs after every change, blocking and unblocking tasks automatically. Reminders fire at thirty, fourteen, seven and zero days before expiry.
Nobody has to notice. Nobody has to remember.
RIDDOR determined at the moment of capture.
An operative reports from their phone in seconds. Operify AI allocates a reference, routes it to an owner by walking the site hierarchy, and alerts by severity. Determination runs at capture and on every triage edit, checking most-serious first: fatality, dangerous occurrence, specified injury, occupational disease, and over-seven-day incapacitation, each with its statutory form and deadline. Operify AI tracks the clock and alerts. Every corrective action becomes a tracked task, closed by manager verification. Incidents are never deleted.