Contractor and permit-control guide

Site access is not permission to work: verify the contractor again where the controlled task begins

A worker may be approved by the contractor-management system and admitted through the site gate, yet still lack authorization to perform hot work, enter a confined space, break containment, isolate equipment, excavate, or work at height. Electronic permit to work connects the verified person to one defined task, location, time window, work team, hazard assessment, and set of controls.

Biometriya Insights14-minute readUpdated October 2026
Short answer

Contractor management establishes whether a company and worker are eligible for the site. Access control decides whether that verified person may cross a checkpoint. ePTW decides whether named people may perform a specific controlled activity under current conditions. Linking the systems avoids duplicate data, but one decision must never silently substitute for another.

One worker, three different operational decisions

Organizations often connect contractor records, gates and permits, then describe the result as one authorization. Operationally, the three layers answer different questions. Keeping them distinct makes the workflow easier to audit and safer to change.

Control layerPrimary questionTypical evidenceResult
Contractor complianceIs this company and worker currently eligible to mobilize?Company approval, contract, worker identity, assignment, induction, competence and documentsReady, conditionally ready, expired, suspended or rejected
Site and zone accessMay this verified worker pass this checkpoint now?Biometric identity, active status, site, shift, time, gate, zone and escort rulesGrant, deny or route for assisted review
Permit to workMay this named work team perform this task under these conditions?Job scope, plant, location, hazards, isolations, controls, roles, validity and coordinationDraft, reviewed, issued, active, suspended, extended, handed back or closed

A valid gate event does not prove a permit is active. A valid permit does not prove every named person has arrived. A biometric match does not prove competence or that gas testing, isolation, toolbox communication and worksite preparation are complete. The integrated system should expose these distinctions rather than compressing them into a misleading green status.

Use one identity without creating one permanent permission

The same trusted worker identity can connect company onboarding, site access, training, attendance and permit roles. Reuse reduces duplicate enrollment and name mismatches. Permission remains contextual: the worker who is eligible for routine mechanical maintenance may be outside the authorized team for today’s confined-space entry.

Biometriya Contractor Management and Site Access can own company and worker readiness. Biometriya ePTW can own task authorization and field controls. Access integration can enforce selected decisions at physical checkpoints without turning a permit into an indefinite door group.

Biometriya ePTW dashboard showing permit status and controlled work information
Permit control: the operational view should make task, location, roles, validity, controls and current status clear to authorizers and field teams.
Biometriya rugged biometric tablet for worker verification in field operations
Field verification: a rugged biometric device can bring the current permit decision to the work location instead of relying only on a gate check.

Put verified identity at the moments where responsibility changes

Biometrics should not be added to every click. Use verification where impersonation, substitution or ambiguity would materially weaken the control. The appropriate moments depend on permit type, risk, workforce model and local requirements.

01Qualify

Approve the contractor company, accountable contacts, scope, insurance, capability and site relationship.

02Ready the worker

Establish identity, assignment, induction, competence, licences and time-limited evidence.

03Plan the work

Define task, plant, location, hazards, interacting work, work party, isolations and precautions.

04Authorize

Confirm that each responsible permit role is held by the intended competent person.

05Validate in field

Verify the performing authority or worker against the active permit and current worksite.

06Monitor and close

Control suspension, extension, shift handover, team changes, hand-back and final closure.

Company approval happens before the permit

A permit authorizer should not need to investigate the contractor’s commercial standing, base qualifications and every worker document while a crew waits at the job. Company qualification, sponsorship, worker enrollment, assignment and standard readiness belong earlier in the contractor lifecycle. Exceptions should be visible before work planning reaches the issue stage.

Permit roles need clear identity and authority

Originator, area authority, isolating authority, gas tester, performing authority, worksite supervisor and permit user can carry different responsibilities. Names alone are not enough if accounts are shared or a device is passed between people. Strong sign-in, role entitlement, re-verification at sensitive transitions and an immutable action trail help show who accepted which responsibility.

Biometric verification confirms the person interacting with the workflow. It does not confer competence. Role assignment should still depend on current training, authorization and the site’s documented permit model.

The work party can change after issue

Replacement workers, late arrivals and crew changes are normal contractor realities. The system should require a controlled amendment or field validation rather than allowing an unrecorded substitution. It should show whether the new worker is site-ready, qualified for the task, briefed on the permit and accepted by the responsible authority.

Make the field result explain what is true now

A field device should not show only “permit found.” It should evaluate the presented identity against the permit and current context, then return an understandable reason when the work cannot proceed.

Worker and assignment
  • Biometric identity resolved to one worker
  • Contractor company and assignment active
  • Worker named in the permit role or work party
  • Required competence and induction current
  • No suspension, expiry or unresolved duplicate
Permit and worksite
  • Correct permit type, task, asset and location
  • Permit issued and inside its validity window
  • Required isolations and linked certificates in state
  • Toolbox communication and acceptance recorded
  • No conflict, suspension or emergency restriction

Verify location without pretending GPS is a safety control

A rugged device can attach site, zone, checkpoint, QR asset marker or location context to the verification. GPS can support the record, especially across distributed assets, but it does not prove the correct plant has been isolated or the atmosphere is safe. Field confirmation should use the worksite and asset controls appropriate to the task.

Show why the decision is amber or red

“Denied” is not an operational instruction. A useful result distinguishes wrong worker, missing work-party membership, expired competence, inactive permit, wrong location, suspended work, missing prerequisite, out-of-window attempt, stale offline data and a technical identity failure. Each reason should have an owner and safe resolution route.

Do not let override become the normal workflow

Urgent work may need escalation, but urgency does not make an undocumented bypass safe. Record who authorized the exception, their authority, the reason, evidence reviewed, exact scope, expiry and follow-up. Some conditions should remain non-overridable. Review recurring overrides as a process problem rather than an operator habit.

Control suspension, handover, offline verification and hand-back

Permits are living controls. Conditions change, simultaneous work creates conflicts, alarms occur, shifts end and plant must return to service. Identity-linked ePTW should support these transitions without suggesting that a permit issued earlier remains valid regardless of what happened afterwards.

Shift handover is a new acceptance of responsibility

If work crosses a shift, the incoming responsible people need the current task state, hazards, isolations, incomplete work, work party and local conditions. The system should record who handed over, who accepted, when it occurred and whether revalidation was required. A previous biometric confirmation should not be silently attributed to the new supervisor.

Suspension must reach people and checkpoints

An alarm, gas result, process change, conflicting job, weather event or operating instruction may suspend work. The field workflow should stop presenting the permit as active, notify responsible roles and preserve the reason. Where access is linked, the site should decide whether suspension also restricts entry to the work zone or merely prohibits the task.

Offline use needs a narrow, explicit policy

Remote plants and shutdown areas may have weak connectivity. Define which permit data, worker identities, role rights and revocations are cached; maximum data age; which actions can occur offline; how device time and event order are protected; and how conflicts are reconciled. Permit issue, extension or closure may require online authority even if a field identity check can be performed locally.

Hand-back closes the operational loop

Stopping work is not the same as returning plant to operation. The permit process should confirm work status, tool and material removal, work-party withdrawal, reinstatement conditions, isolation state and acceptance by the operating authority. HSE guidance emphasizes formal hand-back and safe condition at completion. Biometric verification can strengthen who makes the declaration, but cannot inspect the plant on their behalf.

Test the complete contractor-to-work journey

Test real permit types and workers, including active and expired contractors, wrong work-party members, replacement personnel, multiple subcontractor tiers, similar names, biometric retry, suspended work, linked permits, conflicting activities, shift handover, offline devices, late synchronization and plant hand-back. Include operations, maintenance, contractors, safety, security and permit users in the pilot.

Operational measures worth reviewing

  • Readiness: permits delayed by missing assignment, induction, competence, licence or contractor evidence.
  • Identity: verification success, retries, unresolved identities, substitutions detected and assisted reviews.
  • Permit quality: wrong permit type, missing field, linked-certificate gap, returned permit and rework rate.
  • Field control: wrong location, unlisted worker, out-of-window attempt, suspension response and unauthorized start.
  • Workflow pressure: permits waiting at shift start, authorizer workload, exception time and override frequency.
  • Closure: overdue permits, incomplete hand-backs, stale isolations, unresolved work-party presence and audit findings.

A practical identity-linked ePTW checklist

  • Separation: Are contractor readiness, access and work authorization represented as different decisions?
  • Identity: Is every accountable permit action attributable to one authorized person?
  • Competence: Does biometric verification confirm the person without being mistaken for proof of qualification?
  • Work party: Can replacements and changes be added only through a controlled, visible process?
  • Field context: Does validation check the correct task, asset, location, validity and permit state?
  • Handover: Are outgoing and incoming responsibilities, conditions and incomplete work explicitly accepted?
  • Suspension: Can current restrictions reach field users quickly and clearly?
  • Offline: Are allowed actions, cache age, revocation, time integrity and reconciliation defined?
  • Hand-back: Does closure confirm the worksite and plant state rather than only closing a digital record?
  • Audit: Can reviewers reconstruct who decided what, on which evidence, at what time and location?

The most valuable integration is not a biometric button inside a permit form. It is a coherent chain from contractor qualification to worker readiness, site entry, task-specific authorization, field verification, controlled change and safe hand-back—with every person and decision represented accurately.

Frequently asked questions

Does an active ePTW automatically grant site access?

Not necessarily. Site and zone access should follow the facility’s access policy. A permit may be one input for a narrow location and time window, but it should not create broader or permanent rights.

Does biometric verification prove a contractor is competent?

No. It links the presenting person to an enrolled identity. Competence, induction, licences, medical requirements and role authority must come from current workforce and compliance records.

When should a worker be verified during a permit workflow?

Risk-based points may include permit-role acceptance, work-party briefing, arrival at the controlled worksite, shift handover, team amendment and hand-back. Not every interaction needs biometrics.

Can ePTW work offline?

Selected field functions can work offline if cached data, allowed actions, maximum age, event protection, revocation, synchronization and conflict handling are designed. High-consequence approvals may still require online confirmation.

Can a permit replace a risk assessment or isolation procedure?

No. A permit communicates and coordinates controlled work; it does not make the job safe by itself. Risk assessment, isolations, testing, supervision and task-specific precautions remain essential.

Independent guidance and resources