Company-wide settings. They change how every report and every
figure is worded and counted. None of it is required to start. The setup is the
link you were sent, your own sign-in and the one code everybody scans; everything on this
page is something you might want on top of that, and you can add any of it later.
Your company answers to ONE framework. Pick it once and every
report, matrix and signal grouping speaks that language only, with no comparing
jurisdictions you don't operate in.
Scopes the suggested controls in the dealt-with modal to your trade.
The hazard taxonomy itself never changes.
By default the company reads retellings only: verbatim wording can
identify the writer. The audit view lets a supervisor open an entry's original text to
check a retelling was faithful. Whether keeping that view is right for your
jurisdiction is your call; Off hides it for everyone.
How many people this deployment covers, 1 to 5,000. Seats are
capacity, not identities, and nobody is assigned one. This is the denominator for
the weekly participation figure, so getting it wrong makes that percentage wrong.
The records, and starting over
One deployment holds one company. There is no company column anywhere in here, so
whoever signs in sees every site and every entry on it. That is why handing this to
someone new means emptying it, not renaming things.
Every entry, site, register and action, as one file. An H&S
record can be one you are required to keep, so take this whether or not you are
clearing anything.
Deletes every entry, site, register entry and action, so the next
company starts on nothing of anyone else's. Logins are not touched. This cannot be
undone from in here, and it will not run until the records above have been
downloaded. Type start fresh to confirm.
Accounts sit in a separate database and survive the emptying. If
you leave them alone, anyone still holding one can sign in and read whatever the next
company puts in. Yours is never switched off.
Taking yourself off it
When a company is running on this deployment, they are the only ones who should be able
to read what their people said. This switches your own login off, so nothing you hold opens
it any more.
Empty it first, above. Once you are off, nobody can remove anything left
behind until the company sets up their own login. There is no way back from in here: undoing
it needs somebody with access to the server itself.
Your password stops working immediately. The browser you are in
now keeps working until the session expires, because a session is not re-checked
against the account on every request. Type remove me to confirm.
Link access
Each of the three links can be left open or put behind a sign-in. They are separate
switches because they are separate decisions: closing the client link is a commercial
choice, and closing the crew's QR poster is a choice about anonymity.
A sign-in here only opens the door. It is never attached to what anyone
sends, and an entry made by someone signed in is stored exactly as an anonymous one is.
Turning a switch on does not change any entry already made.
The posters on site, at /w/. Leaving this off is the point of the
product: a person can scan, speak and walk away with no account at all. Turn it on
only if your situation genuinely requires it, and expect fewer people to speak.
The one company link you give clients. On means a client needs the
sign-in from their invitation before the page opens.
The same, for subcontractors and partners.
Your own login
Every login here is handed out with a random password, which is right for sending one
and wrong for living with. Change yours to something you will actually remember.
There is no reset by email, and there cannot be: nothing here records
which login went to which address. That is the same design that keeps entries anonymous.
If you lose this password, the account has to be replaced.
At least 10 characters. A few words together beat a short
complicated one.
Setting a company up
One link that does the whole start: the crew get the code to scan, and whoever runs it
gets their own login, without anybody being walked through it.
Send this to the company and stop there. It shows a printable page
with the crew's code on it and a button that sets up the manager's login. It is a
credential: anyone holding it can create that login, so it stops working after the
logins on it are used up.
Switch it off once a company is set up. A switched-off link and a
wrong one look the same from outside: neither says whether anything is here.
Usually one, or two if somebody needs a spare. It stops there, so a
link that gets forwarded around cannot keep making logins.
Makes a fresh link and puts the count back to the start. The old
link stops working immediately, so one company can never spend another's logins.
Client and partner links
One link per audience, each opening its own page and feeding its own source. Neither
is ever mixed with the crew's.
One link for the whole company. Clients pick the project, then
say it in their own words: not happy, happy, or a suggestion. Print the table card
and stand it where clients are, or send the link with a quote or an invoice.
One link for partners and subcontractors: they pick the job, then
say it in their own words: not happy, working well, or a suggestion. Send it with the
subcontract pack or the purchase order. Their feed is its own source, never mixed
with clients or the crew.
Four groups sign in here: your crew, HR, clients and partners. You keep an email list
for each one and send invitations; every invitation creates an account and mails its
login to that address, without recording which login went where.
Counts workers who signed in to the
crew screen. Anonymous QR-poster reports are never counted, they are not tied to a
person.
Each site gets its own link. Print it as an A4 poster, or send it to the crew.
It opens the crew screen with no app, no account and no sign-in, which is what keeps
what they send unattached to them.
When a site closes, disable it: the poster on the wall stops working
and every entry it ever produced stays exactly where it is. Delete is offered only on a
site that has no history at all, because a report records the site’s name
Deleting a site with entries would cut them loose from the place they came from.
Renaming is safe: the whole history moves with the name.
What the crew calls the place. It appears on every report from
that site, so it cannot be changed later without splitting the history.
Company structure
The Index reads every site on the same sixteen and climbs a ladder with them: floors
under areas, areas under divisions, divisions under the group. Each layer sees the units
under it side by side, and a unit's answers are the union of its floors' answers, so nothing
is counted twice on the way up. Counts on the Index are answers, never people.
With no ladder set, every site is a floor under one group, and the Index
reads it that way today. A site not assigned to a floor stays a floor of its own under the
group, so nothing goes missing while the ladder is being drawn.
Which world the work is in. A sheet changes the words on the ladder,
who sits at each desk, the roles a send-on sheet offers and where an alarm goes the same
day. It never changes the sixteen.
Start with the group: the company, the board or the owner. Add
divisions, areas and floors under it. A floor is the unit a supervisor stands in front
of: the site, the crew, the shift, the ward. A unit with anything still under it is not
deleted.
Loading the ladder…
Every site points at one floor on the ladder. Change the floor and
the site's answers, past and future, are read under it; the answers themselves never
move or change.
Loading the sites…
The company door
One link for the whole company, for the crew who are not standing at a poster. It opens
two doors and nothing else. The HR door is about the company: pay, rosters, how people are
treated. It never asks where anyone is. The place door is about a project or a place: the
person picks it from the list, lets the phone match the nearest one, or scans the code
there, and what they say is read under that place. The two are never averaged.
It is a credential like the posters: anyone holding it can speak
through it. It is minted once and never changes, so print it once. Every site on the
list is one that has coordinates saved under Sites; a site not placed yet is still on
the list, it just cannot be matched by a phone.
Changes take effect immediately and apply to every report from that point
on. Saving needs a signed-in supervisor session in this browser.