Your company answers to ONE framework. Pick it once and every
report, matrix and signal grouping speaks that language only, with no comparing
jurisdictions you don't operate in.
Scopes the suggested controls in the dealt-with modal to your trade.
The hazard taxonomy itself never changes.
By default the company reads retellings only: verbatim wording can
identify the writer. The audit view lets a supervisor open an entry's original text to
check a retelling was faithful. Whether keeping that view is right for your
jurisdiction is your call; Off hides it for everyone.
How many people this deployment covers, 1 to 5,000. Seats are
capacity, not identities, and nobody is assigned one. This is the denominator for
the weekly participation figure, so getting it wrong makes that percentage wrong.
The records, and starting over
One deployment holds one company. There is no company column anywhere in here, so
whoever signs in sees every site and every entry on it. That is why handing this to
someone new means emptying it, not renaming things.
Every entry, site, register and action, as one file. An H&S
record can be one you are required to keep, so take this whether or not you are
clearing anything.
Deletes every entry, site, register entry and action, so the next
company starts on nothing of anyone else's. Logins are not touched. This cannot be
undone from in here, and it will not run until the records above have been
downloaded. Type start fresh to confirm.
Accounts sit in a separate database and survive the emptying. If
you leave them alone, anyone still holding one can sign in and read whatever the next
company puts in. Yours is never switched off.
Taking yourself off it
When a company is running on this deployment, they are the only ones who should be able
to read what their people said. This switches your own login off, so nothing you hold opens
it any more.
Empty it first, above. Once you are off, nobody can remove anything left
behind until the company sets up their own login. There is no way back from in here: undoing
it needs somebody with access to the server itself.
Your password stops working immediately. The browser you are in
now keeps working until the session expires, because a session is not re-checked
against the account on every request. Type remove me to confirm.
Link access
Each of the three links can be left open or put behind a sign-in. They are separate
switches because they are separate decisions: closing the client link is a commercial
choice, and closing the crew's QR poster is a choice about anonymity.
A sign-in here only opens the door. It is never attached to what anyone
sends, and an entry made by someone signed in is stored exactly as an anonymous one is.
Turning a switch on does not change any entry already made.
The posters on site, at /w/. Leaving this off is the point of the
product: a person can scan, speak and walk away with no account at all. Turn it on
only if your situation genuinely requires it, and expect fewer people to speak.
The one company link you give clients. On means a client needs the
sign-in from their invitation before the page opens.
The same, for subcontractors and partners.
Your own login
Every login here is handed out with a random password, which is right for sending one
and wrong for living with. Change yours to something you will actually remember.
There is no reset by email, and there cannot be: nothing here records
which login went to which address. That is the same design that keeps entries anonymous.
If you lose this password, the account has to be replaced.
At least 10 characters. A few words together beat a short
complicated one.
Setting a company up
One link that does the whole start: the crew get the code to scan, and whoever runs it
gets their own login, without anybody being walked through it.
Send this to the company and stop there. It shows a printable page
with the crew's code on it and a button that sets up the manager's login. It is a
credential: anyone holding it can create that login, so it stops working after the
logins on it are used up.
Switch it off once a company is set up. A switched-off link and a
wrong one look the same from outside: neither says whether anything is here.
Usually one, or two if somebody needs a spare. It stops there, so a
link that gets forwarded around cannot keep making logins.
Makes a fresh link and puts the count back to the start. The old
link stops working immediately, so one company can never spend another's logins.
Client and partner links
One link per audience, each opening its own page and feeding its own source. Neither
is ever mixed with the crew's.
One link for the whole company. Clients pick the project, then
say it in their own words: not happy, happy, or a suggestion. Print the table card
and stand it where clients are, or send the link with a quote or an invoice.
One link for partners and subcontractors: they pick the job, then
say it in their own words: not happy, working well, or a suggestion. Send it with the
subcontract pack or the purchase order. Their feed is its own source, never mixed
with clients or the crew.
Four groups sign in here: your crew, HR, clients and partners. You keep an email list
for each one and send invitations; every invitation creates an account and mails its
login to that address, without recording which login went where.
Counts workers who signed in to the
crew screen. Anonymous QR-poster reports are never counted, they are not tied to a
person.
Each site gets its own link. Print it as an A4 poster, or send it to the crew.
It opens the crew screen with no app, no account and no sign-in, which is what keeps
what they send unattached to them.
When a site closes, disable it: the poster on the wall stops working
and every entry it ever produced stays exactly where it is. Delete is offered only on a
site that has no history at all, because a report records the site’s name
Deleting a site with entries would cut them loose from the place they came from.
Renaming is safe: the whole history moves with the name.
What the crew calls the place. It appears on every report from
that site, so it cannot be changed later without splitting the history.
Changes take effect immediately and apply to every report from that point
on. Saving needs a signed-in supervisor session in this browser.