Author: Paul Pennington

  • HazCom & GHS: What Your Written Program Actually Needs to Cover

    Hazard Communication is one of the most frequently cited OSHA standards year after year, and it’s rarely because a workplace has no chemicals under control — it’s because the written program, labels, or training don’t line up with what’s actually happening on site. Under 29 CFR 1910.1200, aligned with the Globally Harmonized System (GHS), employers who have hazardous chemicals in the workplace need a written HazCom program that ties together classification, labeling, safety data sheets, and employee training. Here’s what that program actually has to cover.

    A written program that reflects reality

    The written hazard communication program is the backbone document. It describes how your workplace handles labeling, safety data sheets, and training, and it names who’s responsible for each. The most common gap isn’t a missing program — it’s a program that describes an idealized process no one actually follows. It has to match the chemicals and workflow in front of you.

    The chemical inventory

    You can’t communicate hazards you haven’t listed. Maintain an inventory of the hazardous chemicals present in the workplace, keyed to the product identifier used on the label and safety data sheet so the three always reference each other. When a chemical comes or goes, the inventory changes with it.

    GHS labels

    Under GHS, shipped container labels carry six standardized elements: the product identifier, signal word (Danger or Warning), hazard statements, pictograms, precautionary statements, and supplier information. Workplace containers must also be labeled — either with the same GHS-style information or with an alternative system that conveys the hazards effectively. Unlabeled secondary containers are a recurring citation.

    Safety data sheets (SDS)

    Every hazardous chemical needs a safety data sheet, and under GHS the SDS follows a standardized 16-section format — from identification and hazard identification through handling, exposure controls, and toxicological information. The sheets have to be readily accessible to employees during their work shifts, not locked in an office no one can reach mid-task.

    Employee training

    Employees must be trained on the hazards of the chemicals in their work area and how to protect themselves — how to read labels and SDSs, what the pictograms mean, the physical and health hazards present, and the protective measures in place. Training happens at initial assignment and whenever a new hazard is introduced. Documenting who was trained, on what, and when is what turns training into a defensible record.

    Non-routine tasks and multi-employer sites

    Two areas that often get overlooked: hazards associated with non-routine tasks (such as cleaning a reactor vessel), and how information is shared on multi-employer worksites so that contractors and their employees know about the chemicals they may be exposed to. A complete program addresses both.

    Keeping the pieces aligned

    HazCom citations usually come from drift — the inventory, labels, SDSs, and training slowly stop matching each other. Our HazCom / GHS Evaluation tool structures the written-program elements so the inventory, labeling, SDS access, and training all reference the same source. It’s a documentation framework only — it does not certify compliance, authorize work, or replace competent-person judgment.

  • The Permit-Required Confined Space Checklist Every Crew Should Run

    Permit-required confined spaces are where a lot of the most serious incidents in construction and general industry happen — not because crews are careless, but because the hazards are invisible until they aren’t. An atmosphere reads fine at the top of a vault and is lethal at the bottom. A checklist exists so that the same verification happens every single time, regardless of who’s on shift. Under 29 CFR 1926 Subpart AA, the entry permit is the document that proves it did. Here’s the checklist logic every crew should be able to run before anyone goes in.

    Confirm the space is actually a permit space

    Not every confined space is permit-required. Start by confirming the space meets the definition: large enough to enter and perform work, limited means of entry or exit, and not designed for continuous occupancy — and then whether it carries a hazardous atmosphere, engulfment potential, an internal configuration that could trap or asphyxiate, or any other recognized serious hazard. If it does, it’s a permit space and the full process applies.

    Identify and communicate the hazards

    List the specific hazards for this space: oxygen deficiency or enrichment, flammable or toxic atmospheres, engulfment materials, mechanical or electrical energy, and any hazards introduced by the work itself (welding fumes, for example). Every hazard identified needs a corresponding control before entry is authorized.

    Test the atmosphere — and keep testing

    Atmospheric testing is done before entry and monitored during the work. Test in the order that matters: oxygen first, then flammable gases and vapors, then toxic contaminants. Test at different levels of the space, because gases stratify. Record the readings on the permit — the numbers, not just a checkmark.

    Control the space before entry

    Ventilate as needed, isolate energy sources through lockout/tagout, and eliminate or block any engulfment or flow hazards. Continuous forced-air ventilation is often what makes an otherwise hazardous atmosphere safe to work in — and if it’s required, the permit should say so and the crew should know it can’t stop.

    Assign the roles

    A permit entry is a team activity with defined roles: authorized entrants, an attendant stationed outside who maintains contact and never enters, and an entry supervisor who authorizes and can cancel the entry. Names go on the permit. Everyone should know who holds which role before work starts.

    Set up rescue before, not after

    Rescue provisions are arranged before entry begins — retrieval systems, communication, and a rescue service that can actually respond in time. Most confined-space fatalities include would-be rescuers who entered without protection. The plan for getting someone out has to exist before anyone goes in.

    Authorize, complete, and close out the permit

    The entry supervisor signs to authorize entry. When work is done, the space is closed out, the permit is cancelled, and it’s retained for review. That retained permit is your record that every step above actually happened — which is exactly what an auditor or investigator will ask for.

    Running it the same way every time

    The point of a checklist is consistency: the same verification, the same order, the same documentation, on every entry. Our Confined Space Evaluation tool structures the permit-space assessment so nothing gets skipped under time pressure. It’s a documentation framework only — it does not certify compliance, authorize entry, or replace competent-person judgment.

  • JHA vs. AHA: What’s the Difference and When Do You Need Each?

    If you’ve worked across different job sites, you’ve probably seen the terms JHA and AHA used almost interchangeably — and then seen a client or auditor insist there’s a difference. Both are hazard analysis tools that break a task into steps, identify the hazards in each step, and define controls. The distinction is mostly about terminology, context, and expectations rather than a fundamentally different method. Here’s how to think about when each label applies.

    What a JHA is

    A Job Hazard Analysis (JHA) — sometimes called a Job Safety Analysis (JSA) — breaks a specific job or task into its component steps, identifies the hazards associated with each step, and specifies the controls or safe work practices that address them. It’s the workhorse document of everyday safety planning: focused on a task, written in plain language, and used to brief the crew before work begins.

    What an AHA is

    An Activity Hazard Analysis (AHA) follows the same step / hazard / control logic but is the term used most often on federal and military construction projects — particularly work governed by the U.S. Army Corps of Engineers EM 385-1-1 safety manual. AHAs typically carry additional expectations: listing the competent or qualified persons for the activity, the training and equipment required, and inspection requirements. In practice, an AHA is a more formally structured cousin of the JHA.

    The practical difference

    The analysis method is essentially the same — break the work into steps, find the hazards, control them. What changes is the audience and the required fields. A JHA satisfies most general-industry and private construction expectations. An AHA is what you produce when the contract or governing manual specifically calls for one, and it usually demands more detail around personnel qualifications, equipment, and inspection.

    When do you need each?

    Use a JHA for routine task-level hazard planning on typical job sites, and whenever you want a clear, briefable safety document for a crew. Use an AHA when a contract, a government client, or a governing safety manual (such as EM 385-1-1) explicitly requires one — and check that specification early, because retrofitting a stack of JHAs into AHA format under deadline pressure is where teams lose time and consistency.

    Keeping them consistent

    Whichever term applies, the value comes from consistency: the same steps analyzed the same way, controls that map to real hazards, and a document someone can actually follow. Our JHA/AHA Procedure Builder structures the step-hazard-control logic so the same task is documented the same way every time. It’s a documentation framework only — it does not certify compliance, authorize work, or replace competent-person judgment.

  • How to Write a Compliant LOTO Procedure (29 CFR 1926.417 Guide)

    A lockout/tagout (LOTO) procedure exists to answer one question in a way an auditor, a foreman, and the person doing the work can all agree on: how do we make this equipment safe to service, and how do we prove it was done? Under 29 CFR 1926.417, the expectation isn’t just that energy gets controlled — it’s that the control is documented, specific to the equipment, and repeatable by anyone authorized to perform it. This guide walks through what a compliant, machine-specific LOTO procedure actually contains.

    Procedure identity and scope

    Every procedure should name the specific equipment or machine it applies to, not a general category. “Hydraulic press, Line 3, Asset #HP-0412” is auditable; “presses” is not. Define the scope of the servicing or maintenance activity the procedure covers, since a routine die change and a full teardown may isolate different energy sources.

    Personnel and roles

    Identify who is authorized to perform the lockout, who the affected employees are, and who holds responsibility for verifying the equipment before work begins. Authorized employees apply and remove their own locks; affected employees need to know the equipment is being serviced and must not attempt to start it.

    Energy sources and isolating devices

    List every energy source connected to the equipment — electrical, hydraulic, pneumatic, mechanical, thermal, and any stored energy such as springs or elevated components. For each source, name the specific isolating device (the disconnect, valve, or blocking device) and its location. Vague references are the most common gap in a rejected procedure.

    Shutdown and isolation sequence

    Spell out the ordered steps to shut down the equipment normally, then isolate each energy source. Sequence matters: shutting down in the wrong order can create a hazard rather than remove one. Each isolating device is then locked and tagged by the authorized employee.

    Controlling stored energy

    Isolation alone doesn’t make equipment safe if energy remains stored in the system. The procedure must describe how residual or stored energy is relieved, disconnected, restrained, or otherwise rendered safe — bleeding hydraulic pressure, blocking suspended parts, or grounding capacitors, for example.

    Verifying zero energy

    Before any work starts, the authorized employee verifies isolation was effective — typically by attempting to operate the equipment (after confirming the area is clear) and confirming it will not start, and by testing with instruments where appropriate. This zero-energy verification step is what turns a locked disconnect into a genuinely safe condition.

    Restoring equipment to service

    Document the steps to return the equipment to operation: inspecting the work area, confirming all tools and personnel are clear, removing locks and tags by the employees who applied them, and notifying affected employees before re-energizing.

    Periodic inspection

    A procedure that’s written once and never reviewed drifts out of compliance as equipment changes. Build in a periodic inspection — who reviews the procedure, how often, and how deviations get corrected — so the document keeps matching the machine in front of you.

    From framework to finished procedure

    Getting each of these sections consistent across dozens of machines is where most teams lose time. Our LOTO Procedure Builder structures the energy sources, isolation sequence, and verification steps into a repeatable, machine-specific document. It’s a documentation framework only — it does not certify compliance, authorize work, or replace competent-person judgment.

  • What Are OSHA’s Fatal Four? The 4 Hazards Behind Most Construction Deaths

    If you manage safety on a construction site, four categories of hazard deserve more of your attention than any others. OSHA calls them the “Fatal Four,” and for a straightforward reason: year after year, they account for the majority of construction worker deaths. Understanding them isn’t academic — it shapes where you focus your hazard recognition, your controls, and, just as importantly, the record you keep of both.

    The four are falls, struck-by incidents, caught-in or caught-between incidents, and electrocution. Below, we walk through what each one actually covers on a real jobsite, the OSHA standards most closely tied to them, and why documenting your recognition of these hazards matters as much as recognizing them.

    1. Falls (29 CFR 1926 Subpart M)

    Falls from height are consistently the single largest cause of construction fatalities. They happen at leading edges, on scaffolds, through floor and roof openings, off ladders, and from elevated work platforms. The controlling standard, Subpart M, sets the threshold at which fall protection is generally required and defines the acceptable systems — guardrails, safety nets, and personal fall arrest. But the standard is only half the story on-site. What a reviewer or an investigator asks after the fact is: what conditions were present, what hazards were recognized, and what controls were documented against them?

    2. Struck-By

    Struck-by hazards involve a worker being hit by a moving object — a vehicle, falling material, a swinging load, or a flying particle. They range from a dropped tool at height to a backing dump truck. Because struck-by hazards are so situational, they reward specific, condition-based recognition rather than generic checklists.

    3. Caught-In or Caught-Between

    These incidents involve a worker crushed, pinned, or caught in equipment, collapsing material, or between two objects. Trench collapses and unguarded machinery are classic examples. The energy involved is often invisible until it’s released — which is exactly why documented recognition and controls carry weight.

    4. Electrocution

    Contact with overhead power lines, unsafe equipment, and improper wiring drives this category. It overlaps heavily with hazardous energy control, which is why lockout/tagout documentation sits so close to Fatal Four work.

    Why Documentation Is the Piece That Gets Missed

    Here’s the pattern we see repeatedly: the work gets talked through, hazards get considered, and decisions get made by the people responsible for making them. What goes missing is the record — the clear account of what was reviewed, what was selected, and what was relied on. Recognition that lives only in someone’s head, or in an illegible field note, is hard to stand behind later.

    A structured Fatal Four documentation framework doesn’t make the safety decision for you — your competent person still recognizes the hazard, and your employer still authorizes the work. What it does is turn that real judgment into a clear, consistent record that holds up when someone asks, later, what actually happened.

    Compliance Crucible tools are documentation frameworks. They do not certify compliance, authorize work, or replace competent-person judgment.