Permit to Work Register
Keep a live register of high-risk work permits — who is working where, under what controls, and whether the permit is still valid — and see immediately which permits expired without ever being returned. Runs entirely in your browser. Nothing is uploaded.
Version 1.0.0 · Updated Aug 5, 2026
Overview
How to use Permit to Work Register
The complete in-tool guidance, reproduced here so you can read it before you download.
What this register is
CM8-47 is a live index of the permits you have issued. One row per permit: who is working, on what, where, under what controls, until when, and whether it has come back. From that it works out which permits are in force right now, how long each has left, and — the point of the whole thing — which permits ran past their expiry and were never handed back.
Everything runs inside this single file. There is no account, no upload and no network request of any kind, so contractor names, isolation references and site details never leave the computer you are using.
What it is not
This register does not authorise anything. It does not issue, approve, extend, suspend or close a permit. Typing a row here has no effect on any work anywhere.
A permit to work is a control document. It is issued by a competent, authorised person who has seen the job, assessed the hazards, satisfied themselves that the controls are actually in place, and accepted responsibility for the conditions written on it. It is accepted by the person in charge of the work, held at the job, and handed back when the work stops. That document — signed, on paper or in your permit system — is the permit. This is a register of those documents and nothing more.
Two kinds of work deserve saying out loud. Confined space entry brings duties this tool cannot touch: identifying the space, eliminating entry where the job can be done from outside, atmospheric testing before and during entry, ventilation, a standby person, and workable rescue arrangements that do not depend on the emergency services arriving in time. Most confined space deaths are would-be rescuers. Hot work brings its own: clearing or protecting combustibles, isolating detection, a competent fire watch during the work and for a period after it, and a final check of the area before the site is left. A tick in a checkbox here is a note that somebody said they had done these things. It is not evidence that they were done, and it discharges none of them.
What to record
Add the permit when it is issued, not when it is closed — a register written up afterwards cannot tell you what is live now, which is the only question it exists to answer.
- Permit number — the number on the document itself, so the row and the paper can be matched.
- Issued date and time, valid until date and time — these drive every countdown. Blank times are read generously: a blank issue time is the start of that day, a blank expiry time is 23:59 on that date. That is almost always longer than you intended, so put the real times in.
- Location and description — specific enough that somebody could walk to the job.
- Contractor, person in charge, number of people — the people count is how you know how many are exposed under live permits at any moment.
- Isolation, gas test and fire watch — tick what the permit required, and record the reference or the reading.
- Issued by and accepted by — the two names that make the permit a permit.
- Status and the closed date — set the status to returned or cancelled and record the date the moment the permit comes back. Nothing else clears it from the live list.
Permit types
Nine types are offered: hot work, confined space entry, work at height, electrical isolation or live working, excavation or ground disturbance, lifting operation, pressure system or line breaking, roof access, and a general permit. Use the specific type wherever one fits. A register full of general permits usually means high-risk work is being covered by a document that was not written for it, and the summary table will show it.
Five of these are counted as high-consequence in the headline figures: hot work, confined space, electrical, excavation and pressure systems. That is a fixed list, chosen because the failure mode is immediate and usually fatal. It is not a judgement that work at height or roof access is safe — falls kill more people than any of them. It is a shortlist for the tile, not a risk ranking.
How the state is worked out
Each permit is given one state, calculated fresh from your dates, times, status and this computer's clock. Dates and times are combined into a single moment:
Issued at = date issued + time issued (blank time = 00:00) Valid until = valid-until date + valid-until time (blank time = 23:59)
Time to expiry = valid until − now Permit duration (hours) = (valid until − issued at) ÷ 3,600,000 ms
The states, in the order they are tested:
- Returned or Cancelled — status says so. Nothing else is calculated.
- Expired — NOT RETURNED — the status is “expired”, or now is past the valid-until moment and the permit has not been returned or cancelled.
- Not yet started — issued for a future date and time.
- Suspended — status says the work is stopped. Not counted as live.
- Expiring soon — inside the warning window you set. Counted as live.
- Live — in force, with time left.
“Live” means the permit is in force, not that anybody is on the job. A permit issued this morning and not yet started is still a live authorisation with conditions attached to it.
Time to expiry is shown in hours below two days and in days above, and as “overdue” once it is negative.
The permit that was never returned
An expired permit that was never handed back is the most important thing in this register. It means either the work carried on past the point at which anybody checked the conditions still held, or the job finished and nobody confirmed the site was left safe — plant still isolated, a hole still open, detection still switched off, a lock still on. You do not know which, and that is the problem.
Those permits are marked in red in the State column, listed at the top of the live permits table, named in full underneath the register, coloured red on the location and contractor charts, and counted in their own headline tile. That is deliberate. Nothing here lets you close one off from a keyboard: go and find the person in charge, establish whether the work is still going on, stop it or re-permit it, then physically retrieve and sign off the paper permit.
A permit expiring at the end of a shift is normal and correct. Long-running permits are where this goes wrong: a multi-day excavation permit is easy to forget, which is why the duration column and the average duration by type are worth looking at. If a type routinely runs for days, ask whether it should be re-issued each shift instead.
Isolations, gas tests and fire watch
The Compliance column flags gaps between what a permit says it needed and what has been recorded against it:
- No isolation reference — isolation was required but no lock-off or isolation certificate reference has been entered. Without it, nobody can trace what was isolated or who holds the lock.
- No gas test result — a gas test was required and no reading has been recorded, on a permit that has already started. Permits issued for a future date are not flagged, because the test has not been due yet.
- Confined space, no gas test required — a confined space entry that was issued without an atmospheric test. Sometimes justified; always worth explaining.
- Hot work, no fire watch — hot work issued without a fire watch. Sometimes justified in a dedicated hot work bay; rarely anywhere else.
- Expired, not returned — included here while the breach setting is on.
Record the gas test result as figures, not as “OK”: oxygen percentage, flammable gas as a percentage of the lower explosive limit, and any toxic reading, with the time it was taken. A reading from three hours ago is not a reading now.
The headline figures
Six tiles, calculated on whatever the filters currently show. Permits on the register, with returned and cancelled counts. Currently live, with the number of people those permits cover and how many fall inside the warning window. Expired and not returned. Permits requiring isolation, with any missing references. High-consequence permits live now. And permits returned, as a count and a percentage:
Returned % = permits with status “returned” ÷ permits shown × 100
That percentage is not a performance score. A register filtered to this week will show a low figure simply because most of the work has not finished yet.
Charts and tables
The live and expiring permits table lists everything not yet returned or cancelled, sorted by time to expiry with the overdue ones first. The summary by permit type table gives, per type, the number of permits, how many are live, the average duration, and how many expired without return.
Average duration (hours) = sum of durations ÷ number of permits with both a valid issue moment and a valid expiry moment
Permits missing either date are left out of the average rather than counted as zero, so a type can show a count of six and an average drawn from four. The total row averages every duration in the filter directly — it is not an average of the type averages, which would weight a single roof access permit the same as forty hot work permits.
Settings
Expiry warning window sets how long before expiry a permit starts showing as “Expiring soon”. Four hours suits a site issuing shift-length permits; a day suits multi-day construction permits.
Treat an expired, unreturned permit as a breach is on by default and adds that flag to the Compliance column. Turn it off only if your permit system genuinely allows a permit to lapse without being handed back. The red state, the register footer and the tile do not change either way — the fact is the fact.
Printing and sharing
Print Report produces a report from whatever the current filter shows: header, the six headline figures, the four charts, both summary tables, the full register and your closing notes. Print to PDF to circulate it or to file it as a period record.
The scope line under the title states the filter in force. Clear the filters before issuing anything described as the whole register — a report filtered to hot work will show no excavation breaches, and will not say so unless somebody reads the scope line.
Saving your work
Permits, settings and the report header are written to this browser's local storage as you type, and the toolbar shows the time of the last save. That storage belongs to one browser on one computer: another browser, a private window, a second machine or a clean-up tool that clears site data will not have it.
Treat Export .json as the real save — one file containing everything, which Import .json restores anywhere. Export CSV gives you the register for spreadsheet work and includes every filtered record, not only those drawn on screen. Reset asks twice, then erases everything this tool has stored. There is no undo.
Permit records are usually kept for a defined period after the work — how long differs by country, industry and contract. Establish what applies to you and archive the exports accordingly.
Accuracy & disclaimer
This tool calculates from what you type. It cannot tell whether a permit was issued by a competent person, whether the controls written on it were ever put in place, whether the isolation was proved, whether the gas test was taken with a calibrated instrument, or whether the work being done matches the description. Every state and every countdown depends on the dates, times and status being kept up to date, and on this computer's clock being right.
Permit systems, competence requirements, atmospheric testing standards, rescue arrangements and record retention periods differ by country and by industry. This is an internal record-keeping aid, not legal advice, not a permit, not an authorisation to work, and not a substitute for a permit system operated by competent people.